36 MAC Pt. 1, R. 12.1
Personnel Security Protection
Cite as 36 Miss. Admin. Code Pt. 1, R. 12.1
Personnel Security Protection
A. Each agency must screen individuals prior to authorizing access to any non-public
agency systems or data. Screening activities include but are not limited to the
evaluation/assessment of an individual’s conduct, integrity, judgment, loyalty,
reliability, and stability (i.e., the trustworthiness of the individual).
1. Ensure that all staff which are provided access to non-public data are subject
to, at a minimum, background checks in accordance with applicable laws.
B. Each agency must ensure that access to agency systems and data are protected during
and after personnel actions such as terminations and transfers.
1. Establish a documented process for disabling user access within a predefined
time upon employee departures. This may include disabling or deleting user
accounts, VPN access, and the return or disablement of access tokens and
keys.
2. Consider timely execution of termination actions for individuals terminated
for cause. In certain situations, agencies must consider disabling the system
accounts of individuals that are being terminated prior to the individuals being
notified.
3. Ensure that all security-related agency system-related property is retrieved and
retain access to all agency information and systems formerly controlled by the
terminated individual.