Skip to content
arrow_back
search
Annex A 6.2 verified ISO/IEC 27001:2022

Terms and conditions of employment for security

Ensure job agreements state everyone's info security duties clearly.

record_voice_over

Plain language

This control is about making sure everyone's job agreements, like contracts, clearly explain what they need to do to protect the organisation's information. It's important because if people don't understand their responsibilities, they might accidentally jeopardise sensitive data or cause a security breach.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

People controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The employment contractual agreements shall state the personnel’s and the organization’s responsibilities for information security.
verified ISO/IEC 27001:2022 Annex A 6.2
priority_high

Why it matters

If employment agreements omit information security duties, personnel may mishandle data, causing breaches, compliance failures and loss of trust.

settings

Operational notes

Review and update employment contracts at onboarding and periodically to include clear information security responsibilities, confidentiality and reporting duties.

Mapping detail

Mapping

Direction

Controls