Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 6.6

Confidentiality or Non-Disclosure Agreements: A Practical Implementation Guide

Use clear confidentiality agreements that match the information, relationship and jurisdiction.

This control concerns identifying, documenting, reviewing and signing confidentiality or non-disclosure agreements that protect organizational information.

Practical interpretation: An NDA is not a substitute for access control or secure handling. It establishes obligations and remedies while operational controls reduce the opportunity for disclosure.

What should the control achieve?

  • Relationships requiring confidentiality terms are identified.
  • Agreements define protected information and permitted use.
  • Terms are signed before disclosure.
  • Agreements are reviewed when risk or law changes.

Step-by-step implementation

1

Identify use cases

Cover employees, contractors, suppliers, partners, candidates and transaction parties.

2

Define protected scope

Describe confidential information, exclusions, purpose and authorized recipients.

3

Set handling duties

Address protection, onward disclosure, incident reporting, return, deletion and compelled disclosure.

4

Define duration and remedies

Match survival periods and consequences to information and law.

5

Execute before access

Track signatures, entities and effective dates.

6

Review and enforce

Update templates, investigate breaches and retain agreement evidence.

What this could look like in practice

A product company uses employment confidentiality clauses, supplier NDAs and a transaction-specific NDA for acquisition discussions. The latter restricts purpose, named advisers, secure transfer and deletion if negotiations end.

ActivityPractical implementationEvidence
EmployeeConfidentiality terms accompany employment agreement.Signed terms
SupplierNDA precedes sharing architecture details.Executed NDA
ProjectPurpose-specific agreement limits recipients and retention.Project agreement
TerminationReturn/deletion and continuing duties are confirmed.Closure record

Implementation evidence

  • NDA policy
  • Approved templates
  • Legal review
  • Signed agreements
  • Agreement register
  • Disclosure approvals
  • Return/deletion evidence
  • Breach records

Useful metrics

  • Required NDAs signed before disclosure
  • Expired or missing agreements
  • Template review completion
  • Confidentiality breaches

Common mistakes

  • Using one template in every country.
  • Defining confidential information impossibly broadly.
  • Signing after disclosure.
  • Failing to bind subcontractors or advisers.
  • Keeping agreements without knowing what was shared.

Questions an auditor may ask

  • When is an NDA required?
  • How are templates selected and reviewed?
  • Show proof the agreement preceded disclosure.
  • How are return and deletion handled?
Implementation test: Select a sensitive external disclosure and verify purpose, recipient, signed terms, secure transfer and end-of-use handling.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.