Run background checks on all new hires before they start work, and conduct periodic re-checks for existing personnel as needed. These checks must comply with local laws, regulations, and ethical standards. The depth and frequency of each check should be proportionate to:
In other words, a janitor doesn’t need the same level of vetting as your Head of AI Security—scale the checks to match the risk.
This control checks if new hires are trustworthy and fit for the job. It includes background reviews before starting and ongoing checks, balanced with laws and risks, to avoid hiring someone who might harm data security.
A company hiring a bookkeeper verifies their resume, references, and criminal record before offering the job, ensuring they can handle financial data safely.
Answer: Screening should be done before joining and periodically afterward, especially for critical roles.
Answer: References, resume accuracy, qualifications, identity, and possibly credit or criminal checks for sensitive positions.
Answer: Include screening requirements in contracts with suppliers.
Employment contracts must clearly spell out what the employee is responsible for regarding information security—and what the organization is responsible for too. This means both sides know exactly who does what to keep data safe.
Job contracts should clearly list security duties for employees and the company. This ensures everyone knows what to do to keep information safe from day one.
A new employee’s contract includes rules like not sharing passwords and reporting lost devices, which they sign before starting.
Answer: Confidentiality agreements, legal responsibilities, asset handling, and actions for disregarding security requirements.
Answer: During the pre-employment process.
Answer: For a defined period, as stated in terms and conditions.
All employees and relevant external parties (e.g., contractors, partners) must receive proper information security training. This includes:
The training should be tailored to what each person actually does in their job—so a developer gets different content than someone in HR, but everyone gets what they need to do their part in keeping the organization secure.
Everyone needs training on security rules to avoid mistakes. This includes regular sessions and updates so staff know how to protect data in their roles.
A shop runs monthly emails and quizzes on spotting phishing, helping staff avoid scams with customer emails.
Answer: Periodically, with initial training for new hires or role changes.
Answer: Management commitment, compliance needs, personal accountability, basic procedures, and contacts for advice.
Answer: Test knowledge at the end of activities.
Establish a documented disciplinary procedure to address information security policy violations by employees or relevant external parties. Ensure this process is communicated to everyone in advance.
Have a clear process for dealing with security rule breaks. It deters problems and handles them fairly, starting after confirming a violation.
If an employee shares a password, the company follows steps like a warning or training, based on how serious it is.
Answer: After verifying a violation has occurred.
Answer: Nature and gravity of the breach, if intentional, repeats, and training received.
Answer: To deter violations and deal with them appropriately.
Define and document all information security responsibilities that continue after employment ends or changes. Ensure these duties are legally enforceable and communicated to the relevant personnel and external parties before the transition occurs.
Even after leaving or changing roles, some security duties continue, like keeping secrets. Define these in contracts to protect company info.
A former manager’s contract says they can’t share client lists for a year after leaving.
Answer: Treat as termination of old role and start of new.
Answer: Identify and transfer to others.
Answer: Use the process when their contract or job ends or changes.
Create documented confidentiality and non-disclosure agreements tailored to your organization’s information protection needs. Review these agreements periodically to keep them current, and ensure they are signed by all employees and relevant external parties who handle sensitive information.
Use agreements to keep sensitive info private. Review them regularly and have everyone sign who needs access.
New hires sign an NDA promising not to share company recipes.
Answer: Definition of protected info, duration, actions on termination, responsibilities, ownership, permitted use, audit rights, reporting process, return terms, and non-compliance actions.
Answer: Periodically and when changes influence requirements.
Answer: Personnel and interested parties like suppliers.
Put security controls in place for remote workers to protect any company information they access, process, or store while working outside the office. This means securing devices, connections, and data the same way you would inside the office—whether they’re working from home, a coffee shop, or on the road.
For home or remote work, set rules to keep data safe, like secure connections and home setup checks.
A firm provides secure laptops and VPNs for staff working from home.
Answer: Physical security, rules for environment, communications, virtual desktops, unauthorized access threats, network use, security measures, equipment support, insurance, backup, audit, and revocation.
Answer: Suitable devices and furniture if privately-owned not allowed.
Answer: Provide hardware/software support and maintenance.
Establish and communicate a formal reporting mechanism that enables personnel to promptly report any observed or suspected information security events through designated channels. Ensure the process encourages timely reporting and protects reporters from retaliation.
Make it easy for staff to report security issues quickly, like strange emails, to stop problems early.
Set up a clear, easy-to-use system for employees to report any security incidents they spot or suspect—quickly and without hassle. Make sure they know exactly which channel to use (e.g., a dedicated email, a hotline, or an internal ticketing system) and that they can report concerns without fear of blame or retaliation.
Answer: To prevent or minimize incidents’ effects.
Answer: Clear procedures, multiple channels, anonymous options, and awareness of what to report.
Answer: Through training and non-punitive culture.