ISO 27001A.6 — Responsibilities after termination or change of employment
A.6.5
Responsibilities after termination or change of employment
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Ensure information security responsibilities and access continue to be managed after termination or change of employment.
Points of focus
- Define termination and role-change checklists
- Revoke logical access on effective date
- Recover or wipe company assets
- Confirm completion with dated evidence
Implementation notes
Wire HRIS or offboarding tickets to IdP disable actions with an SLA (same business day for privileged roles). Cover contractors and freelancers. Rotate secrets the leaver could have copied. Keep a checklist owner in security ops and sample completed checklists for Stage 2.
Audit tip: Pick three recent leavers: show HR date, IdP disable time, and asset disposition. Gaps of days between last day and revocation fail.
Evidence auditors typically request:
- HR termination ticket with effective timestamp
- IdP deprovision audit log
- MDM wipe or asset return record
- Privileged key rotation after leaver events
Common gaps
- Access left active days after last day
- Personal devices never wiped
- Shared credentials not rotated on departure
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.6.5 | This control |
| SOC 2 | CC6.2, CC6.3 | Related SOC 2 themes (CC6.2, CC6.3) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.312(a)(1) | Related HIPAA themes (§164.312(a)(1)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.6.5)
Frequently Asked Questions
Same logical controls apply; emphasize MDM wipe and credential rotation because you may never see a badge return.
Eliminate them. If a break-glass account existed, rotate it on every privileged leaver.
No. Termination is an event-driven control; reviews catch drift, they do not replace day-zero revocation.
Even without owned data centers, responsibilities after termination or change of employment still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with hr termination ticket with effective timestamp, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.