ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Human Resources Security Policy

Human Resources Security Policy

1. Purpose

The Human Resources Security Policy establishes the organization’s requirements for managing information-security risks associated with employees, contractors, consultants, interns, temporary workers, and other personnel throughout the employment or engagement lifecycle.

The policy is intended to ensure that personnel:

  • Are appropriately screened based on role and risk
  • Understand their information-security responsibilities
  • Protect organizational and customer information
  • Receive appropriate security awareness and training
  • Receive only authorized access
  • Protect credentials and organizational assets
  • Report security incidents promptly
  • Follow applicable information-security policies
  • Have access removed when no longer required
  • Continue to protect confidential information after termination where applicable

Core Principle

Recruit → Screen → Define Responsibilities → Onboard → Train → Access → Monitor → Change → Offboard


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Interns
  • Temporary workers
  • Agency personnel
  • Third-party personnel
  • Remote workers
  • Personnel with privileged access
  • Personnel with access to customer information
  • Personnel with access to production systems
  • Personnel performing security-sensitive functions

The policy applies throughout the personnel lifecycle.


3. Policy Statement

The organization shall manage personnel-related information-security risks in a manner that is:

  • Risk-based
  • Proportionate
  • Appropriate to the role
  • Consistent with applicable law
  • Consistent with contractual requirements
  • Consistent with customer requirements
  • Appropriate to information sensitivity and system access

Personnel shall be granted access and responsibilities based on legitimate business requirements and shall be expected to protect organizational information and systems.


4. Human Resources Security Objectives

The organization shall establish appropriate controls to:

  1. Identify personnel-security risks.
  2. Assess role sensitivity.
  3. Perform appropriate background verification.
  4. Define security responsibilities.
  5. Communicate security requirements.
  6. Provide appropriate security awareness.
  7. Control access throughout the personnel lifecycle.
  8. Protect confidential information.
  9. Manage contractors and third-party personnel.
  10. Address security violations.
  11. Revoke access when personnel leave or change roles.
  12. Retain appropriate evidence.
  13. Periodically review personnel-security controls.

5. Roles and Responsibilities

5.1 Management

Management shall:

  • Support personnel-security requirements.
  • Provide appropriate resources.
  • Approve significant personnel-security requirements.
  • Ensure significant personnel risks are addressed.

5.2 HR / People Function

HR shall:

  • Coordinate personnel lifecycle processes.
  • Support screening and verification.
  • Maintain appropriate personnel records.
  • Communicate employment-related security requirements.
  • Coordinate onboarding and offboarding.
  • Support disciplinary processes.

5.3 Information Security

Information Security shall:

  • Define security requirements.
  • Assess security risks.
  • Identify sensitive roles with relevant stakeholders.
  • Define security training requirements.
  • Support access and privileged-access requirements.
  • Monitor personnel-related security risks.
  • Support investigations where appropriate.

5.4 Managers

Managers shall:

  • Define business need for access.
  • Identify role responsibilities.
  • Approve appropriate access.
  • Notify HR/IT of role changes.
  • Support timely offboarding.
  • Ensure personnel understand relevant responsibilities.

5.5 Personnel

Personnel shall:

  • Protect organizational information.
  • Follow applicable security policies.
  • Protect authentication credentials.
  • Use systems only for authorized purposes.
  • Report security incidents.
  • Complete required security training.
  • Return organizational assets when required.
  • Follow confidentiality obligations.

6. Role Risk Assessment

The organization shall consider role risk before assigning security-sensitive responsibilities.

Factors may include:

  • Information accessed
  • Information classification
  • System access
  • Privileged access
  • Production access
  • Customer-data access
  • Personal-data access
  • Financial authority
  • Cloud administration
  • Security-system administration
  • Source-code access
  • Credential/secret access
  • Regulatory responsibility
  • Business-critical responsibilities

Job title alone should not determine role sensitivity.


7. Sensitive Roles

The organization shall identify roles requiring enhanced security controls where appropriate.

