A.6.6A.6 People controls

Confidentiality or non-disclosure agreements

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.6.6 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Keep information accessible to staff or outside parties confidential.

How to meet this control

In short: Identify, document and review NDA requirements.

  1. Step 01Maintain a library of NDA and confidentiality templates covering employees, contractors and third parties, each scaled to the sensitivity of the information
  2. Step 02Require an NDA before granting any external party access to confidential or client data, tracked in the vendor or contract register
  3. Step 03Define in each agreement exactly what information is protected, the permitted use, the duration and what happens to the data at the end
  4. Step 04Include obligations to report unauthorised disclosure and the consequences of breach, plus audit rights for highly sensitive engagements
  5. Step 05Review NDA wording periodically against current Australian law and update expired or outdated agreements
  6. Step 06Store signed agreements centrally so they can be retrieved and enforced

Tip: Use NDAs for staff and third parties handling confidential information.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Identify, document, review and have people sign confidentiality agreements reflecting protection needs
  • ›Use legally enforceable terms set on the type, classification and permitted access of the information
  • ›Define exactly what information must be protected
  • ›State how long the agreement lasts and what happens when it ends, including return or destruction
  • ›Set out signatories' duties to prevent unauthorised disclosure and define permitted use
  • ›Address ownership of information, trade secrets and IP, and include audit rights for sensitive cases
  • ›Define how unauthorised disclosure is reported and the actions to take if the agreement is breached
  • ›Check agreements comply with the relevant law and review them periodically

Audit evidence to keep

  • - Signed NDAs for a sample of staff and third parties
  • - The NDA or confidentiality agreement templates
  • - A register linking each external party to its signed confidentiality agreement
  • - Records of the periodic review of NDA terms
  • - An agreement showing defined protection scope, duration and end-of-term handling

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.6.6. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all people controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.