Blog
Articles and resources on information security, compliance, and best practices.
ISO 27001 Control A.6.3: Information Security Awareness, Education and Training
Annex A control 6.3 requires staff to receive appropriate security awareness, education and training. How to build a programme that changes behaviour and evidences it for audit.
ISO 27001 Control A.6.4: Disciplinary Process
Annex A control 6.4 requires a formal, communicated disciplinary process for security violations. How to build one that is fair, lawful, and gives your other controls teeth.
ISO 27001 Control A.6.5: Responsibilities After Termination or Change of Employment
Annex A control 6.5 requires security duties that survive a role change or exit to be defined and enforced. How to run secure offboarding and what auditors check.
ISO 27001 Control A.6.6: Confidentiality or Non-Disclosure Agreements
Annex A control 6.6 requires identified, documented, reviewed and signed NDAs. What a good confidentiality agreement covers, who signs, and what auditors expect.
ISO 27001 Control A.6.7: Remote Working
Annex A control 6.7 requires security measures for work done outside the organization's premises. How to secure remote and hybrid work and what auditors check.
ISO 27001 Control A.6.8: Information Security Event Reporting
Annex A control 6.8 requires a timely mechanism for staff to report security events. How to build reporting channels people actually use, and what auditors check.
ISO 27001 Control A.6.2: Terms and Conditions of Employment
Annex A control 6.2 requires employment agreements to state security responsibilities. What to put in the contract, how to cover contractors, and what auditors expect to see.
ISO 27001 Control A.6.1: Screening
Annex A control 6.1 requires background verification of people before they join and on an ongoing basis. How to screen proportionately, stay lawful, and evidence it for audit.
ISO 27001 Clause 10.2: Nonconformity and Corrective Action
Clause 10.2 governs how you handle things that go wrong in the ISMS. The difference between correction and corrective action, how to do root cause properly, and what auditors check.
ISO 27001 Clause 10.1: Continual Improvement
Clause 10.1 requires you to continually improve the ISMS. What continual improvement means in practice, how to evidence it, and why the 2022 revision put it first in Clause 10.