Examples include:

  • Cloud administrators
  • System administrators
  • Database administrators
  • Security engineers
  • SOC personnel
  • VAPT personnel
  • DevOps personnel
  • Production administrators
  • Source-code administrators
  • Identity administrators
  • Finance personnel with significant financial authority
  • Personnel handling highly sensitive customer information

Sensitive roles may require additional:

  • Screening
  • Approval
  • Training
  • Access restrictions
  • Monitoring
  • Periodic review
  • Re-screening where appropriate

8. Background Verification

Background verification shall be based on:

  • Role risk
  • Access level
  • Information sensitivity
  • Legal requirements
  • Regulatory requirements
  • Contractual requirements
  • Customer requirements

Depending on the role and applicable law, verification may include:

  • Identity verification
  • Employment verification
  • Education/qualification verification
  • Professional references
  • Professional certification
  • Regulatory checks
  • Sanctions screening
  • Criminal checks where lawful and relevant
  • Financial checks where lawful and relevant

The organization shall avoid collecting unnecessary sensitive personal information.


9. Screening Authorization

Where background verification is performed:

☐ Appropriate authorization shall be obtained where required.
☐ Screening shall be performed through approved processes/providers.
☐ Information shall be protected against unauthorized access.
☐ Results shall be reviewed by authorized personnel.
☐ Material discrepancies shall be assessed appropriately.
☐ Exceptions shall be documented and approved.


10. Background Verification Records

The organization may maintain a controlled Background Verification Register containing appropriate information such as:

  • Personnel/reference ID
  • Role
  • Risk level
  • Screening level
  • Required checks
  • Completion status
  • Completion date
  • Exception status
  • Review date

Complete background reports should not be stored in the register unless there is a documented need.


11. Screening Exceptions

Where required screening cannot be completed:

  • The reason shall be documented.
  • Security risk shall be assessed.
  • Alternative verification shall be considered.
  • Compensating controls shall be identified where appropriate.
  • Appropriate approval shall be obtained.
  • An expiry/review date shall be established.
  • The exception shall be monitored until resolved.

An exception shall not be treated as a permanent cancellation of a required security control.


12. Employment Terms and Security Responsibilities

Employment or engagement terms shall address relevant security responsibilities.

Depending on the role, these may include:

  • Confidentiality
  • Acceptable use
  • Information protection
  • Security incident reporting
  • Credential protection
  • Intellectual property
  • Customer information protection
  • Personal-data protection
  • Asset protection
  • Compliance with security policies
  • Return of organizational information and assets

13. Confidentiality

Personnel shall protect confidential information obtained through their employment or engagement.

Confidentiality requirements may apply to:

  • Customer information
  • Personal data
  • Source code
  • Business information
  • Security information
  • Credentials and secrets
  • Intellectual property
  • Financial information
  • Internal documentation

Where appropriate, confidentiality agreements or contractual clauses shall be established.

Confidentiality obligations may continue after termination where applicable.


14. Security Awareness and Training

Personnel shall receive appropriate security awareness and training.

Training may cover:

  • Information security
  • Password security
  • MFA
  • Phishing
  • Social engineering
  • Data protection
  • Confidential information
  • Incident reporting
  • Acceptable use
  • Remote working
  • Device security
  • Secure use of cloud services
  • AI/generative AI security
  • Role-specific security responsibilities

Training shall be appropriate to the person’s responsibilities and risk.


15. Security Policy Communication

Personnel shall have access to applicable security policies and procedures.

The organization may require acknowledgement for selected policies.

Where acknowledgement is used:

  • Applicable policies shall be identified.
  • Personnel shall be provided access.
  • Acknowledgement shall be recorded.
  • Material changes shall be communicated.
  • Overdue acknowledgements shall be tracked where required.

Acknowledgement demonstrates receipt/review and does not by itself demonstrate compliance.


16. Access Management

Access shall be:

  • Authorized
  • Based on business need
  • Appropriate to the person’s role
  • Limited to the required scope
  • Reviewed periodically
  • Removed when no longer required

The organization shall apply least privilege where appropriate.


17. Joiner Process

Before or during onboarding, as appropriate:

☐ Role is identified
☐ Role risk is assessed
☐ Required screening is determined
☐ Screening is completed or appropriately controlled
☐ Security responsibilities are communicated
☐ Required policies are provided
☐ Security training is completed
☐ Access is approved
☐ Accounts are created
☐ MFA is configured where required


18. Mover Process

When personnel change roles:

  • Existing access shall be reviewed.
  • Unnecessary access shall be removed.
  • New access shall be approved.
  • Role sensitivity shall be reassessed.
  • Additional screening shall be considered where appropriate.
  • Privileged access shall be separately reviewed.

