N.2.08 Background checks on candidates for employment
Control Overview
This control mandates that the organization establishes and implements a risk-based screening and background check procedure for all candidates prior to employment, onboarding, or internal promotion into high-privilege positions. The depth and breadth of the screening must be directly proportional to the information security risks associated with the target role. This process ensures the competence and reliability of personnel, minimizing insider threats and preventing security incidents caused by unauthorized or unvetted access to sensitive systems and data environments.
Applicability Note: This control is fully applicable to the anDREa platform and represents a vital security control governing all hires, external contractors, and systems engineers.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement integrates screening directly into the human resources component of our ISO/IEC 27001-based ISMS, balancing strict security requirements with European privacy and labor laws.
anDREa applies a tiered, risk-proportional methodology to background checks. All positions undergo baseline checks, including identity verification, qualification reviews, and reference checks. For roles involving access to high-confidentiality information or infrastructure management (e.g., platforms administrators, cloud developers, and Research Support Team members), enhanced screening is required. This includes a mandatory request for a Certificate of Good Conduct (VOG) or its regional equivalent. The evaluation of screening data is strictly restricted to designated, qualified personnel who ensure that all procedures comply with the General Data Protection Regulation (GDPR) and local labor regulations.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.06.01 - Screening | Mandates that background verification checks for all candidates for employment are carried out in accordance with relevant laws, regulations, and ethics. |
| HR Security Policies | Personnel Screening & Background Check Procedure | The authoritative text defining the tiered verification requirements, automated triggers, and role-based matrix for candidate vetting. (A.06.01 - Screening) |
| Vetting Mandates | VOG (Certificate of Good Conduct) Requirements | Formal operational specifications defining which high-privilege technical and managerial roles require mandatory criminal record checks. (Identity Checks) |
| Operational Records | Identity Checks | Secure HR audit logs verifying that credentials, identities, references, and certificates were validated before account issuance. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Tiered screening workflows, mandatory VOG rules for sensitive roles, and authorized evaluation procedures are fully defined and active. Continuous Improvement: To optimize readiness for external audits, explicitly highlight and cross-reference the enhanced screening criteria used for "NIS 2 critical roles" (such as personnel managing system infrastructure that supports essential or important platform services) within your main screening matrix.