A6.2 Terms and conditions of employment
3 min read
ISO 27001 A6.2 Terms and conditions of employment require organizations to embed information security requirements into employment contracts and ensure that employees acknowledge their obligations before starting their roles. This prevents insider threats, unauthorized data access, and non-compliance with security regulations.
Defining clear terms and conditions of employment is essential to ensure that employees understand their responsibilities regarding information security. Employees, contractors, and third parties with access to an organization’s systems and data must be contractually bound to comply with security policies, confidentiality requirements, and consequences for violations.
Implementation Guide #
Step 1: Define Security Responsibilities in Employment Contracts
Employment contracts should explicitly state:
- Employee responsibilities for protecting sensitive information.
- Acceptable use policies for company resources, including email, internet, and devices.
- Confidentiality and non-disclosure agreements (NDAs) for handling sensitive data.
- Consequences for security breaches, including disciplinary actions or termination.
Step 2: Ensure Legal and Regulatory Compliance
- Align contracts with relevant laws like GDPR, HIPAA, or local labor laws.
- If applicable, include data protection clauses for employees handling personal data.
- Specify conditions for remote work security and device usage.
Step 3: Require Formal Acknowledgment
- Employees must sign an acknowledgment confirming they understand and agree to comply with security policies.
- For contractors and third parties, a separate Information Security Agreement should be signed.
Step 4: Establish a Security Code of Conduct
- Define expected security behaviors (e.g., not sharing passwords, locking workstations).
- Include reporting mechanisms for security incidents or policy violations.
- Set clear consequences for violations to deter non-compliance.
Step 5: Regularly Update Employment Terms
- Update terms and conditions to reflect new security threats, technologies, and regulations.
- Reaffirm employee acknowledgment during annual security training or contract renewals.
Templates #
- Employment Contract Security Clause (covering confidentiality, acceptable use, and policy compliance).
- Non-Disclosure Agreement (NDA) Template.
- Acceptable Use Policy for IT Resources.
- Remote Work Security Agreement (for employees working offsite).
Example #
A company handling financial data requires all employees to sign an NDA and an Acceptable Use Policy before receiving access to internal systems. A contractor working remotely is required to use a company-provided VPN and sign a Remote Work Security Agreement to ensure compliance with security policies.
If an employee violates data security policies, such as sharing customer financial details, disciplinary actions include termination and legal consequences, ensuring strict enforcement of security policies.
How to Comply with ISO 27001 A.6.2 #
✔ Include security obligations in employment contracts and contractor agreements.
✔ Require employees to sign NDAs and policy acknowledgments.
✔ Establish clear disciplinary measures for security violations.
✔ Regularly update policies and communicate changes to employees.
How to Pass an Audit #
Key Documents to Prepare:
- Employee contracts with security clauses.
- Signed NDAs and Acceptable Use Policies.
- Logs of employee acknowledgment of security responsibilities.
- Security training records.
What the Auditor Will Check:
- Are security responsibilities clearly defined in contracts?
- Are employees and contractors aware of their obligations?
- Is there a documented disciplinary process for security violations?
Top 3 Mistakes People Make #
- Not Including Security Clauses in Contracts – Employees may be unaware of security obligations.
- Failure to Update Employment Terms – Security threats evolve, so contracts must be regularly reviewed.
- Ignoring Contractors and Third Parties – External personnel must also comply with security policies.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.6.2 Terms and Conditions of Employment | Preventive, Risk-Based, Operational |
| Purpose | Ensure employees understand and comply with information security policies |
| Applicability | All employees, contractors, and third parties |
| ISO 27001 Domains | People Management, Human Resources Security |
Clearly defined terms and conditions of employment help organizations reduce security risks, enforce compliance, and prevent insider threats. Employees and contractors must be fully aware of their security obligations, which should be reinforced through training and regular updates.