People are consistently the most exploited element in any organisation's security posture, and CTDISR-2025 Section 14 addresses this directly. The requirements cover background checks for staff with system access, security awareness training with documented records, insider threat detection mechanisms, and formal procedures for managing access when staff join, move roles, or leave.
These requirements are straightforward to understand but consistently incomplete in implementation: most ISPs do some version of each, but few have the documentation trail that satisfies an auditor's three-part test of implementation, currency, and ownership.
Staff Background Checks
Background checks are required for all staff with access to organisational systems, not just senior staff or those with privileged access. For Pakistani ISPs, what constitutes an adequate background check in practice is: identity verification against official documents (CNIC verification), employment history verification for prior relevant positions, and a criminal record check where the access level justifies it.
The documentation requirement is the part most ISPs are missing: conducting background checks informally during recruitment, without producing a dated record showing what was checked and the result, doesn't satisfy the audit requirement. Each check needs to produce a record that can be retrieved and presented as evidence.
For new hires, the background check should be completed before the individual is granted system access. A background check performed after someone has been working with full access for three months partially defeats the purpose and is still a procedural finding.
For existing staff hired before the background check requirement existed, a pragmatic approach is to conduct verification checks at the next natural review point (annual review, role change) and document them, rather than retroactively disrupting existing staff relationships. The key is having a documented plan for achieving full coverage and showing progress against it.
Security Awareness Training
Annual security awareness training is mandatory for all staff, with records maintained as audit evidence. The training must cover at a minimum: phishing and social engineering awareness, password security and credential management, incident reporting procedures, and acceptable use of organisational systems and data.
The records requirement is specific: you need evidence that each named staff member completed training in the relevant period, not just that training was conducted. A sign-off sheet, a completion report from a training platform, or email confirmations with dates satisfies this. A vague statement that all staff completed training without supporting documentation does not.
Phishing simulation exercises are also required. A phishing simulation involves sending simulated phishing emails to staff (using a platform like KnowBe4, Proofpoint Security Awareness Training, or similar) and measuring the click and credential-submission rate. The simulation results inform where additional training is needed and demonstrate that you're actively testing awareness rather than just conducting annual training and assuming it's working.
Role-specific training for technical and privileged users goes beyond general awareness: staff who administer network equipment, manage subscriber data, or respond to incidents need training that covers the specific risks and responsibilities of their role. This doesn't need to be a separate formal course; incorporating role-specific content into technical onboarding and regular team meetings with documented discussion of relevant topics can satisfy the requirement if the documentation is there.
Insider Threat Detection
Insider threat detection mechanisms don't require a dedicated insider threat programme in the enterprise sense. For most Pakistani ISPs, the practical implementation covers: access logs that make unusual access patterns visible (a NOC engineer accessing the billing database at 2am with no operational reason should generate a review), monitoring for large data exports or transfers by privileged users, and behavioural indicators in the context of staff changes (a departing employee accessing systems or data outside their normal scope in their final weeks is a pattern worth flagging).
The important distinction under Section 14 is that insider threat detection is a documented control, not just good security hygiene. Write down what monitoring is in place, what patterns would trigger a review, and who reviews flagged incidents. That documentation converts implicit monitoring into an auditable control.
Joiner, Mover, Leaver Procedures
Joiner-mover-leaver (JML) procedures are the formal process for managing access at each staff lifecycle transition. For joiners: what access is provisioned, when, and by whom, with approval documentation. For movers: when a staff member changes roles, how is their previous access reviewed and adjusted, and who is responsible for ensuring old access is revoked and new access appropriate to the new role is granted. For leavers: what is the process for revoking all access on departure, and within what timeframe.
The leaver procedure is where most ISPs have the most significant gap. Informal departures where credentials are never formally revoked, contractors who retain access after an engagement ends, and email accounts that remain active for months after a departure are consistently found during access audits. A leaver checklist that covers every system an individual had access to, with sign-off confirming revocation, is the practical implementation.
The timeliness of access revocation matters as much as the procedure itself: a procedure that requires access to be revoked within 24 hours of departure but shows a pattern of revocation happening a week later in practice is still a finding. The procedure and the actual execution need to match.
For operators building HR security procedures as part of a broader CTDISR compliance programme, CTDISR Audit Readiness includes Section 14 gap closure. For ongoing governance of HR security controls including training programme oversight, CISO-as-a-Service covers this as part of the governance remit.