Background screening is an operational security control: it helps organizations reduce the risk of insider threats, fraud, and inappropriate access by verifying identity, employment history, and other relevant checks before granting trust, credentials, and system access. This aligns with security governance practices that protect organizational assets (data, systems, finances, customers) by ensuring personnel are vetted according to policy and role sensitivity.
Option A (“increase access restrictions”) is related but incomplete—screening doesn’t restrict access by itself; it supports decisions about whether access should be granted at all, and at what level. Option B (define KPIs) is performance management, not security. Option C (evaluate PHI) is healthcare-data specific and not the purpose of background checks.
In project environments, especially those handling sensitive data (PII/financial/customer records) or regulated work, background screening supports compliance and reduces risk exposure. It’s part of broader operational security controls alongside least privilege, need-to-know, MFA, monitoring, and offboarding. Therefore, the best explanation is to apply operational security.