A6.6 Confidentiality or non-disclosure agreements
3 min read
Confidentiality or Non-Disclosure Agreements (NDAs) are essential tools for protecting sensitive organizational information from being misused, leaked, or disclosed without authorization. ISO/IEC 27001 Control A6.6 Confidentiality or non-disclosure agreements requires organizations to ensure that all relevant personnel—employees, contractors, third-party partners—are aware of and bound by confidentiality obligations during and after their relationship with the organization.
This control strengthens the organization’s legal and operational safeguards by holding individuals accountable for securing confidential data and intellectual property.
Implementation Guide #
- Define the Scope of Confidentiality
- Clearly identify the types of information considered confidential (e.g., customer data, source code, financial records, trade secrets).
- Define the boundaries: What is allowed, what is restricted, and under what conditions information can be shared.
- Prepare Standard NDA Templates
- Develop standardized NDA templates for employees, third-party vendors, consultants, and temporary workers.
- Customize agreements to reflect job roles, departments, or access levels where applicable.
What to Include in an NDA:
- Definition of confidential information
- Duration of the confidentiality obligation (e.g., 2 years after termination)
- Permitted disclosures (e.g., legal obligations, court orders)
- Consequences of breach
- Responsibilities for return or destruction of information upon exit
- Ensure Timely Signing of Agreements
- NDAs should be signed before granting access to any sensitive data, systems, or projects.
- Agreements should be revisited and renewed when roles or responsibilities change.
- Store and Track Signed Agreements
- Maintain a secure and centralized repository (digital or physical) for all signed NDAs.
- Use HR or contract management systems to track the status and renewal dates.
Tools that Help:
- Document management systems (DocuSign, Adobe Sign, PandaDoc)
- HR platforms (BambooHR, Zoho People, Workday)
- Educate Staff on Their Obligations
- Regularly train employees and contractors on what constitutes confidential information.
- Make sure they understand their responsibilities and the legal consequences of a breach.
Compliance with ISO 27001 A.6.6 #
To comply with this control:
- Establish a confidentiality policy and communicate it clearly to all parties.
- Implement NDAs for all individuals with access to non-public information.
- Retain signed agreements as part of employment or vendor records.
- Periodically review and update NDA templates to meet evolving legal and business needs.
How to Pass an Audit #
Documents Auditors May Request:
- Confidentiality or NDA policy
- NDA templates used for different roles
- Records of signed NDAs (employees, vendors, contractors)
- Training materials or records of awareness programs
Auditors Will Check:
- Are NDAs consistently applied across the organization?
- Is there evidence that NDAs are signed before access is granted?
- Are there procedures to handle NDA violations or breaches?
Common Pitfalls #
- Using outdated NDA templates that don’t cover modern threats like cloud storage or data sharing apps.
- Granting system or project access before the NDA is signed.
- Failing to include subcontractors who may indirectly access data.
- Not reminding staff of their obligations after termination.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.6.6 Confidentiality or Non-Disclosure Agreements | Preventive, Legal, Human Resource Management |
| Purpose | Ensure sensitive information remains protected during and after employment or service |
| Applicability | All internal and external personnel with access to confidential information |
| ISO 27001 Domains | Human Resource Security, Legal & Compliance |
NDAs are not just legal paperwork—they are a strategic component of your information security framework. A well-designed and enforced confidentiality agreement helps minimize the risk of data leaks, supports compliance with privacy regulations, and reinforces the organization’s security culture.