Skip to content
compliancebase
ISO 27001A.6 — Terms and conditions of employment

A.6.2

Terms and conditions of employment

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Ensure employment contractual agreements state information security responsibilities for personnel and contractors.

Points of focus

  • Security responsibilities in employment terms
  • Contractor agreements include security clauses
  • Confidentiality / IP as applicable
  • Updates when roles change materially

Implementation notes

Work with HR/legal to embed confidentiality, acceptable use, and security responsibility language in employee and contractor agreements. Gate IdP access on checklist completion (with A.6.1 screening as applicable). When hiring in multiple countries, keep local counsel in the loop. Re-ack security policies on major role changes.

Audit tip: Show that access provisioning requires completed agreements in the JML checklist.

Evidence auditors typically request:

  • Employment agreement templates with security clauses
  • Contractor MSA/SOW security language
  • HR checklist requiring signed terms before access
  • Records of signed agreements (metadata)

Common gaps

  • Contractors access prod on a handshake
  • Security clauses missing from older templates
  • No link between signed terms and IdP provisioning

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.2This control

Primary sources

Frequently Asked Questions

NDAs help confidentiality; still state security behaviour expectations and policy compliance duties.

Use locally appropriate agreements; the ISMS cares that responsibilities are contractual and understood.

A.6.6 focuses on confidentiality/NDA arrangements; A.6.2 is broader employment security terms.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above