Skip to main content

peopleVersion 1SOC2ISO27001NIST800-171

Human Resources Security Policy

Pre-employment, onboarding, role changes, and off-boarding for personnel.

Download PDFSHA-256 df533549510d8782…

Human Resources Security Policy

1. Purpose

Ensures that personnel who access Rex Black or client data are qualified, identified, aware of their responsibilities, and handled securely throughout employment.

2. Pre-employment

  1. Identity is verified during onboarding (government ID or equivalent).
  2. Role-appropriate background checks are performed for any position with access to Confidential or Restricted data, subject to applicable law. Results are stored encrypted and accessed only by the CEO or Privacy Officer.
  3. For CUI-relevant roles, U.S. person status and any required clearances are verified before access is granted.
  4. References are contacted for final-round candidates.

3. Onboarding

  1. Offer letter and NDA are signed before first day.
  2. The signed Acceptable Use Policy acknowledgement, Security Training completion, and Access Request (002-access- control-policy.md) are completed in the first 5 business days.
  3. New hires receive:
    • Rex Black-issued or approved device per the Endpoint Security Policy.
    • Password Manager / Vault access.
    • MFA factors provisioned.
    • Email and role-based system access.

4. During employment

  1. All personnel complete annual security awareness training and policy refresh. Results are recorded.
  2. Role changes trigger access reviews within 5 business days (add / remove / modify per new responsibilities).
  3. Performance issues involving security (policy violations) are documented and addressed per the disciplinary process.

5. Off-boarding

  1. On notice of separation:
    • CEO is informed.
    • Access review started.
  2. On last day (or immediately, for involuntary terminations):
    • All access revoked within 4 hours (SSO, VPN, AWS, Google Workspace, GitHub, Slack, SaaS tools).
    • Device recovery initiated; MDM wipe executed if device is not returned within 5 business days.
    • Handover of documents, credentials, and in-flight work completed.
  3. Exit interview covers return of property and confidentiality obligations that survive termination.
  4. Former personnel remain subject to NDA obligations as stated in their agreement.

6. Contractors and temporary personnel

  1. Contractors execute a Rex Black Contractor NDA and an acceptable- use agreement before receiving any access.
  2. Contractor access is time-boxed at grant; renewal requires confirmation of continued need.
  3. Contractors are subject to the same policies as employees for the scope of their work.

7. Disciplinary process

  1. Security-related policy violations follow a graduated process: informal counseling → written warning → final warning → termination, escalated immediately for violations that cause material harm.
  2. Suspected criminal activity is reported to the CEO and handled per the Incident Response Plan.

8. Roles & responsibilities

Role Responsibility
CEO Hiring, separation, disciplinary decisions.
Security Officer Access grant/revoke execution; training tracking.
Privacy Officer Handling of personal data about personnel.

9. References

  • 002-access-control-policy.md
  • 003-acceptable-use-policy.md
  • 024-security-training-and-awareness-policy.md

10. Revision history

Version Date Author Approver Change
1.0 2026-04-17 CEO CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center