1. ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Annex A, Control A.6.1.1 ("Screening") states, "Background verification checks on all candidates to be employed shall be carried out prior to joining the organization and on an ongoing basis, taking into account applicable laws, regulations and ethics. They should be proportional to the business requirements, the classification of the information to be accessed and the perceived risks." This control implicitly includes checks like criminal records for roles with significant risk.
2. Whitman, M. E., & Mattord, H. J. (2019). Management of Information Security (6th ed.). Cengage Learning. In Chapter 5, "Personnel and Security," the section on "Employment Criteria and Screening" details the importance of background checks. It explicitly lists criminal background checks, credit checks, and education verification as key components of screening potential employees for information security-sensitive positions (pp. 188-189).
3. Stanford University. (2023). Administrative Guide Memo 2.1.5: Recruitment and Selection. Section 4, "Background Checks," outlines that a background check, which may include a criminal history check, is a required condition of employment for certain positions, particularly those with access to sensitive data or financial assets. This demonstrates the real-world application of additional screening in a reputable institutional setting.