ISO 27001 Control A.6.2: Terms and Conditions of Employment

· 6 min read · Lyudmil Arkov

Control A.6.2 turns a good intention - “our people are responsible for security” - into a contractual obligation. It requires the employment agreement to state, in writing, both the personnel’s and the organization’s responsibilities for information security. This is what makes security enforceable rather than aspirational: if an obligation is not in the contract, holding someone to it later is far harder, and the disciplinary process has nothing to stand on. A.6.2 is a preventive people control, and it works hand in hand with the screening you completed before the person joined. This is the second control in our walk through Annex A.

What the control requires

Annex A control 6.2 of ISO 27001:2022 states that the employment contractual agreements shall state the personnel’s and the organization’s responsibilities for information security.

Two points are easy to miss:

  • Both directions. The agreement states the individual’s responsibilities and the organization’s. It is not only a list of duties imposed on the employee; the organization also commits to its side, such as providing training and communicating policies.
  • Contractual. The obligations live in the employment agreement or an equivalent binding document, not only in a policy the person may never have read. Policies can change; the contract creates the enforceable link to them.

A.6.2 is preventive: setting clear obligations up front reduces the chance of mishandling and gives the organization a firm basis to act if obligations are breached. As always, Annex A states the control and your Statement of Applicability records how you meet it; ISO 27002 holds the detailed guidance.

How to implement terms and conditions

Put a security clause in every employment agreement

The cleanest implementation is a standard information security clause in the employment contract (or an onboarding agreement that the contract references). It does not need to be long, but it should:

  • Require compliance with the organization’s information security policy and topic-specific policies
  • State the duty to protect information the person accesses, in line with its classification
  • Reference confidentiality obligations (with the detail in the NDA under A.6.6)
  • Note that obligations relevant to security continue after employment ends, where lawful
  • Point to the disciplinary consequences of breach

Reference policies rather than freezing them into the contract

You want the contract to bind the person to your policies as they evolve, without needing a contract amendment every time a policy changes. The usual approach is a clause requiring adherence to “the organization’s information security policies as amended from time to time,” with the policies themselves maintained separately under documented information control. That keeps the binding obligation stable while the detail stays current.

State the organization’s responsibilities too

Because the control is explicitly two-directional, reflect the organization’s commitments: providing awareness, education and training (A.6.3), communicating policies, and giving people the tools to meet their obligations. This is not just box-ticking - it is fairer and it strengthens any later enforcement, because the organization can show it upheld its side.

Cover contractors and temporary staff equivalently

Contractors rarely sign your employment contract, so their security obligations must be captured another way - in the contractor agreement, a statement of work, or a signed acceptable-use and confidentiality undertaking. Auditors expect equivalent coverage regardless of employment status. Anyone with access needs a binding statement of their security responsibilities.

Capture acknowledgement as evidence

The control is evidenced by the agreements themselves plus proof the person accepted them. A signed contract, a countersigned onboarding pack, or a dated policy-acknowledgement record all work. For new joiners, fold acknowledgement into onboarding so it is never skipped.

A.6.1 and A.6.6. Terms and conditions sit between screening (verify the person) and confidentiality agreements (A.6.6, the detailed NDA). Together they form the pre-access trust package.

A.6.3 connection. The organization’s side of the agreement - to train and inform - is delivered through awareness, education and training (A.6.3).

A.6.5 connection. Obligations that survive the end of employment, referenced here, are enforced through responsibilities after termination or change of employment (A.6.5).

Clause 5.2 connection. The contract binds people to the information security policy; the policy is what the obligation actually points at.

Clause 7.3 connection. Awareness ensures people understand the obligations they signed up to, so the contractual duty is not just words on a page.

What auditors check

Security is actually in the agreement. Auditors sample employment contracts or onboarding agreements and look for an information security clause. A policy that merely exists somewhere, with no contractual link, is weaker.

Both directions are covered. They check that the agreement reflects the organization’s responsibilities as well as the individual’s, matching the wording of the control.

Contractors are covered equivalently. Auditors specifically look at how non-employees are bound, since this is where coverage often falls away.

Acknowledgement is evidenced. They want proof people accepted the terms - signatures or dated acknowledgements - not just a template that exists in HR.

The link to policies holds. Auditors check that the contract meaningfully binds people to current policies, rather than referencing a document that has since been replaced.

Common mistakes to avoid

Relying on policy alone. Having an information security policy but never referencing it in any binding agreement leaves obligations unenforceable. The control specifically wants the contractual link.

One-directional clauses. Listing only the employee’s duties and omitting the organization’s responsibilities misses the explicit two-way wording of A.6.2.

Contractors left out. Binding employees but giving contractors access with no equivalent undertaking is the most common gap auditors find here.

No acknowledgement record. A great clause with no evidence anyone accepted it is hard to enforce and hard to audit. Capture acceptance at onboarding.

Freezing policies into contracts. Quoting a policy verbatim in the contract means every policy change needs a contract change. Reference policies as amended from time to time instead.

Ignoring post-employment obligations. Failing to note that confidentiality and certain duties continue after departure creates a gap that A.6.5 then cannot cleanly close.

How 27kay can help

We help organizations turn security responsibilities into clean, enforceable contractual terms that cover employees and contractors alike. As part of ISO 27001 implementation, we draft the information security clauses, connect them to your policy set and confidentiality agreements, and build acknowledgement into onboarding so the evidence is there when the auditor asks. For the full picture, see our ISO 27001 knowledge hub.

Unsure whether your contracts actually bind people to your security policies? Get in touch - we will review your employment and contractor agreements and close any gaps before your audit does.