ISO 27001 A.6.2: Terms and conditions of employment
What This Control Requires
The employment contractual agreements shall state the personnel's and the organization's responsibilities for information security.
In Plain Language
If an employee leaks confidential data and their contract says nothing about security responsibilities, you have a very weak position legally. This control ensures that employment contracts and agreements spell out information security obligations clearly for both sides.
On the employee side, contracts should cover the obligation to follow security policies, the responsibility to protect organisational information, confidentiality obligations that survive after they leave, and the consequences of non-compliance. On the organisation's side, commitments like providing security training and the necessary tools should also be documented.
This applies to everyone who touches your data - permanent employees, contractors, and temporary staff alike. The specific agreement type varies (employment contract versus service agreement), but the principle is the same: security responsibilities must be formally documented in a binding agreement.
How to Implement
Work with HR and legal to review and update your employment contracts and engagement agreements with proper information security clauses. Make sure the clauses are enforceable in your jurisdiction.
Key clauses to include: obligation to comply with information security policies and procedures, acknowledgment of responsibility for protecting organisational information and assets, specific confidentiality obligations covering company data, client data, and trade secrets, a prohibition on disclosing or misusing information obtained during employment, intellectual property assignment for work-related creations, obligation to report security incidents and policy violations, agreement to return all organisational assets on termination, and consequences for security policy violations.
Put a separate confidentiality or non-disclosure agreement (NDA) in place that extends beyond the employment period. Define how long post-employment confidentiality lasts - typically 2-5 years, or indefinitely for trade secrets. Make sure it covers all types of confidential information the person may encounter.
For contractors and third-party personnel, include equivalent security clauses in service agreements or require separate confidentiality agreements. Ensure staffing agencies include appropriate security terms in their own agreements with the people they provide.
Get signed agreements before granting access to information and systems. Maintain a register tracking all signed agreements and chase up any gaps. When agreements are updated, get personnel to review and re-sign.
Include security responsibilities in job descriptions to reinforce the contractual obligations. Review agreements periodically to keep them aligned with current policies and legal requirements.
Evidence Your Auditor Will Request
- Employment contract templates showing information security clauses
- Signed employment contracts with security terms for recent hires
- Confidentiality and non-disclosure agreements for all personnel
- Contractor and third-party service agreements with security obligations
- Register tracking signed agreements and completion status for all personnel
Common Mistakes
- Employment contracts do not include specific information security responsibilities
- Confidentiality agreements do not extend beyond the employment period
- Contractors and temporary staff do not sign security agreements before starting work
- Agreements are outdated and do not reflect current security policies
- No tracking mechanism to ensure all personnel have signed required agreements
Related Controls Across Frameworks
| Framework | Control ID | Relationship |
|---|---|---|
| SOC 2 | SOC 2 CC1.4 (related mapping) | Related |
| GDPR | GDPR Art.28(3)(b) (partial overlap mapping) | Partial overlap |
| GDPR | GDPR Art.32 (partial overlap mapping) | Partial overlap |
Frequently Asked Questions
What happens if we cannot change existing employment contracts?
Should security responsibilities be included in the contract or in a separate agreement?
Related Articles
The True Cost of Compliance: DIY vs Consultant vs Platform (2026)
A realistic comparison of three compliance approaches - DIY spreadsheets, hiring a consultant, or using a platform - with costs, timelines, and tradeoffs.
Read article →ISO 27001 Certification Cost in 2026: A Realistic Breakdown
A detailed breakdown of ISO 27001 certification costs in 2026 - audit fees, consultant costs, tooling, internal time, and practical tips to reduce spend.
Read article →How to Get ISO 27001 Certified: A Step-by-Step Guide
A practical walkthrough of the ISO 27001 certification process - from scoping to stage 2 audit. Covers timelines, costs, common mistakes, and what auditors actually look for.
Read article →Track ISO 27001 compliance in one place
AuditFront helps you manage every ISO 27001 control, collect evidence, and stay audit-ready.
Start Free Assessment