Personnel & Third-Party Security Standard (SFA 06-107.1.3)

Summary

Requirements for managing the security responsibilities of staff and vendors across the employment lifecycle, from screening and rules of behavior through transfers, offboarding, and discipline; supports Policy 06-107.1.

Body

Quick Overview
  • This standard sets the specific requirements for keeping people (employees) and outside parties (vendors, contractors, and other third-party providers) from becoming a security risk to SFA.
  • It covers the full lifecycle: setting the rules of behavior, screening people before they get access, handling transfers, offboarding people who leave, and applying discipline when the rules are broken.
  • It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
  • It applies to everyone who uses SFA information resources, including vendors and contingent workers, and is carried out mainly by the CISO's office, Human Resources, and Privacy Officers.
  • These requirements are the minimum baseline SFA must meet; the university may choose to do more.
  • Meeting this standard is mandatory unless a formal exception is granted.

Most security incidents trace back to people: someone who was never properly vetted, who was never told the rules, who kept access after changing jobs, or who walked out the door still holding a badge and a login. This standard closes those gaps. It spells out what SFA must do to make sure the people and companies who touch SFA systems and data, from the day they are hired or contracted to the day they leave, are trustworthy, know their responsibilities, and lose their access at the right time. It is the "people side" of SFA's security program.

i
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources. Anyone working within SFA IT facilities, including authorized vendors, visitors, and contingent workers, must follow it when using SFA information resources unless a contract documents otherwise. In practice, the requirements below are carried out mostly by:

  • The CISO and the Office of Information Security, who define and enforce personnel and third-party security requirements.
  • Human Resources (HR), who run background checks, offboarding, and disciplinary actions.
  • Privacy Officers (PO), who keep privacy and legal obligations built into the rules and contracts.
  • IT management and teams, who enforce the requirements and grant or remove access.
  • Vendors and third-party service providers, who must comply and report security concerns.
i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • CISO / Office of Information Security: Develops, maintains, and reviews the personnel and third-party procedures (job responsibilities, rules of behavior, screening, transfers, offboarding, and discipline) and makes sure they are communicated, working with HR, Privacy Officers, and IT.
  • Human Resources (HR): Runs background checks and screenings, offboards separated individuals, and defines and administers disciplinary actions.
  • Privacy Officers (PO): Keep the procedures and contracts current with privacy laws and regulations and make sure third parties meet SFA's privacy requirements. (At some institutions this role may also sit with a legal or compliance officer.)
  • IT Management / Teams: Enforce the requirements, monitor conformance, and report potential security violations to the right people.
  • Third-Party Service Providers: Comply with SFA's security and privacy requirements and report any security concerns affecting SFA systems or data.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into six areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.1.3.1.1) are shown so you can match them to the attached PDF.

1  Vendor Job Responsibilities & Rules of Behavior  Setting the terms for outside parties ⌄

Before a vendor or outside organization can touch SFA systems or data, SFA must set clear, written terms and hold them to SFA's security and privacy standards.

  • Evaluate, define, and put in place terms and conditions for any trust relationship with a vendor or outside organization that is allowed to reach SFA systems from the outside or to process, store, or transmit SFA data, and require them to maintain adequate security and privacy controls (06-107.1.3.1.1).
  • Define and document access agreements for SFA systems, review and update them at least once every 12 months, and require users to sign before getting access and re-sign when the agreement or their job changes (06-107.1.3.1.2).
  • Document security requirements and procedures for vendors, including their security roles, and require vendors to notify SFA as soon as possible when a vendor worker holding SFA credentials or badges transfers or separates (06-107.1.3.1.3).
  • Include contract terms (reviewed and approved by the Office of General Counsel) that establish SFA's ownership of and rights to data the vendor creates or maintains, and impose applicable privacy and records requirements on any vendor system holding SFA data (06-107.1.3.1.4).
  • For external system services, require that the provider's interests match SFA's, and either run SFA-controlled integrity checks or obtain provider evidence to verify the integrity of the data and processing the service performs (06-107.1.3.1.5).
2  Job Responsibilities & Rules of Behavior  Telling people the rules ⌄

SFA must give users clear rules for how to use systems and data safely, and build security responsibilities into job descriptions.

