Skip to main content
Back to results
NIST 800-171 R-3.9.2

Protect CUI During Personnel Actions

Official citation: 3.9.2

Class: core · Severity: high

Statement of the obligation — verify against source

3.9.2

What it means

Protect CUI systems during and after personnel changes such as terminations and transfers. On departure, promptly disable accounts, revoke credentials and authenticators, and recover equipment and access cards; on transfer, adjust access to fit the new role so no one keeps access they no longer need.

Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.