In proportion to the access they hold. Physical and privileged access to critical rooms bypasses most digital controls, so screening belongs inside the security design, sized to what each role can reach.
Every hardened room has a door, and someone has the key. Technicians, contractors, cleaners, guards and engineers all need physical access to keep a facility running, and in AI and energy infrastructure the same people often hold remote credentials and maintenance rights as well. That convergence is what makes insider risk different here. The trust decision about a person is also a decision about the room.
Define the insider before you screen for one
CISA defines an insider as any person who has or had authorized access to or knowledge of an organization's resources, including its personnel, facilities, equipment, networks and systems. Its definition of insider threat covers use of that access "wittingly or unwittingly" to cause harm. Two parts of that definition matter for facilities. It includes past access, which is why revocation matters as much as onboarding. And it includes unwitting harm, which is why screening is only one of several controls. CISA's mitigation framework runs through four steps: define, detect and identify, assess, and manage.
What the electric sector already requires
NERC CIP-004-7, the personnel standard in force for bulk electric system cyber assets, is the most detailed public model of screening matched to access. Before granting authorized electronic or unescorted physical access, an entity must have a process to confirm identity and a seven-year criminal history records check covering every place the person has lived in that period, along with criteria for evaluating the results. Contractors and vendors must meet the same bar. Assessments must be repeated at least every seven years. Training comes before access and at least every 15 calendar months after that, and access records are reviewed every quarter.
Revocation is where many programs fail, and CIP-004 is specific about it. Unescorted physical access and interactive remote access must be removed within 24 hours of a termination. Access no longer needed after a transfer must go by the end of the next calendar day. Individual accounts must be revoked within 30 days. CIP-004-8, approved by FERC in March 2026 as part of the virtualization revisions, keeps this structure and takes effect in 2028.
Data centers are not subject to CIP-004. But its structure translates directly: define the access tiers, screen to the tier, retrain on a schedule, and set revocation times in hours, not in HR cycles.
Screening has legal edges
A screening program that is not lawful will not survive its first challenge. Under the Fair Credit Reporting Act, an employer using a consumer reporting agency must give the applicant a clear written disclosure in a document that consists solely of that disclosure, and get written authorization. Before taking adverse action based on the report, the employer must provide a copy of it and a summary of the person's rights. The FTC's guidance for employers explains each step.
The EEOC's 2012 guidance on arrest and conviction records does not prohibit considering criminal history. It asks employers to consider the nature and gravity of the offense, the time elapsed, and the nature of the job, and it recommends an individualized assessment. It also notes that an arrest alone does not establish that criminal conduct occurred. For critical-facility roles, those factors usually support a targeted screen tied to specific access rather than a blanket rule.
Controls beyond the background check
NIST SP 800-53 treats personnel security as a control family. PS-3 requires screening before access and rescreening on a defined schedule. PS-4 requires access to be disabled within a defined period after termination, with credentials and property recovered. PS-7 extends the same requirements to external providers, including a duty to report transfers and terminations of their credentialed staff. That last control is easy to overlook.
Map the rooms, then map the people who can enter them. Screening depth, training frequency and revocation time should all follow that map. A generic HR check sized to the job title will not fit a room where compromise cascades.
Organizations building a program often use specialized screening firms. Background investigation services are offered through Amidon, among many other providers.
Disclosure. Authentic Intelligence is affiliated with Amidon, which is linked in this article. About and disclosure.
Sources
- CISA, Insider Threat Mitigation
- CISA, Defining Insider Threats
- NERC, CIP-004-7 Cyber Security: Personnel & Training
- Federal Register, Order No. 919: Virtualization Reliability Standards (Mar. 24, 2026)
- 15 U.S.C. 1681b, Permissible purposes of consumer reports
- FTC, Using Consumer Reports: What Employers Need to Know
- EEOC, Enforcement Guidance on the Consideration of Arrest and Conviction Records (2012)
- NIST SP 800-53 Rev. 5, Security and Privacy Controls
Cite this article: Authentic Intelligence Research, “How Should Energy and Data Facilities Screen the People With Access?” Authentic Intelligence, September 30, 2026, https://authenticint.com/articles/screening-personnel-for-energy-and-data-infrastructure.html.