Information security responsibilities start before day one. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on new hires reading a dense policy document weeks after starting, or assuming that employees “just know” their security obligations. Policy acknowledgments are useful, but if your security rules are not anchored in contractual reality from the moment an offer is signed, your legal and operational enforcement options evaporate when a breach occurs. Annex A 6.2 ensures your security expectations hold up under legal and regulatory scrutiny.
ISO 27001:2022 includes Annex A 6.2 to ensure your organisation clearly defines, communicates, and legally enforces information security responsibilities within employment contracts and terms of engagement. This control updates former 2013 requirements (7.1.2) and links contractual terms directly with acceptable use policies, confidentiality obligations, disciplinary frameworks, and pre-access onboarding controls.
Quick Summary: What ISO 27001 Annex A 6.2 Requires
At a practical level, Annex A 6.2 is about embedding information security duties into the legal contract governing an individual’s work. It does not mean writing a 50-page employment contract full of legal jargon; it expects clear, enforceable contractual linkage to your security framework. Here is what you need to do in plain English:
- Embed Security Obligations in Offer Letters & Contracts: State explicitly inside employment agreements that adhering to security policies is a core job responsibility.
- Include Explicit Confidentiality Language: Incorporate non-disclosure and confidentiality obligations that apply during employment and survive departure (Annex A 6.6).
- Link Contracts directly to Security Policies: Reference your Information Security Policy (Annex A 5.1) and Acceptable Use Rules inside employment agreements.
- Clarify Disciplinary Consequences: Explicitly state that deliberate or negligent policy breaches may lead to formal HR disciplinary action or dismissal (Annex A 6.4).
- Require Signed Terms Before System Access: Block IT account provisioning until signed employment terms and policy sign-offs are attached to the HR onboarding record.
- Update Terms Upon Major Role Transitions: Re-evaluate contractual terms when personnel move into higher-risk roles handling sensitive data or privileged access.
Why Policy Assumptions Without Contractual Backing Fail
A policy is a operational guide; a contract is a legal obligation. If an employee or contractor causes a severe data breach, leaks trade secrets, or routinely bypasses security controls, relying solely on an informal policy handbook leaves your business legally vulnerable and unable to enforce disciplinary or legal remedies.
Ignoring terms and conditions of employment controls exposes your business to severe hazards:
- Unenforceable Disciplinary Measures: HR or employment tribunals overturning disciplinary actions or dismissals because security compliance was never formally defined as a contractual duty (Annex A 6.4).
- Unprotected Post-Employment Data Theft: Ex-employees taking customer lists, pricing data, or source code without fear of legal recourse because confidentiality obligations were omitted from base terms (Annex A 6.5).
- Access Granted Before Agreements Are Signed: Onboarding personnel gaining access to production cloud environments or sensitive records before legally agreeing to protect them.
- Contractor & Supplier Access Ambiguity: Third-party personnel operating within your network under generic service statements that lack explicit security and compliance standards (Annex A 8.30).
My 8 Step Plan to Implement Annex A 6.2 Fast
You do not need a massive legal retainer to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready contractual security framework.
1. Incorporate Core Security Duties into Base Employment Templates
Co-author standard employment agreement templates with your HR and Legal teams to include explicit security duties:
- State clearly that protecting organizational assets and following security policies is a primary condition of employment.
- Require employees to take reasonable care to safeguard corporate hardware, credentials, and data in their daily duties.
- Specify that security obligations apply regardless of working location (office, hybrid, or remote) (Annex A 6.7).
2. Embed Binding Confidentiality Clauses
Ensure that confidentiality requirements are explicit inside every offer letter and contract (Annex A 6.6):
- Define what constitutes confidential information (customer PII, financial data, IP, source code, security configurations).
- Prohibit unauthorized disclosure, copying, or removal of confidential information during employment.
- Explicitly state that confidentiality obligations remain legally binding indefinitely or for a defined multi-year period post-employment (Annex A 6.5).
3. Contractually Reference Live Security Policies
Avoid copying transient technical rules directly into employment contracts. Instead, use contractual linkage:
- Include a contractual clause stating that employees agree to comply with the master Information Security Policy and Acceptable Use Policy as updated from time to time.
