ISO 27001 Annex A People Control

07/30/2026
ISO 27001 Annex A People Control
Reading Time: 5 minutes

ISO 27001 Annex A 6.1 – Screening

Requirements

Run background checks on all new hires before they start work, and conduct periodic re-checks for existing personnel as needed. These checks must comply with local laws, regulations, and ethical standards. The depth and frequency of each check should be proportionate to:

  • The sensitivity of the role,
  • The level of access the person will have to confidential or critical information, and
  • The specific risks associated with that position.

In other words, a janitor doesn’t need the same level of vetting as your Head of AI Security—scale the checks to match the risk.

Explanation

This control checks if new hires are trustworthy and fit for the job. It includes background reviews before starting and ongoing checks, balanced with laws and risks, to avoid hiring someone who might harm data security.

Example

A company hiring a bookkeeper verifies their resume, references, and criminal record before offering the job, ensuring they can handle financial data safely.

FAQ 1: When should screening be performed?

Answer: Screening should be done before joining and periodically afterward, especially for critical roles.

FAQ 2: What should be included in verification checks?

Answer: References, resume accuracy, qualifications, identity, and possibly credit or criminal checks for sensitive positions.

FAQ 3: How to handle screening for supplier personnel?

Answer: Include screening requirements in contracts with suppliers.

ISO 27001 Annex A 6.2 – Terms and Conditions of Employment

Requirements

Employment contracts must clearly spell out what the employee is responsible for regarding information security—and what the organization is responsible for too. This means both sides know exactly who does what to keep data safe.

Explanation

Job contracts should clearly list security duties for employees and the company. This ensures everyone knows what to do to keep information safe from day one.

Example

A new employee’s contract includes rules like not sharing passwords and reporting lost devices, which they sign before starting.

FAQ 1: What should be clarified in contractual obligations?

Answer: Confidentiality agreements, legal responsibilities, asset handling, and actions for disregarding security requirements.

FAQ 2: When should security roles be communicated?

Answer: During the pre-employment process.

FAQ 3: How long do responsibilities continue after employment?

Answer: For a defined period, as stated in terms and conditions.

ISO 27001 Annex A 6.3 – Information Security Awareness, Education and Training

Requirements

All employees and relevant external parties (e.g., contractors, partners) must receive proper information security training. This includes:

  • General awareness training to build a security mindset,
  • In-depth education specific to their role,
  • Regular refreshers on the company’s main security policy, related topic-specific policies, and any procedures they need to follow.

The training should be tailored to what each person actually does in their job—so a developer gets different content than someone in HR, but everyone gets what they need to do their part in keeping the organization secure.

Explanation

Everyone needs training on security rules to avoid mistakes. This includes regular sessions and updates so staff know how to protect data in their roles.

Example

A shop runs monthly emails and quizzes on spotting phishing, helping staff avoid scams with customer emails.

FAQ 1: How often should training take place?

Answer: Periodically, with initial training for new hires or role changes.

FAQ 2: What should awareness programmes cover?

Answer: Management commitment, compliance needs, personal accountability, basic procedures, and contacts for advice.

FAQ 3: How to assess understanding?

Answer: Test knowledge at the end of activities.

ISO 27001 Annex A 6.4 – Disciplinary Process

Requirements

Establish a documented disciplinary procedure to address information security policy violations by employees or relevant external parties. Ensure this process is communicated to everyone in advance.

Explanation

Have a clear process for dealing with security rule breaks. It deters problems and handles them fairly, starting after confirming a violation.

Example

If an employee shares a password, the company follows steps like a warning or training, based on how serious it is.

FAQ 1: When should the disciplinary process start?

Answer: After verifying a violation has occurred.

FAQ 2: What factors influence the response?

Answer: Nature and gravity of the breach, if intentional, repeats, and training received.

FAQ 3: What is the purpose of the process?

Answer: To deter violations and deal with them appropriately.

ISO 27001 Annex A 6.5 – Responsibilities After Termination or Change of Employment

Requirements

Define and document all information security responsibilities that continue after employment ends or changes. Ensure these duties are legally enforceable and communicated to the relevant personnel and external parties before the transition occurs.

Explanation

Even after leaving or changing roles, some security duties continue, like keeping secrets. Define these in contracts to protect company info.

Example

A former manager’s contract says they can’t share client lists for a year after leaving.

FAQ 1: How to manage role changes?

Answer: Treat as termination of old role and start of new.

FAQ 2: What to do with leaving personnel’s security roles?

