ISO 27001:2022
People controls – ISO 27001:2022

ISO 27001:2022 6.6: Confidentiality or non-disclosure agreements

Confidentiality or non-disclosure agreements that match the organization's information protection needs are to be identified, written, reviewed regularly and signed by staff and by the outside parties concerned. Purpose (stated in ISO/IEC 27002:2022): maintains the confidentiality of information that personnel or external parties can access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 6.6.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 38 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

HIPAA Security Rule · 3 controls

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 164.308(b)(3) Written Contract or Other Arrangement
  • 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties

C5 (Germany) · 2 controls

  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • C5-HR-06 Confidentiality agreements

FedRAMP High · 2 controls

  • PL-4 Rules of Behavior
  • PS-6 Access Agreements

FedRAMP Moderate · 2 controls

  • PL-4 Rules of Behavior
  • PS-6 Access Agreements

ISO 27701:2019 · 2 controls

  • 6.4 Human resource security
  • 6.6 Access control
  • ISO-17025-4.2 Confidentiality
  • 4.2 Confidentiality
  • 25012-Confidentiality Confidentiality
  • ISO-25012-4.8 Confidentiality

PCI DSS 4.0 · 2 controls

  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 3.7.8 3.7.8 Key custodians formally acknowledge responsibilities

AICPA SOC 3 · 1 control

  • SOC3-CONFID Confidentiality

APPI · 1 control

  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure

EU AI Act · 1 control

  • EUAI-Art.61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor

ISO 27001:2013 · 1 control

  • A.13.2.4 Confidentiality or non-disclosure agreements

ISO 27002:2022 · 1 control

  • 6.6 Confidentiality or non-disclosure agreements
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

NY DFS 23 NYCRR 500 · 1 control

  • 30(4) Art. 30(4) Ensure health data are processed only by persons bound to confidentiality

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in People controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 6.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.