Confidentiality or non-disclosure agreements
Purpose
Keep information accessible to staff or outside parties confidential.
How to meet this control
In short: Identify, document and review NDA requirements.
- Step 01Maintain a library of NDA and confidentiality templates covering employees, contractors and third parties, each scaled to the sensitivity of the information
- Step 02Require an NDA before granting any external party access to confidential or client data, tracked in the vendor or contract register
- Step 03Define in each agreement exactly what information is protected, the permitted use, the duration and what happens to the data at the end
- Step 04Include obligations to report unauthorised disclosure and the consequences of breach, plus audit rights for highly sensitive engagements
- Step 05Review NDA wording periodically against current Australian law and update expired or outdated agreements
- Step 06Store signed agreements centrally so they can be retrieved and enforced
Tip: Use NDAs for staff and third parties handling confidential information.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Identify, document, review and have people sign confidentiality agreements reflecting protection needs
- ›Use legally enforceable terms set on the type, classification and permitted access of the information
- ›Define exactly what information must be protected
- ›State how long the agreement lasts and what happens when it ends, including return or destruction
- ›Set out signatories' duties to prevent unauthorised disclosure and define permitted use
- ›Address ownership of information, trade secrets and IP, and include audit rights for sensitive cases
- ›Define how unauthorised disclosure is reported and the actions to take if the agreement is breached
- ›Check agreements comply with the relevant law and review them periodically
Audit evidence to keep
- - Signed NDAs for a sample of staff and third parties
- - The NDA or confidentiality agreement templates
- - A register linking each external party to its signed confidentiality agreement
- - Records of the periodic review of NDA terms
- - An agreement showing defined protection scope, duration and end-of-term handling
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.6.6. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.