Skip to content
compliancebase
ISO 27001A.6 — Confidentiality or non-disclosure agreements

A.6.6

Confidentiality or non-disclosure agreements

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Ensure personnel and relevant third parties acknowledge confidentiality obligations protecting organizational information.

Points of focus

  • NDA or confidentiality clause before access
  • Cover employees and contingent workers
  • Retain signed records
  • Refresh when roles materially change

Implementation notes

Gate IdP provisioning on NDA completion in HRIS. Use standard templates for full-time and contractors. Flow confidentiality into vendor DPAs where they process customer data. Re-acknowledge on promotion into privileged roles if counsel requires.

Audit tip: Sample ten active privileged users and show dated confidentiality acknowledgements. Missing early-employee paperwork is a common finding.

Evidence auditors typically request:

  • Signed NDA or offer-letter confidentiality clause
  • Contractor MSA confidentiality schedule
  • CLM or HRIS record of signature date
  • Access provisioning gated on NDA complete

Common gaps

  • Access granted before signature
  • Vendors without flow-down confidentiality
  • Missing records for early hires

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.6.6This control
SOC 2CC1.1Related SOC 2 themes (CC1.1) — map in your crosswalk; not identical requirements.
GDPRArticle 28, Article 32Related GDPR themes (Article 28, Article 32) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Usually you need an individual acknowledgement or contract clause, not only a shared PDF.

Yes if they can access customer or production data.

Confidentiality duties support Article 32 and processor instructions; they do not replace a DPA.

Even without owned data centers, confidentiality or non-disclosure agreements still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with signed nda or offer-letter confidentiality clause, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above