A.6.6
    People Controls

    Confidentiality or non-disclosure agreements

    Confidentiality or non-disclosure agreements reflecting the organization's needs for the protection of information should be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.

    Purpose

    To maintain confidentiality of organizational information through legal agreements.

    Implementation Guidance

    Use NDAs for employees, contractors, and third parties

    Define what constitutes confidential information

    Specify duration of confidentiality obligations

    Review and update NDAs regularly

    Maintain signed copies of all agreements

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.6.6 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.6.6 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.6.6 Confidentiality or non-disclosure agreements. Built for compliance professionals.

    Try ISMS Copilot free