A6.1 Screening
3 min read
Screening is a crucial step in hiring employees and contractors who will handle sensitive information. ISO 27001 A6.1 Screening emphasizes that organizations should conduct pre-employment background checks to verify the trustworthiness and reliability of individuals before granting them access to critical systems and data.
Failure to screen employees properly can lead to insider threats, fraud, data breaches, or regulatory non-compliance. Screening helps organizations minimize risks by ensuring that personnel with access to sensitive data meet security and ethical standards.
Implementation Guide #
Step 1: Define Screening Criteria
- Establish risk-based screening procedures depending on the sensitivity of the role.
- Higher-risk positions (e.g., system administrators, financial officers, legal staff) require more thorough background checks.
Step 2: Conduct Background Checks
- Identity Verification: Confirm the candidate’s legal identity (passport, national ID, or driver’s license).
- Employment History Check: Verify past employment, professional references, and roles.
- Criminal Record Check: Ensure there are no legal issues that could pose security risks (based on legal allowances in your country).
- Education & Certifications Validation: Verify academic and professional qualifications, especially for technical and security-related roles.
- Financial Checks (if applicable): For roles involving financial transactions, conduct credit checks to assess potential fraud risks.
Step 3: Document and Maintain Records
- Keep screening records secure and confidential to comply with privacy laws (e.g., GDPR, CCPA).
- Define who has access to screening reports and how they are stored.
Step 4: Re-Screening for High-Risk Roles
- Conduct periodic re-screening for employees in critical security positions (e.g., IT admins, finance, legal teams).
- Implement continuous monitoring for insider threat detection.
How to Comply with ISO 27001 A.6.1 #
- Implement a formal screening policy as part of the hiring process.
- Ensure all hiring managers and HR staff follow standard screening guidelines.
- Regularly update screening criteria based on new threats and regulatory changes.
- Keep records of completed background checks and maintain confidentiality.
How to Pass an Audit #
Key Documents to Prepare:
- Screening Policy Document
- Background Check Procedures
- Records of Completed Employee Screenings
- Privacy Policy on Handling Screening Data
What the Auditor Will Check:
- Are screening processes documented and followed consistently?
- Do high-risk roles have enhanced screening requirements?
- Are screening records securely stored and protected under privacy regulations?
Top 3 Mistakes Organizations Make #
- Skipping Screening for Contractors – Third-party workers with access to sensitive data should also be screened.
- Not Defining Role-Based Screening Levels – Applying the same level of screening for all roles wastes resources and creates gaps in security.
- Ignoring Periodic Re-Screening – Employee circumstances change; organizations should conduct re-screening for critical roles.
ISO 27001 Screening FAQ #
Q1: Is screening mandatory for all employees?
Screening should be risk-based. High-risk roles require more thorough screening, while lower-risk positions may have minimal checks.
Q2: Can an organization skip criminal record checks?
This depends on local laws. Some countries restrict access to criminal history, while others allow checks for specific job roles.
Q3: How can organizations ensure compliance with privacy laws when screening?
- Obtain consent before conducting checks.
- Limit the data collected to what is necessary for the role.
- Securely store and encrypt screening records.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.6.1 Screening | Preventive, Risk-Based, Operational |
| Purpose | Prevent security incidents and ensure trustworthy personnel handling sensitive data |
| Applicability | Applicable to all employees and contractors with access to sensitive information or systems |
| ISO 27001 Domains | People Management, Human Resources Security |
Screening is the first line of defense against insider threats and fraud. Organizations must ensure they have structured, risk-based, and legally compliant background verification processes. By hiring trustworthy employees, businesses can reduce security risks and strengthen overall information security.