19. Leaver Process

When employment or engagement ends:

  • Access shall be identified.
  • Accounts shall be disabled or removed.
  • Privileged access shall be revoked.
  • Cloud access shall be removed.
  • SaaS access shall be removed.
  • Production access shall be removed.
  • Source-code access shall be removed.
  • Physical access shall be revoked.
  • Organizational assets shall be returned.
  • Organizational information shall be returned or deleted where required.
  • Credentials, tokens, keys, or secrets shall be addressed where necessary.

20. Privileged Access

Personnel with privileged access shall be subject to additional controls appropriate to risk.

These may include:

  • Enhanced authorization
  • MFA
  • Named accounts
  • Least privilege
  • Privileged-access management
  • Session logging
  • Activity monitoring
  • Periodic access review
  • Temporary or just-in-time access
  • Additional screening where appropriate

Privileged access shall not be granted merely because an employee holds a senior job title.


21. Production Access

Personnel requiring production access shall have:

  • Documented business need
  • Appropriate approval
  • Appropriate authentication
  • Least-privilege access
  • Appropriate logging/monitoring
  • Periodic review

Production access should be limited to personnel who require it to perform their responsibilities.


22. Remote Working

Personnel working remotely shall protect organizational information and systems.

Requirements may include:

  • Secure authentication
  • MFA
  • Approved devices
  • Device encryption
  • Secure network access
  • VPN or equivalent controls where appropriate
  • Protection of confidential information
  • Secure physical environment
  • Prompt reporting of lost or stolen devices

23. Mobile Devices

Where organizational information is accessed through mobile devices:

  • Appropriate authentication shall be used.
  • Device security shall be enabled.
  • Encryption shall be used where appropriate.
  • Approved applications shall be used where required.
  • Lost or stolen devices shall be reported.
  • Remote-wipe capability shall be considered where appropriate.

24. Acceptable Use

Personnel shall use organizational systems and information only for authorized purposes.

The organization may define requirements for:

  • Email
  • Internet access
  • SaaS applications
  • Cloud services
  • Corporate devices
  • Personal devices
  • Removable media
  • Software installation
  • Social media
  • AI/generative AI services

25. AI and Generative AI

Personnel using AI services shall follow organizational requirements concerning:

  • Confidential information
  • Customer information
  • Personal data
  • Source code
  • Credentials
  • Security information
  • Approved AI services
  • Data retention
  • Use of submitted information for training where relevant
  • Human review of AI-generated output

Sensitive information shall not be submitted to AI services unless the use is authorized and appropriate safeguards are in place.


26. Contractor and Third-Party Personnel

Contractors and third-party personnel shall be subject to appropriate security requirements.

Depending on risk:

  • Screening may be required.
  • Confidentiality requirements may apply.
  • Security training may be required.
  • Access shall be approved.
  • Access shall be restricted.
  • Temporary access should be used where appropriate.
  • Access shall be reviewed.
  • Supplier responsibilities shall be defined.
  • Offboarding shall be completed.

27. Security Incident Reporting

Personnel shall promptly report suspected or actual security incidents.

Examples include:

  • Phishing
  • Lost device
  • Stolen device
  • Unauthorized access
  • Accidental information disclosure
  • Malware
  • Credential compromise
  • Suspicious activity
  • Data leakage
  • Security-policy violation

Personnel should not delay reporting while attempting to determine the complete impact of an event.


28. Disciplinary Process

The organization shall maintain an appropriate process for addressing intentional or negligent violations of information-security requirements.

The process shall:

  • Follow applicable law
  • Be appropriately documented
  • Protect confidentiality
  • Consider the nature and severity of the violation
  • Involve appropriate HR and management personnel
  • Involve Information Security where necessary
  • Provide appropriate escalation

Disciplinary action should be handled through the organization’s established employment and legal processes.


29. Personnel Security During Investigations

Where a personnel-related security investigation occurs:

  • Access may be restricted where authorized.
  • Relevant evidence shall be protected.
  • Confidentiality shall be maintained.
  • HR, Information Security, Legal, and management responsibilities shall be coordinated as appropriate.
  • Investigations shall follow applicable law and organizational procedures.

30. Role Changes and Re-Screening

The organization shall reassess security requirements when personnel:

  • Move to a sensitive role
  • Receive privileged access
  • Receive production access
  • Receive access to restricted information
  • Assume financial authority
  • Assume security responsibilities
  • Change geographic location where relevant
  • Take on materially different responsibilities

Re-screening shall be performed where justified by risk, law, regulation, contract, or organizational requirements.


