Under ISO/IEC 27001:2022, Annex A.6 (People Controls) establishes the human resource security requirements. It consists of 8 controls designed to manage personnel security risks before, during, and after employment.
Here is the complete breakdown of these controls, organized by how they apply across the employment lifecycle:
Pre-Employment Controls
A.6.1 Screening
- What it does: Ensures candidates are suitable and trustworthy for their roles.
- Implementation: Background verification checks (such as criminal records, employment history, and academic qualifications) are conducted on all job candidates, contractors, and existing staff changing roles, proportionate to the sensitivity of the data they will access and applicable laws.
A.6.2 Terms and conditions of employment
- What it does: Sets legal expectations for information security from day one.
- Implementation: Employment contracts must explicitly state the information security responsibilities of both the employee and the organization, including compliance with security policies and ongoing legal obligations.
During Employment Controls
A.6.3 Information security awareness, education and training
- What it does: Keeps staff vigilant and skilled at identifying threats.
- Implementation: All personnel and relevant third parties must receive regular awareness training, education, and updates tailored to their specific roles and current threats (e.g., social engineering, phishing, and data handling).
A.6.4 Disciplinary process
- What it does: Ensures accountability and consequences for security violations.
- Implementation: A formal disciplinary process must be clearly communicated and enforced for personnel who commit an information security breach, policy violation, or act of negligence.
A.6.6 Confidentiality or non-disclosure agreements
- What it does: Protects sensitive organizational data through legal safeguards.
- Implementation: NDAs reflecting the need to protect sensitive information must be identified, regularly reviewed, and signed by employees, contractors, and relevant external parties.
A.6.7 Remote working
- What it does: Secures organizational assets and data outside the traditional office.
- Implementation: Security measures, physical controls, and technical guidelines must be established to protect information processed, accessed, or stored while personnel work remotely (from home, public spaces, or while traveling).
A.6.8 Information security event reporting
- What it does: Establishes a reporting channel for vulnerabilities and security incidents.
- Implementation: The organization must provide clear, accessible mechanisms for personnel to report observed or suspected information security events, vulnerabilities, or weaknesses quickly and securely.
Post-Employment Controls
A.6.5 Responsibilities after termination or change of employment
- What it does: Protects organizational assets and revokes access during life-cycle changes.
- Implementation: Clear procedures must be in place to manage, communicate, and enforce security responsibilities and access rights when an employment contract is terminated or significantly changed (such as returning company equipment, revoking software licenses, and disabling badges).
Articles
- ISO 27001 Annex A 6.1 Screening
- ISO 27001 Annex A 6.2 Terms and conditions of employment
- ISO 27001 Annex A 6.3 Information security awareness, education and training
- ISO 27001 Annex A 6.4 Disciplinary process
- ISO 27001 Annex A 6.5 Responsibilities after termination or change of employment
- ISO 27001 Annex A 6.6 Confidentiality or non-disclosure agreements
- ISO 27001 Annex A 6.7 Remote working
- ISO 27001 Annex A 6.8 Information security event reporting
