Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 6.2

Terms and Conditions of Employment: A Practical Implementation Guide

Make information security responsibilities explicit, understandable and enforceable from the start of employment.

This control concerns including relevant information security responsibilities in employment contractual arrangements.

Practical interpretation: A generic confidentiality clause is rarely enough. Terms should reflect role, access, intellectual property, acceptable use, incident reporting and continuing obligations.

What should the control achieve?

  • Security duties are communicated contractually.
  • Terms reflect applicable law and role risk.
  • Changes are acknowledged when responsibilities change.
  • Relevant duties continue after termination.

Step-by-step implementation

1

Define baseline clauses

Cover policy compliance, confidentiality, acceptable use, incident reporting, asset return and monitoring transparency.

2

Tailor sensitive roles

Add privilege, intellectual property, conflict, remote-work or regulatory duties as needed.

3

Align supporting documents

Reference current policies without creating contractual contradictions.

4

Review legally

Ensure enforceability, fairness and jurisdiction-specific requirements.

5

Obtain acceptance

Complete signature or acknowledgement before access.

6

Update and retain

Manage role changes, policy changes and post-employment duties.

What this could look like in practice

A software company uses baseline security clauses for all staff and additional privileged-access obligations for administrators. Contractors sign equivalent confidentiality, IP and asset-return terms before receiving accounts.

ActivityPractical implementationEvidence
OfferApproved terms reflect role tier.Signed agreement
OnboardingEmployee acknowledges referenced policies.Acknowledgement
Role changeNew privileged duties are accepted.Amendment
ExitContinuing confidentiality and return duties are reminded.Exit record

Implementation evidence

  • Approved security clauses
  • Employment templates
  • Contractor terms
  • Signed agreements
  • Policy acknowledgements
  • Role-specific amendments
  • Legal reviews
  • Exit reminders

Useful metrics

  • Personnel with accepted terms before access
  • Outdated contract templates
  • Role changes requiring amendments
  • Missing contractor clauses

Common mistakes

  • Relying only on an employee handbook.
  • Using clauses that conflict with local law.
  • Forgetting contractors, interns and temporary staff.
  • Changing duties without communication.
  • Failing to define obligations after employment.

Questions an auditor may ask

  • Which security duties are contractual?
  • How are role-specific terms selected?
  • Show acceptance before access.
  • Which obligations survive termination?
Implementation test: Sample employees and contractors in different roles and verify signed terms match their current responsibilities.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.