ISO/IEC 27001:2022 Annex A · Control 6.2
Terms and Conditions of Employment: A Practical Implementation Guide
Make information security responsibilities explicit, understandable and enforceable from the start of employment.
This control concerns including relevant information security responsibilities in employment contractual arrangements.
What should the control achieve?
- Security duties are communicated contractually.
- Terms reflect applicable law and role risk.
- Changes are acknowledged when responsibilities change.
- Relevant duties continue after termination.
Step-by-step implementation
Define baseline clauses
Cover policy compliance, confidentiality, acceptable use, incident reporting, asset return and monitoring transparency.
Tailor sensitive roles
Add privilege, intellectual property, conflict, remote-work or regulatory duties as needed.
Align supporting documents
Reference current policies without creating contractual contradictions.
Review legally
Ensure enforceability, fairness and jurisdiction-specific requirements.
Obtain acceptance
Complete signature or acknowledgement before access.
Update and retain
Manage role changes, policy changes and post-employment duties.
What this could look like in practice
A software company uses baseline security clauses for all staff and additional privileged-access obligations for administrators. Contractors sign equivalent confidentiality, IP and asset-return terms before receiving accounts.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Offer | Approved terms reflect role tier. | Signed agreement |
| Onboarding | Employee acknowledges referenced policies. | Acknowledgement |
| Role change | New privileged duties are accepted. | Amendment |
| Exit | Continuing confidentiality and return duties are reminded. | Exit record |
Implementation evidence
- Approved security clauses
- Employment templates
- Contractor terms
- Signed agreements
- Policy acknowledgements
- Role-specific amendments
- Legal reviews
- Exit reminders
Useful metrics
- Personnel with accepted terms before access
- Outdated contract templates
- Role changes requiring amendments
- Missing contractor clauses
Common mistakes
- Relying only on an employee handbook.
- Using clauses that conflict with local law.
- Forgetting contractors, interns and temporary staff.
- Changing duties without communication.
- Failing to define obligations after employment.
Questions an auditor may ask
- Which security duties are contractual?
- How are role-specific terms selected?
- Show acceptance before access.
- Which obligations survive termination?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.