# Human resources security policy

Source: https://aestech.com.au/policy-templates/#human-resources-security-policy
Markdown URL: https://aestech.com.au/policy-templates/human-resources-security-policy.md

Use for ISO 27001 A.6.1 to A.6.6, A.6.8, SOC 2 Security, and personnel security controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines the security responsibilities and controls that apply to people before, during and after employment or engagement with the company, so that staff understand and meet their information security obligations.

2. Scope
This policy applies to all employees and contractors throughout their relationship with the company, from recruitment to termination, including changes of role.

3. Policy statements
- Background and identity verification appropriate to the role and to legal limits must be completed before access to sensitive systems is granted.
- Employment and contractor agreements must include information security and confidentiality obligations.
- New starters must receive security awareness training before or shortly after gaining access, and refresher training at least annually.
- Access must be granted according to role and the access control policy, and adjusted promptly on role change.
- On termination or end of engagement, access must be revoked within [x] hours and company assets must be returned.
- A disciplinary process must apply to breaches of security policy, applied consistently and fairly.
- Confidentiality obligations continue after employment ends where appropriate.

4. Roles and responsibilities
- [HR] manages screening, agreements, onboarding and offboarding administration.
- Hiring managers define role requirements and approve access needs.
- IT provisions and revokes access in line with HR triggers.
- The [Security Lead] owns security awareness training and the security elements of the disciplinary process.

5. Procedures
- Complete pre-employment screening proportionate to the role.
- Issue agreements that include security and confidentiality terms.
- Run onboarding that includes security training and acknowledgement of key policies.
- Trigger access changes for joiners, movers and leavers through a defined workflow.
- Recover assets and confirm access removal at offboarding.
- Track training completion and follow up non-completion.

6. Evidence and records
Keep screening records, signed agreements and acknowledgements, training completion records, joiner, mover and leaver tickets, asset return records and disciplinary records where applicable.

7. Review cadence
This policy is reviewed at least annually and after changes to legal or regulatory requirements.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md