A.6.2
    People Controls

    Terms and conditions of employment

    The employment contractual agreements should state the personnel's and the organization's responsibilities for information security.

    Purpose

    To ensure personnel understand and accept their information security responsibilities.

    Implementation Guidance

    Include information security responsibilities in employment contracts

    Define consequences of security policy violations

    Include confidentiality and non-disclosure requirements

    Address intellectual property ownership

    Require acknowledgment of security policies

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.6.2 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.6.2 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.6.2 Terms and conditions of employment. Built for compliance professionals.

    Try ISMS Copilot free