DISP Personnel Categories Explained

Personnel security is a foundational element of the Defence Industry Security Program (DISP). While organisations often focus on policies, cyber controls, and facilities, DISP assessments place equal emphasis on who has access to Defence information and environments.

To manage this risk, DISP groups people into defined personnel categories, each with different security expectations. Misunderstanding these categories is a common source of confusion and can lead to incorrect clearance assumptions or compliance gaps.

This article explains the main personnel categories under DISP, how they are applied in practice, and why correct categorisation matters for organisations working with Defence.

Why DISP uses personnel categories

DISP is designed to ensure that access to sensitive Defence information is controlled, proportionate, and justifiable.

Not every person associated with an organisation poses the same level of security risk. Some individuals require regular access to classified information, while others may have only incidental exposure or none at all.

Personnel categories help Defence and organisations:

  • Apply security controls consistently
  • Ensure clearances are granted where genuinely required
  • Avoid over-clearing or under-clearing staff
  • Align personnel access with operational need

Correct categorisation supports both security outcomes and workforce efficiency.

The importance of correct categorisation

Personnel categorisation is not an academic exercise. It directly affects:

  • Who must hold a security clearance
  • What level of clearance is required
  • Who can access Defence facilities or systems
  • How personnel movements and changes are managed

Incorrect categorisation can result in individuals accessing information they should not, or being excluded from work they are required to perform.

DISP assessments expect organisations to demonstrate that personnel categories are clearly defined, understood, and applied consistently.

Key personnel under DISP

Key personnel are individuals who hold positions of authority or influence within the organisation that could impact security outcomes.

This typically includes:

  • Directors and senior executives
  • Owners or controlling interests
  • Security officers or managers
  • Individuals with decision-making authority over Defence work

Key personnel are assessed not only on their access to information, but also on their ability to influence security culture, governance, and compliance.

In most cases, key personnel are required to hold an appropriate level of security clearance consistent with the organisation’s DISP membership level and access requirements.

Relevant personnel under DISP

Relevant personnel are individuals who require regular or sustained access to Defence information, assets, systems, or facilities as part of their role.

This group often includes:

  • Operational staff
  • Technical specialists
  • Engineers, ICT professionals, and analysts
  • Project managers and delivery personnel

Relevant personnel are the group most commonly associated with security clearance requirements, such as Baseline or NV1 clearance.

Clearance levels for relevant personnel must align with the classification of information they access, not their job title or seniority.

Ancillary personnel under DISP

Ancillary personnel are individuals whose roles may involve incidental or supervised access to Defence environments but do not require independent access to classified information.

Examples may include:

  • Administrative support staff
  • Facilities and maintenance personnel
  • Cleaning or security services staff
  • Temporary or contract workers

Ancillary personnel may not require the same level of clearance as relevant personnel, but their access must still be controlled and justified.

DISP expects organisations to manage ancillary access through supervision, access controls, and procedural safeguards.

Personnel who do not require access to Defence information

Some individuals associated with an organisation may have no access to Defence information, systems, or facilities.

This can include:

  • Staff working exclusively on non-Defence projects
  • External service providers with no Defence engagement
  • Personnel located in separate business units or locations

These individuals generally do not require security clearances under DISP, provided access separation is effective and enforceable.

Clear boundaries between Defence and non-Defence activities are essential to support this distinction.

Most organisations entering the Defence supply chain underestimate what DISP actually requires or assume existing policies are enough.

The DISP Readiness Quiz gives you a fast, structured way to understand where your organisation really stands.

How personnel categories affect clearance requirements

Personnel categories help determine whether a clearance is required, but they do not automatically define the clearance level.

Clearance level decisions are based on:

  • Information classification accessed
  • Frequency and nature of access
  • System and facility exposure
  • Contractual requirements

For example, a relevant person accessing PROTECTED information may require Baseline clearance, while another relevant person accessing SECRET information will require NV1 clearance.

The category informs the assessment, but classification drives the decision.

Managing personnel movement between categories

Personnel roles and responsibilities change over time. DISP expects organisations to manage these changes proactively.

This includes:

  • Reassessing access when roles change
  • Initiating clearance upgrades where required
  • Restricting access where no longer justified
  • Updating records and reporting changes appropriately

Failing to manage personnel movement is a common source of DISP non-compliance.

Common mistakes in personnel categorisation

Organisations often encounter issues where:

  • All staff are treated as relevant personnel unnecessarily
  • Ancillary staff access is not properly controlled
  • Key personnel clearance requirements are overlooked
  • Categories are defined but not applied in practice

These mistakes can increase cost, complexity, and security risk.

Demonstrating personnel control during DISP assessment

During DISP assessment, Defence looks for evidence that:

  • Personnel categories are clearly defined
  • Access controls align with those categories
  • Clearance decisions are justified and documented
  • Supervision and segregation measures are effective

Evidence may include role descriptions, access matrices, clearance records, and procedural controls.

Why personnel categorisation supports security culture

Clear personnel categorisation reinforces a risk-aware security culture.

When staff understand:

  • Why access is controlled
  • What information they are authorised to handle
  • How responsibilities differ across roles

Security becomes a shared responsibility rather than an abstract requirement.

Final thoughts

Personnel categories are a practical mechanism for managing security risk under DISP.

By clearly defining who requires access, at what level, and under what conditions, organisations can apply security controls proportionately and effectively.

Correct categorisation supports compliance, protects sensitive information, and enables Defence work to proceed without unnecessary friction.

Understanding and applying these categories correctly is a critical part of operating securely within the Defence supply chain.

Most organisations entering the Defence supply chain underestimate what DISP actually requires or assume existing policies are enough.

The DISP Readiness Quiz gives you a fast, structured way to understand where your organisation really stands.

more insights