A.6.2 Terms and conditions of employment
- Andy Systems
- ISMS Guides
A.6.2 Terms and Conditions of Employment would include:
-
Employment Contracts: Review of employment contracts for all employees to ensure that they include relevant information related to information security obligations, responsibilities, and expectations.
-
Information Security Policy Acknowledgment: Documentation showing that all employees have acknowledged and agreed to comply with the organization's information security policies as a condition of their employment.
-
Confidentiality Agreements: Records of confidentiality agreements signed by employees, outlining their commitment to maintaining the confidentiality of sensitive information they have access to during their employment.
-
Non-Disclosure Agreements (NDAs): Verification of NDAs signed by employees to prevent them from disclosing proprietary or sensitive information outside of their employment.
-
Employment Screening Results: Evidence that the results of employee screenings, such as background checks, reference checks, and criminal history checks, have been considered in the terms and conditions of employment.
-
Access Rights and Privileges: Documentation of the specific access rights and privileges granted to each employee based on their job role and responsibilities.
-
Employee Training Records: Records of information security training provided to employees and their acknowledgment of completion.
-
Termination Procedures: Documentation of procedures for handling the termination of employment, including the revocation of access rights and retrieval of company-owned devices and information.
-
Reporting Incidents: Proof that employees are aware of their responsibility to report any information security incidents they may encounter during their employment.
-
Compliance with Legal Requirements: Verification that the organization's terms and conditions of employment align with relevant employment laws, industry regulations, and data protection requirements.
-
Periodic Review: Evidence of periodic reviews of employment terms and conditions to ensure they remain up-to-date and reflect any changes in information security practices or regulations.
By reviewing these pieces of evidence, an auditor can assess whether the organization's terms and conditions of employment adequately address information security requirements and whether employees are aware of their responsibilities and obligations regarding the protection of sensitive information. The goal is to ensure that the organization has appropriate measures in place to mitigate the risk of insider threats and unauthorized access, and that employees understand their role in maintaining the overall security posture of the organization.