31. Personnel Records Protection

HR and personnel records shall be appropriately protected.

Controls may include:

  • Access restriction
  • Role-based access
  • Secure storage
  • Encryption where appropriate
  • Data minimization
  • Retention requirements
  • Secure disposal
  • Access logging where appropriate

Personnel records shall not be accessible to unauthorized employees.


32. HR Systems Security

Systems containing personnel information shall receive appropriate security controls.

Examples include:

  • HRIS
  • Payroll systems
  • Recruitment platforms
  • Background verification systems
  • Learning platforms
  • Employee document repositories
  • Performance-management systems

Controls may include:

  • MFA
  • Role-based access
  • Least privilege
  • Logging
  • Supplier due diligence
  • Backup
  • Data protection
  • Retention and disposal

33. HR Suppliers

HR-related suppliers shall be assessed according to their risk.

Examples include:

  • Payroll providers
  • HRIS providers
  • Recruitment agencies
  • Background verification providers
  • Benefits providers
  • Learning platforms
  • Contractor management platforms

Where applicable, contracts shall address:

  • Confidentiality
  • Information security
  • Personal-data protection
  • Incident notification
  • Access control
  • Data location
  • Subprocessors
  • Data retention
  • Data deletion/return

34. Security Responsibilities After Termination

Where applicable, personnel shall continue to comply with obligations relating to:

  • Confidentiality
  • Intellectual property
  • Customer information
  • Personal data
  • Trade secrets
  • Organizational information
  • Security information

The applicable obligations shall be communicated through appropriate contractual or employment arrangements.


35. Monitoring and Compliance

The organization shall periodically assess compliance with this policy.

Monitoring may include:

  • Background verification completion
  • Security training completion
  • Policy acknowledgement
  • Access reviews
  • Privileged-access reviews
  • Offboarding reviews
  • Sensitive-role reviews
  • Security incidents involving personnel
  • Policy violations
  • Contractor security
  • HR-system access reviews

36. Exceptions

Exceptions to this policy shall:

  • Be documented
  • Have a valid business justification
  • Be risk-assessed
  • Have appropriate compensating controls where required
  • Have an owner
  • Have an expiry/review date
  • Be approved by authorized personnel

Legal or regulatory requirements shall not be bypassed through an internal policy exception.


37. Policy Violations

Potential violations shall be handled according to the organization’s established processes.

Examples include:

  • Unauthorized access
  • Sharing credentials
  • Unauthorized disclosure
  • Circumventing security controls
  • Unauthorized software installation
  • Improper handling of customer information
  • Deliberate security-policy violations

Significant violations shall be escalated appropriately.


38. Business Continuity

Personnel-security arrangements shall support business continuity.

The organization should identify appropriate alternatives for critical personnel responsibilities.

Consider:

☐ Backup personnel
☐ Cross-training
☐ Emergency contacts
☐ Emergency access
☐ Critical-role succession
☐ Knowledge transfer
☐ Recovery responsibilities

The objective is to avoid excessive dependency on a single individual for critical security or operational activities.


39. Records

Appropriate records may include:

  • Background Verification Register
  • Screening records
  • Sensitive Role Register
  • Employment agreements
  • NDA records
  • Training records
  • Policy acknowledgements
  • Access approvals
  • Access reviews
  • Contractor records
  • Offboarding records
  • Asset-return records
  • Security incident records
  • Disciplinary records where appropriate
  • Exception records
  • Re-screening records

Records shall be protected according to their sensitivity.


40. Privacy and Data Protection

Personnel-security activities shall respect applicable privacy and data-protection requirements.

The organization shall consider:

  • Purpose limitation
  • Data minimization
  • Lawful processing
  • Access restrictions
  • Retention
  • Secure disposal
  • Data-subject rights where applicable
  • Cross-border transfer requirements where applicable
  • Supplier/subprocessor requirements

Screening shall be proportionate to the role and risk.


41. Security Awareness Effectiveness

The organization should evaluate whether security awareness is effective rather than relying solely on attendance.

Possible indicators include:

  • Training completion
  • Knowledge assessments
  • Phishing exercise results
  • Incident reporting behavior
  • Policy violations
  • Repeated security mistakes
  • Security incident trends

Results may be used to improve awareness programs.


