ISO 27001A.6 — Terms and conditions of employment
A.6.2
Terms and conditions of employment
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Ensure employment contractual agreements state information security responsibilities for personnel and contractors.
Points of focus
- Security responsibilities in employment terms
- Contractor agreements include security clauses
- Confidentiality / IP as applicable
- Updates when roles change materially
Implementation notes
Work with HR/legal to embed confidentiality, acceptable use, and security responsibility language in employee and contractor agreements. Gate IdP access on checklist completion (with A.6.1 screening as applicable). When hiring in multiple countries, keep local counsel in the loop. Re-ack security policies on major role changes.
Audit tip: Show that access provisioning requires completed agreements in the JML checklist.
Evidence auditors typically request:
- Employment agreement templates with security clauses
- Contractor MSA/SOW security language
- HR checklist requiring signed terms before access
- Records of signed agreements (metadata)
Common gaps
- Contractors access prod on a handshake
- Security clauses missing from older templates
- No link between signed terms and IdP provisioning
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.2 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.2)
Frequently Asked Questions
NDAs help confidentiality; still state security behaviour expectations and policy compliance duties.
Use locally appropriate agreements; the ISMS cares that responsibilities are contractual and understood.
A.6.6 focuses on confidentiality/NDA arrangements; A.6.2 is broader employment security terms.