ISO 27001:2022 Annex A 6.2 Terms of Employment Explained

ISO 27001 Annex A 6.2 Terms and Conditions Of Employment

In this guide you will learn how to implement ISO 27001 Annex A 6.2 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 6.2 Terms and Conditions Of Employment is an ISO 27001 control that requires an organisation to have contracts in place with employees that set out their responsibilities for information security.

Purpose & Definition

The purpose of ISO 27001 Annex A 6.2 is to ensure that employees are fully aware of their information security responsibilities in relation to their role.

ISO 27001 defines ISO 27001 Terms and Conditions of Employment as:

The employment contractual agreements should state the personnel’s and the organisations responsibilities for information security.

ISO 27001:2022 Annex A 6.2 Terms and Conditions Of Employment

FREE ISO 27001 Annex A 6.2 Training Video

In this free training video you will learn How to implement Annex A 6.2 ISO 27001 Terms and Conditions of Employment and Pass Your Audit.

Implementation Guide

General Guidance

You are going to have to

  • engage with a legal professional for professional advice
  • engage with a HR professional for professional advice
  • put in place contracts that include the personnel and the organisations responsibilities for information security
  • ensure you have contractual agreements with all personnel that are legally binding
  • ensure you adhere to all applicable laws and regulations

ISO 27001 Policies

The contract should consider your ISO 27001 policies. That is the main information security policy and any ISO 27001 topic specific policies. Policies are statements of what you do for information security and what is expected of people.

What to include in the employment contract

The following can be considered:

  • NDA, non disclosure agreements
  • confidentiality agreements
  • legal rights

The following are guidance and I am not really sure they sit well in contractual agreements but to be aware that the standard has them as guidance

  • Classification of information
  • management of information
  • management of assets
  • information processing facilities
  • information services
  • handling information you get from third parties and interested parties
  • what actions will be taken if you don’t follow the information security requirements

Communication

You will communicate roles and responsibilities for information security during the pre employment phase of your process.

Agreement

Information security requirements should be agreed which usually is the case of the employee signing the contract and you having a copy of the contract on file.

Appropriateness of terms

You want to make sure that any terms and requirements are appropriate to the person, their role, what they do and the access they have.

Review of terms

As a process of continual improvement be sure to review the terms you have, especially if you change your policies or the laws, or regulations change.

Non Disclosure Agreement

There are certain things that will remain in place after employment and this is usually defined for a set period of time. Consider things like an ISO 27001 non disclosure agreement and confidentiality agreement that you may want in place for 12 months post employment ending.

Employee hand book /code of conduct

Having an employee hand book or code of conduct is a fantastic way to share and communicate information security responsibilities and key messages and I have seen this work well in many organisations.

Employees that come from agency / third party

If you have employees that you do not employ directly but rather you use and agency of third party then the agency of third party should really enter into a contract on behalf of those people.

How to implement ISO 27001 Annex A 6.2

Implementing ISO 27001 Annex A 6.2 requires a structured approach to integrating security obligations into the legal relationship between the organisation and its personnel.

1. Formalise Information Security Clauses in Contracts

Work with Legal and HR departments to ensure that every employment agreement contains explicit security mandates rather than generic references.

  • Incorporate a mandatory requirement for personnel to adhere to the organisation’s Information Security Policy (ISP) and Acceptable Use Policy (AUP).
  • Define the legal and regulatory consequences of security breaches, linking them directly to the organisation’s formal Disciplinary Process.
  • Specify the ownership of intellectual property (IP) and data created during the term of employment.
  • Ensure clauses cover the requirement to report security events or suspected weaknesses immediately.

2. Provision Enforceable Non-Disclosure Agreements (NDAs)

Identify and document specific confidentiality requirements that protect sensitive data before access is granted to any internal or external party.

  • Draft standalone NDAs or confidentiality clauses that define exactly what constitutes “Confidential Information.”
  • Mandate that these obligations “survive” the termination of employment, remaining in force for a defined period or indefinitely.
  • Require signed acknowledgements from all third-party contractors and freelance consultants prior to provisioning their IAM roles.
  • Store all signed digital agreements in a centralised, tamper-proof document management system.

3. Document Responsibilities for Asset Handling

Clearly define the expected conduct for the use, return, and protection of organisational physical and digital assets.

  • Include specific terms regarding the use of Multi-Factor Authentication (MFA) and the protection of authentication credentials.
  • Establish the “Clear Desk and Clear Screen” requirements within the contractual terms of employment.
  • Formalise the legal obligation to return all hardware, security fobs, and ID badges upon the cessation of the business relationship.
  • Outline the restrictions on the use of unauthorised software or personal cloud storage for company data.

4. Formalise the Disciplinary Process Linkage

Ensure that personnel are aware that security failures are treated as professional performance issues subject to formalised sanctions.

  • Integrate the Security Disciplinary Policy with the standard HR disciplinary handbook to ensure consistency.
  • Communicate the “graduated” approach to sanctions, ranging from mandatory retraining for minor negligence to termination for gross misconduct.
  • Provide evidence of this linkage during the initial security induction training for all new starters.

