Back

Require regular vacations for personnel using restricted information or sensitive information.


CONTROL ID
06550
CONTROL TYPE
Human Resources Management
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Establish, implement, and maintain an occupational health and safety policy., CC ID: 00716

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • The organization must require job or shift rotations for personnel who use sensitive information and require that they take regular scheduled vacations that exceed several days. (CSR 1.10.2, Pub 100-17 Medicare Business Partners Systems Security, Transmittal 7, Appendix A: CMS Core Security Requirements CSR, March 17, 2006)