  • Work with Privacy Officers to give users the rules that describe their responsibilities and expected behavior for using systems and data securely, and review and update those rules at least once every 12 months (06-107.1.3.2.1).
  • Include in the rules of behavior, at a minimum, limits on social media and external sites, rules about posting organizational information publicly, and rules on using SFA identifiers (like email addresses) and passwords to create accounts on outside sites (06-107.1.3.2.2).
  • Work with HR, Privacy Officers, and other departments to document all positions tied to information security and privacy, write those roles into position descriptions, and review and update them at least once every 12 months (06-107.1.3.2.3).
3  Personnel Screening  Checking people before access ⌄

People must be vetted before they are given access, and re-checked when their situation changes.

  • Work with HR to run background checks or other required screening during hiring, before granting access to any SFA system or data and before the start date, and re-screen users when their job changes, when they need significant new access (such as admin rights), after misconduct or a security incident, or when regulations like Texas Education Code Section 51.215 require it (06-107.1.3.3.1).
  • Verify with HR that, before the start date, anyone accessing a system that handles SFA data has passed the required screening before access is granted (06-107.1.3.3.2).
4  Employee Transfer  Adjusting access when roles change ⌄

When someone changes jobs inside SFA, their access should change with them, so they do not keep permissions they no longer need.

  • When a user is reassigned or transferred, review and confirm whether they still need their current physical and logical access to systems, assets, and IT facilities, adjust access to match the new role, and notify users of the changes as needed (06-107.1.3.4.1).
5  Offboarding Separated Individuals  Cutting off access when people leave ⌄

When someone leaves SFA, their access, credentials, and assets must be recovered quickly and completely.

  • Schedule and conduct exit interviews, surveys, or questionnaires with departing users within 7 calendar days of their last day, covering the offboarding steps, the assets, data, and credentials to be collected, and any other security considerations (06-107.1.3.5.1).
  • Work with HR to define separation actions carried out as soon as possible: disable access to all systems and facilities, terminate credentials, inventory and collect assigned assets, and identify data under retention or legal holds, then obtain remaining assets and physical credentials and notify affected users (HR defines the notification timing so the CISO's office is alerted in time to act) (06-107.1.3.5.2).
  • Use automated tools to notify and terminate user access in advance of and on the last day of employment, where technically feasible (06-107.1.3.5.3).
6  Disciplinary Actions  Consequences for breaking the rules ⌄

When users or vendors break the security and privacy rules, SFA must apply consistent, HR-defined consequences.

  • Work with HR to apply the HR-defined disciplinary measures for vendors and users who fail to comply with SFA 06-107 security and privacy policies and standards, and, when a formal disciplinary process starts, notify the disciplined user and their manager within one business day, identifying the user and the reason (06-107.1.3.6.1).
!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no feasible remediation, follow the exception process in the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

The requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, mainly the PS (Personnel Security) family, plus AC-20, SA-4, SA-9, and PL-4.
  • TAC 202, for example 202.72, 202.75, 202.77.
  • Texas DIR Security Controls Catalog (PS-2 through PS-9, AC-20, SA-4, SA-9) and the DIR Prohibited Technologies list.
  • NIST CSF (GV.RR-02, PR.AA-02) and NIST 800-171 (3.1.20, 3.9.1, 3.9.2).
  • Privacy and sector frameworks: GDPR, HIPAA, GLBA, and FERPA.
  • UTS 165 (sections 22.1, 22.5, 22.6, 22.9) for third-party and external service requirements.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy

Related standards:

Other references:

  • Texas Department of Information Resources Prohibited Technologies
  • Texas Risk and Authorization Management Program (TX-RAMP)
  • SFA 06-107 Controls Crosswalk Reference

Responsible office: Office of Information Security; Privacy Officers (PO)  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173924
Created
Thu 7/16/26 2:20 PM
Modified
Thu 7/16/26 5:57 PM

Related Articles

Related Articles (3)

Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.