We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

ISO/IEC 27001:2022 · Annex A theme 2 of 4 · 8 controls

Annex A.6: People Controls

Eight controls, one theme: the human layer — screening, terms, awareness, discipline, remote working and reporting. Small count, but the controls auditors verify through interviews rather than documents, which is why unprepared organisations fail them in the corridor, not the audit room.

Reviewed by Tanya Kumari, Director — compliance assessment & certification readiness · Part of the Annex A series

The controls that decide your audit

A.6.1
Screening

Background verification proportional to business requirements, data classification and perceived risks — before joining AND on role change.

A.6.2
Terms and conditions of employment

Contracts state information-security responsibilities that survive employment where relevant (confidentiality, IP, return of assets).

A.6.3
Awareness, education and training

Role-appropriate security awareness on joining and at planned intervals, with effectiveness evaluated — not just attendance captured.

A.6.4
Disciplinary process

A formalised, communicated process for security violations — the control that makes policy enforceable.

A.6.5
Responsibilities after termination

Duties that remain valid after exit are defined, communicated and enforced — paired with asset return and access revocation.

A.6.6
Confidentiality / NDA agreements

NDAs for personnel and interested parties, reviewed at planned intervals.

A.6.7
Remote working

Security measures for remote work: device controls, home-network expectations, physical protections — post-2020 this is verified, not assumed.

A.6.8
Event reporting

Personnel report observed or suspected events through an easily reachable channel, in good time — the human sensor network.

Control numbers reference ISO/IEC 27001:2022 Annex A (ISO/IEC 27002:2022 numbering). The 2013→2022 transition ended 31 October 2025 — audits now run against this control set.

Where audits actually fail

Screening claimed, evidence absent

Auditors sample joiners and ask for verification records; "HR does it" without artefacts fails A.6.1 — especially for contractors, who are routinely skipped.

Awareness = one annual slide deck

A.6.3 asks for role-relevant content and effectiveness measurement — phishing-simulation results, quiz outcomes, targeted refreshers.

Staff cannot name the reporting channel

The interview question that decides A.6.8: "you see something suspicious — what do you do?" A hesitant answer outweighs a beautiful procedure document.

Leavers keep knowledge obligations nobody told them about

A.6.5 needs exit communication evidence — a checklist item confirming post-employment duties were restated at departure.

Evidence an auditor accepts

  • Sampled screening records for employees AND contractors (A.6.1)
  • Contract template clauses + signed NDA register (A.6.2/6.6)
  • Training records with role mapping and effectiveness measures (A.6.3)
  • Remote-working policy and technical enforcement evidence (A.6.7)
  • Event-report samples showing the channel works end to end (A.6.8)
  • Exit checklist samples: asset return, access revocation, duty restatement

Annex A.6 FAQ

Does screening apply to contractors and third-party staff?

Yes — A.6.1 covers candidates for employment broadly, and auditors increasingly sample contractor onboarding precisely because it is the common gap.

How often must security awareness training run?

On joining and at planned intervals thereafter (annually in most ISMS), with content appropriate to role and evidence that effectiveness is evaluated (A.6.3).

Is a remote-working policy mandatory?

Where remote working happens, A.6.7 requires implemented security measures — policy plus enforcement (MDM, VPN, disk encryption), verified rather than assumed.

Organizational (A.5)Physical (A.7)

Annex A.6 in your ISMS

We take organisations from gap assessment to certificate — and keep the ISMS audit-ready on SigmaTrust afterwards.