5. Audit and Review Contractual Compliance

Perform regular reviews of personnel files and third-party contracts to ensure all security terms remain current and signed.

  • Conduct an annual review of contract templates to align with new legal requirements, such as GDPR or updated ISO 27001 control sets.
  • Verify that all active personnel have a signed, valid NDA on record through a cross-reference audit with the Register of Entrants (ROE).
  • Revoke access rights immediately for any individual whose contractual status changes or whose agreement has expired.

How to pass the audit

To comply with ISO 27001 Annex A 6.2 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:

  • Write, sign off, implement and communicate your topic specific information security policies
  • Write, sign off, implement and communicate your contract of employment template under the guidance and advice of a HR professional and a legal professional
  • Implement your contract of employment with personnel
  • Implement your communication plan to communicate to relevant and interested parties
  • Ensure that the contract of employment meets all laws as well as local laws and regulations
  • Implement a process of internal audit that checks that the appropriate controls are in place and effective and where they are not follow the continual improvement process to address the risks

To pass an audit of ISO 27001 Annex A 6.2 you are going to make sure that you have followed the steps above in how to comply.

What the auditor will check

The audit is going to check a number of areas for compliance with Annex A 6.2. Lets go through them

1. That you have a documented contract of employment

The auditor will meet with the HR team and look for a documented contract of employment template. They will then seek evidence that the contract of employment is in place by reviewing a sample of employees. They will be checking that the terms of this clause have been met.

2. That you have communicated the terms of employment

The process needs to be communicated to relevant and interested parties. The audit will check that the training and awareness plan and the communication plan and look for past evidence that this has happened.

3. That people are aware of their responsibilities

The audit is going to check for documented processes, documented topic specific policy and these have been communicated and people have been trained on what is required of them. It will check if people have a contract with terms and they understand and accept them.

Top 3 mistakes and how to avoid them

In my experience, the top 3 mistakes people make for ISO 27001 Terms and Conditions of Employment are

1. You have no evidence that anything actually happened

You need to keep records and minutes of everything. You need a paper trail to show it was done. Make sure you have updated contracts for all employees and personnel and that they meet the requirements of this control. In smaller organisations and start ups it is often the case that this is not in place.

2. One or more members of your team haven’t done what they should have done

Prior to the audit check that all members of the team have done what they should have. Do they know where the process documents are in relation to the employment process? Has everyone got a contract and received and accepted terms of employment? Do a pre audit as close to the audit as you can that checks the contract and terms of employment process and the HR team that will be involved. Assuming they are doing the right thing is a recipe for disaster. Check!

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 6.2 FAQ

What information security clauses must be in an employment contract?

Employment contracts must explicitly state the employee’s duty to protect sensitive information and adhere to the organisation’s Information Security Management System (ISMS).
A mandatory requirement to follow all internal security policies and procedures.
Enforceable confidentiality and non-disclosure (NDA) clauses.
Responsibilities for the protection of physical and digital assets.
Acknowledgement of the disciplinary process in the event of a security breach.

Does Annex A 6.2 apply to temporary staff and contractors?

Yes, ISO 27001 Annex A 6.2 applies to all individuals with access to organisational information assets, including third-party contractors, freelancers, and temporary staff.
Agreements with contractors must reflect the same security rigour as permanent staff.
Contractual terms should include the right for the organisation to audit compliance.
Terms must specify that confidentiality duties extend beyond the end of the contract.
Specific clauses should cover the return of assets upon termination of the engagement.

Are Non-Disclosure Agreements (NDAs) required for ISO 27001?

Yes, confidentiality or non-disclosure agreements are a fundamental component of Annex A 6.2 to ensure data protection is legally enforceable.
NDAs should be signed prior to granting any access to sensitive or proprietary data.
The agreement must clearly define what constitutes “confidential information.”
Obligations must remain in force after an individual leaves the organisation.
Copies of signed agreements must be maintained as verifiable audit evidence.

Can an organisation fail an audit due to missing security terms in contracts?

Yes, failing to include specific information security terms in employment or contractor agreements is a common cause of minor non-conformities during ISO 27001 audits.
Auditors perform spot checks on personnel files to verify signed contracts.
Lack of security clauses weakens the legal standing and enforceability of the ISMS.
Contracts must be updated to align with the current ISO 27001:2022 control set.
Evidence of signed NDAs for all relevant third parties is a high-priority audit item.

What is the difference between ISO 27001 Annex A 6.1 and 6.2?

The primary difference is that Annex A 6.1 focuses on the screening of personnel before they join, while Annex A 6.2 focuses on the contractual obligations once they are hired.
Annex A 6.1 (Screening): Identity verification and background checks.
Annex A 6.2 (Terms): Legal contracts and security responsibilities.
Both controls work together to manage human-centric security risks.

ISO 27001 Controls and Attribute values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveAvailability
Confidentiality
Integrity
ProtectHuman resource securityGovernance and ecosystem

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top