Skip to content
arrow_back
search
Annex A 6.6 verified ISO/IEC 27001:2022

Confidentiality and Non-disclosure Agreements

Ensure all relevant parties sign agreements to protect confidential information.

record_voice_over

Plain language

This control makes sure that anyone who has access to confidential information, like employees or partners, signs an agreement to keep that information secret. It's important because without these agreements, sensitive information could be shared, leading to competitive harm or legal trouble.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

People controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
verified ISO/IEC 27001:2022 Annex A 6.6
priority_high

Why it matters

Without confidentiality/NDAs, staff and third parties may disclose sensitive information, causing legal action, competitive harm and loss of customer trust.

settings

Operational notes

Maintain a register of required confidentiality/NDAs, ensure onboarding/contracting includes signature capture, and review clauses at least annually for legal and business changes.

Mapping detail

Mapping

Direction

Controls