ISO 27001 People controls
The 8 people controls cover the human side: screening, employment terms, awareness, and what happens when people join, move, or leave.
Screening
Confirm that everyone hired is appropriate for their role and stays appropriate throughout their employment.
Guidance and how to meet it →Terms and conditions of employment
Make sure staff understand the security responsibilities tied to the roles they are taking on.
Guidance and how to meet it →Information security awareness, education and training
Ensure staff and relevant outside parties know about and carry out their information security duties.
Guidance and how to meet it →Disciplinary process
Make consequences of security violations clear, deter breaches and deal fairly with anyone who breaks the rules.
Guidance and how to meet it →Responsibilities after termination or change of employment
Protect the organisation's interests when someone leaves or changes their job or contract.
Guidance and how to meet it →Confidentiality or non-disclosure agreements
Keep information accessible to staff or outside parties confidential.
Guidance and how to meet it →Remote working
Keep information secure when staff are working away from the organisation premises.
Guidance and how to meet it →Information security event reporting
Enable staff to report security events they notice in a timely, consistent and effective way.
Guidance and how to meet it →