Answer: Identify and transfer to others.

FAQ 3: How to apply to external personnel?

Answer: Use the process when their contract or job ends or changes.

ISO 27001 Annex A 6.6 – Confidentiality or Non-Disclosure Agreements

Requirements

Create documented confidentiality and non-disclosure agreements tailored to your organization’s information protection needs. Review these agreements periodically to keep them current, and ensure they are signed by all employees and relevant external parties who handle sensitive information.

Explanation

Use agreements to keep sensitive info private. Review them regularly and have everyone sign who needs access.

Example

New hires sign an NDA promising not to share company recipes.

FAQ 1: What elements to include in agreements?

Answer: Definition of protected info, duration, actions on termination, responsibilities, ownership, permitted use, audit rights, reporting process, return terms, and non-compliance actions.

FAQ 2: When to review agreements?

Answer: Periodically and when changes influence requirements.

FAQ 3: Who do agreements apply to?

Answer: Personnel and interested parties like suppliers.

ISO 27001 Annex A 6.7 – Remote Working

Requirements

Put security controls in place for remote workers to protect any company information they access, process, or store while working outside the office. This means securing devices, connections, and data the same way you would inside the office—whether they’re working from home, a coffee shop, or on the road.

Explanation

For home or remote work, set rules to keep data safe, like secure connections and home setup checks.

Example

A firm provides secure laptops and VPNs for staff working from home.

FAQ 1: What to consider in remote working policy?

Answer: Physical security, rules for environment, communications, virtual desktops, unauthorized access threats, network use, security measures, equipment support, insurance, backup, audit, and revocation.

FAQ 2: What equipment to provide?

Answer: Suitable devices and furniture if privately-owned not allowed.

FAQ 3: How to handle support?

Answer: Provide hardware/software support and maintenance.

ISO 27001 Annex A 6.8 – Information Security Event Reporting

Requirements

Establish and communicate a formal reporting mechanism that enables personnel to promptly report any observed or suspected information security events through designated channels. Ensure the process encourages timely reporting and protects reporters from retaliation.

Explanation

Make it easy for staff to report security issues quickly, like strange emails, to stop problems early.

Example

Set up a clear, easy-to-use system for employees to report any security incidents they spot or suspect—quickly and without hassle. Make sure they know exactly which channel to use (e.g., a dedicated email, a hotline, or an internal ticketing system) and that they can report concerns without fear of blame or retaliation.

FAQ 1: Why report events quickly?

Answer: To prevent or minimize incidents’ effects.

FAQ 2: What to include in reporting mechanisms?

Answer: Clear procedures, multiple channels, anonymous options, and awareness of what to report.

FAQ 3: How to encourage reporting?

Answer: Through training and non-punitive culture.

AI Impact Assessment isn’t optional anymore

AI Impact Assessment isn’t optional anymore

Reading Time: 3 minutesIn 2026, with regulations like the EU AI Act and emerging global frameworks tightening, AI impact assessments are mandatory for responsible deployment. Enter ISO/IEC 42005:2025—the first international…
Read more
Starting Your ISO/IEC 42001 Journey

Starting Your ISO/IEC 42001 Journey

Reading Time: 2 minutesBefore building your AI Management System (AIMS), ask: “What is our organization’s role in AI?” ISO/IEC 42001 isn’t one-size-fits-all—it tailors requirements to your spot in the AI…
Read more
ISO 27001 Annex A People Control

ISO 27001 Annex A People Control

Reading Time: 5 minutesISO 27001 Annex A 6.1 – Screening Requirements Run background checks on all new hires before they start work, and conduct periodic re-checks for existing personnel as…
Read more
ISO 9001 Logo_Gabriel Consultant
Gabriel Consultant in ISO Consulting
Service with 20 years of experience.
ISO 14001 Certification logo
Ecovadis_Silver Badge_Gabriel Consultant
EcoVadis_Badges_Approved-Partner-2025
Find Us
© 2024 Gabriel Consultant. All rights reserved
Find Us
ISO 14001 Certification logo
ISO 9001 Logo_Gabriel Consultant
Ecovadis_Silver Badge_Gabriel Consultant
EcoVadis_Badges_Approved-Partner-2025
© 2024 Gabriel Consultant. All rights reserved
Standard

Office Hour: 9:00- 18:00

Tel : +852 23664622

Email : info@gabriel.hk

Free 30 Min Consultation Call

Request an economy and speedy way to get an ISO Certification