The organization should establish a process to verify the criminal background of personnel performing critical cybersecurity tasks.
Before starting their duties, these individuals should provide an official criminal record extract confirming no crimes related to information security have been committed.
The process should also cover re-checks if suspicions arise. A valid security clearance classified as "confidential" or higher may be considered an acceptable substitute, where applicable.
Individuals found to have a record of information security crimes should not be allowed to work in positions requiring access to protected information.