A6.5 Responsibilities after termination or change of employment
2 min read
When an employee leaves an organization or transitions to a new role, security risks don’t end—they evolve. Uncontrolled access to company systems, forgotten accounts, or lingering privileges can lead to data breaches, insider threats, and compliance violations.
ISO 27001 A6.5 Responsibilities after termination or change of employment ensures that organizations properly revoke access, retrieve assets, and enforce post-employment obligations to maintain security.
Implementation Guide #
Step 1: Define Clear Offboarding Procedures
A structured offboarding process should include:
- Immediate termination of access rights to systems, networks, and cloud services.
- Collection of company assets, such as laptops, mobile devices, ID cards, and access tokens.
- Review of ongoing security responsibilities, such as NDAs and data handling restrictions.
- Exit interviews to reinforce security awareness and identify any potential risks.
Step 2: Revoke Access to IT Systems Promptly
- Disable Active Directory accounts, VPN access, and email accounts.
- Remove access to shared drives, cloud storage (Google Drive, OneDrive, Dropbox), and internal platforms.
- Deactivate Multi-Factor Authentication (MFA) tokens, badges, and remote access tools.
- Update passwords for shared accounts if the departing employee had access.
Tools for Access Revocation:
- Identity & Access Management (IAM) solutions (Okta, Microsoft Entra ID, CyberArk).
- Privileged Access Management (PAM) tools (BeyondTrust, One Identity, HashiCorp Vault).
- HR and IT workflow automation tools (Workday, BambooHR, ServiceNow).
Step 3: Retrieve Company Assets
- Recover all devices, external drives, security tokens, and ID cards.
- Wipe and re-image laptops and mobile devices before reassignment.
- Check for unauthorized copies of sensitive data (USB drives, personal cloud accounts).
Tools for Asset Management:
- Mobile Device Management (MDM) solutions (Microsoft Intune, Jamf, VMware Workspace ONE).
- Enterprise Asset Management (EAM) tools (Asset Panda, Freshservice).
Step 4: Enforce Confidentiality Agreements & Legal Compliance
- Ensure the employee is aware of their post-employment obligations, such as:
- Non-Disclosure Agreements (NDAs).
- Intellectual property protection clauses.
- Data retention and deletion policies.
- Monitor for unauthorized access attempts after termination.
Solutions for Monitoring Former Employees:
- User Behavior Analytics (UBA) tools (Splunk UEBA, Exabeam, Microsoft Defender for Identity).
- DLP solutions (Forcepoint, Symantec DLP, McAfee Total Protection).
Example Scenario #
Situation: A software developer resigns but retains access to the company’s GitHub repository. Months later, a competitor releases a similar product.
Action Taken:
- Access logs show unauthorized downloads from the employee’s account.
- Incident response team investigates and finds that access was never revoked.
- Mitigation: IAM policies are updated to enforce automatic access revocation.
How to Comply with ISO 27001 A.6.5 #
- Implement standardized offboarding checklists for IT and HR.
- Use automated access revocation tools to ensure no lingering permissions.
- Conduct exit interviews to reinforce security responsibilities.
- Enforce NDAs and security policies post-employment.
How to Pass an Audit #
Key Documents to Prepare:
- Employee offboarding policy outlining security responsibilities.
- Records of access revocation for past employees.
- Asset return logs for company-owned devices.
- Legal agreements (NDAs, confidentiality clauses).
What the Auditor Will Check:
- Are access rights removed immediately after employment ends?
- Are employees aware of their security responsibilities post-termination?
- Does the organization track and retrieve company assets properly?
Common Mistakes to Avoid #
- Delayed Access Revocation – Even a few days of lingering access can lead to data leaks.
- Failure to Retrieve Devices – A lost company laptop can be a security nightmare.
- Ignoring Contractors & Third-Parties – Vendors and temporary workers also need strict offboarding.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.6.5 Responsibilities After Termination | Preventive, Governance, Compliance |
| Purpose | To ensure secure termination and role changes |
| Applicability | All employees, contractors, third parties |
| ISO 27001 Domains | HR Security, Access Control |
A weak offboarding process creates security blind spots. Organizations must act swiftly to revoke access, retrieve assets, and remind former employees of their obligations.
Action Step: Review your termination process today—are you leaving security gaps?