ISO 27001:2022
People controls – ISO 27001:2022

ISO 27001:2022 6.2: Terms and conditions of employment

Employment contracts and agreements are to set out the information security responsibilities of both the individual and the organization. Purpose (stated in ISO/IEC 27002:2022): makes personnel understand what their roles demand of them for security. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.2.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 40 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 6.2 Information security policies
  • 6.4 Human resource security
  • 6.4.1 Prior to employment
  • 6.4.2 During employment

SOC 2 · 3 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)

C5 (Germany) · 2 controls

  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • C5-HR-02 Employment terms and conditions

FedRAMP High · 2 controls

  • PL-4 Rules of Behavior
  • PS-6 Access Agreements

FedRAMP Moderate · 2 controls

  • PL-4 Rules of Behavior
  • PS-6 Access Agreements

NIST SP 800-53 Rev 5 · 2 controls

APRA CPS 234 · 1 control

  • CPS234-P19 Policy Direction to All Responsible Parties
  • AUCDR-IS-6 Information security training and awareness program
  • MYHR-REG-3 Conditions of registration and participation

CIS Controls v8 · 1 control

  • CIS-6.1 Establish an Access Granting Process

COBIT 2019 · 1 control

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor

ISO 14001:2015 · 1 control

  • 6.2 Environmental objectives and planning to achieve them

ISO 22000:2018 · 1 control

  • 6.2 Objectives of the food safety management system and planning to achieve them

ISO 22301:2019 · 1 control

  • 6.2 Business continuity objectives and planning to achieve them

ISO 27001:2013 · 1 control

  • A.7.1.2 Terms and conditions of employment

ISO 27002:2022 · 1 control

  • 6.2 Terms and conditions of employment

ISO 37001:2016 · 1 control

  • 6.2 6.2 Anti-bribery objectives and planning to achieve them

ISO 37301:2021 · 1 control

  • 6.2 Compliance objectives and planning to achieve them

ISO 45001:2018 · 1 control

  • 6.2 OH&S objectives and planning to achieve them

ISO 55001:2014 · 1 control

  • 6.2 Asset management objectives and planning to achieve them

ISO 9001:2015 · 1 control

  • 6.2 Quality objectives and planning to achieve them

ISO/IEC 42001:2023 · 1 control

  • 6.2 AI objectives and planning to achieve them

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

PCI DSS 4.0 · 1 control

  • 3.7.8 3.7.8 Key custodians formally acknowledge responsibilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 6.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 40 it maps to, and the evidence behind each claim, over MCP and REST.