Terms and conditions of employment
Purpose
Make sure staff understand the security responsibilities tied to the roles they are taking on.
How to meet this control
In short: State security responsibilities in employment contracts.
- Step 01Embed an information security clause into the standard employment contract template that binds the worker to the Acceptable Use Policy and the wider ISMS policy set
- Step 02Issue a separate confidentiality or NDA schedule for roles touching client or restricted data, signed before access is provisioned
- Step 03Reference data-protection and intellectual-property obligations explicitly, naming the Privacy Act and the organisation ownership of work product
- Step 04Surface the key security terms during the offer and induction stage so candidates accept them knowingly rather than buried in fine print
- Step 05Run a periodic legal review of contract templates whenever privacy law, the Fair Work Act or internal policy changes, and re-issue updated terms
- Step 06State which obligations, such as confidentiality, survive termination and for how long
Tip: Reference your security policies and confidentiality obligations in the contract.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Build the security policy and topic-specific policies into the contractual obligations placed on staff
- ›Require staff with access to confidential information to sign confidentiality agreements before access
- ›Spell out legal duties and rights, such as those around copyright and data protection law
- ›State responsibilities for classifying information and handling assets and information services
- ›Cover how information from outside parties must be handled, and consequences for ignoring requirements
- ›Communicate security roles and responsibilities to candidates during the pre-employment stage
- ›Review the security terms whenever laws, regulations or internal policies change
- ›Where relevant, make certain responsibilities continue for a defined time after employment ends
Audit evidence to keep
- - A signed employment contract showing the security and confidentiality clauses
- - The contract template with the embedded information security terms
- - A countersigned NDA for a worker in a data-sensitive role
- - Records of the periodic legal or HR review of contract wording
- - Induction acknowledgement confirming the new hire accepted the security terms
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.6.2. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.