- Ensure new hires acknowledge receipt of and sign the Acceptable Use Policy during onboarding.
- Maintain clear intranet links so personnel can access the latest approved policy versions at any time (Annex A 5.1).
4. Outline Consequences of Non-Compliance Explicitly
Contractual transparency sets expectations and serves as an effective deterrent against intentional policy evasion:
- Reference your formal HR Disciplinary Policy directly inside employment agreements (Annex A 6.4).
- Clarify that failure to comply with security rules or gross negligence may result in formal warnings, suspension, termination of employment, or legal prosecution.
- Differentiate clearly between accidental human errors (handled via retraining) and intentional policy evasion or gross negligence.
5. Enforce a “No Signed Contract, No Access” Onboarding Gate
Never grant system credentials, physical access badges, or corporate hardware based on verbal promises or pending paperwork:
- Automate HR onboarding workflows to block IT ticket generation until a fully executed, signed employment contract is verified.
- Ensure physical security leads hold access badges (Annex A 7.2) until HR confirms all contractual and NDA prerequisites are met.
- Provision initial system accounts with restricted, minimal permissions until security induction training is completed (Annex A 6.3).
6. Extend Contractual Discipline to Contractors and Temporary Staff
Contractors, freelancers, and third-party staff often handle high-risk systems but bypass standard employee HR workflows:
- Require all independent contractors and agency staff to sign individual Non-Disclosure Agreements (NDAs) prior to onboarding.
- Incorporate explicit information security and data protection schedules into all Statement of Work (SOW) and Master Services Agreements (MSAs) (Annex A 8.30).
- Mandate that third-party personnel adhere strictly to internal Acceptable Use Policies while accessing corporate assets.
7. Re-Evaluate Terms During Major Internal Role Changes
When an employee transitions into a role with significantly higher risk or privileged access, update their terms:
- Review contractual confidentiality and security clauses when staff move into executive, system administrator, HR, or financial roles.
- Require execution of specialized addendums or higher-tier NDAs for personnel gaining access to trade secrets or source code.
- Re-align physical and logical access permissions immediately to match the new role, purging legacy rights (Annex A 8.3).
8. Maintain Centralized, Auditable HR Records
Demonstrate compliance to your auditor by maintaining organized, verifiable records for all personnel:
- Store signed offer letters, employment contracts, NDAs, and policy acknowledgment forms inside a secure, access-controlled HR portal.
- Perform annual spot-check audits of HR files to ensure 100% contract and NDA coverage across active employees and contractors.
- Provide anonymized sample records (e.g., offer letters, policy sign-off logs) as audit evidence during ISO 27001 surveillance audits.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same employment terms mistakes. Here are the main traps and how to solve them:
- Problem: IT Provisioning Full Cloud Access Days Before HR Receives a Signed Contract
Ninja Solution: Implement a hard dependency in your ticketing system blocking IT credential creation until HR checks off the “Contract Signed” gate. - Problem: Employment Contracts Omitting Confidentiality Clauses and Relying on Loose Handbooks
Ninja Solution: Add standard, legally binding confidentiality language directly into your master offer letter and employment contract templates. - Problem: Third-Party Contractors Operating on Oral Agreements Without Signed NDAs
Ninja Solution: Require signed vendor NDAs and security schedules as a mandatory prerequisite in your Procurement onboarding process. - Problem: Contracts Referencing Specific Policy Version Numbers That Become Obsolete Immediately
Ninja Solution: Contractually bind employees to “applicable information security policies as published and updated on the intranet.”
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 6.2 is about setting security expectations that hold up under legal, operational, and regulatory scrutiny. Policies explain how to operate safely, but contractual terms define the legally enforceable boundaries of employment.
By embedding security duties in offer letters, adding binding confidentiality clauses, linking contracts to live policies, clarifying disciplinary consequences, enforcing strict pre-access onboarding gates, extending terms to contractors, and maintaining organized HR audit records, you anchor security in legal reality, protect your assets, and satisfy your ISO 27001 auditor with complete confidence.