42. Management Review

Management should receive relevant information regarding personnel-security performance.

Possible inputs include:

  • Screening coverage
  • High-risk role status
  • Security-training status
  • Access-control issues
  • Privileged-access findings
  • Personnel-related incidents
  • Policy violations
  • Offboarding issues
  • Contractor risks
  • Open corrective actions
  • Repeated findings

43. Policy Review

This policy shall be reviewed periodically and when significant changes occur.

Review triggers may include:

☐ Organizational restructuring
☐ Major technology changes
☐ New regulatory requirements
☐ New customer requirements
☐ Major security incident
☐ Significant personnel-security finding
☐ New remote-working model
☐ New AI usage
☐ Significant changes in HR systems
☐ Changes to sensitive roles
☐ Changes to business operations

Review Frequency: __________________

Policy Owner: ______________________


44. Policy Compliance

Compliance with this policy may be assessed through:

  • Internal audits
  • HR security audits
  • Access reviews
  • Security compliance monitoring
  • Management reviews
  • Risk assessments
  • Incident investigations
  • Supplier assessments

Non-compliance shall be recorded and addressed through the organization’s corrective-action and risk-management processes.


45. AWS SaaS Startup Example

For an AWS-based SaaS startup, personnel security should give additional attention to roles such as:

  • AWS Administrator
  • DevOps Engineer
  • Production Engineer
  • Database Administrator
  • Security Engineer
  • Developer with production access
  • CI/CD Administrator
  • VAPT Consultant

For example, an AWS Administrator may require:

Sensitive-role assessment → Enhanced screening where justified → Confidentiality obligations → Security training → Named account → MFA → Least privilege → Privileged-access controls → Logging → Periodic review → Controlled offboarding

The same level of control would not necessarily be appropriate for every employee.


46. Startup-Friendly HR Security Model

A startup can implement this policy using five lifecycle stages:

Before Joining

  • Role risk assessment
  • Background verification
  • Employment terms
  • Confidentiality

Joining

  • Security responsibilities
  • Security awareness
  • Policy communication
  • Access approval
  • MFA

During Employment

  • Access reviews
  • Security awareness
  • Role changes
  • Incident reporting
  • Policy compliance

Sensitive Roles

  • Enhanced controls based on risk
  • Privileged-access management
  • Production-access controls
  • Additional monitoring
  • Periodic review

Leaving

  • Access revocation
  • Asset return
  • Information protection
  • Credential/token handling
  • Continuing confidentiality obligations

47. Common Mistakes

Avoid:

  • Treating HR security as only an HR responsibility
  • Applying identical screening to every role
  • Granting access before required controls are completed
  • Ignoring contractors
  • Ignoring third-party personnel
  • Failing to identify sensitive roles
  • Failing to review role changes
  • Not testing offboarding
  • Relying only on training attendance
  • Storing excessive personal information
  • Ignoring HR-system security
  • Ignoring HR suppliers
  • Granting privileged access without additional controls
  • Failing to document exceptions
  • Applying intrusive screening without a lawful and proportionate basis
  • Failing to review personnel-security incidents and recurring issues

48. Relationship With Other ISMS Documents

DocumentRelationship
Employee Screening PolicyDefines screening principles
Background Verification ProcedureDefines verification process
Background Verification RegisterTracks screening
Sensitive Role Identification ChecklistIdentifies sensitive roles
Role-Based Screening MatrixDetermines screening level
HR Security Audit ChecklistAudits personnel-security controls
Security Awareness ProcedureDefines security training
Security Policy Acknowledgement RegisterTracks acknowledgements
Access Management ProcedureControls access
Privileged Access ProcedureControls privileged access
Employee Onboarding ProcedureControls joining
Employee Offboarding ProcedureControls termination
Contractor Screening ProcedureControls contractors
Incident Response ProcedureHandles security incidents
Risk RegisterTracks significant personnel risks

49. ISO/IEC 27001 Connection

This policy supports the organization’s management of information-security risks associated with personnel throughout the employment and engagement lifecycle.

Relevant areas may include:

  • Personnel screening
  • Employment terms and conditions
  • Security awareness and training
  • Confidentiality
  • Access control
  • Privileged access
  • Remote working
  • Personnel changes
  • Termination or change of employment
  • Contractor and third-party personnel
  • Incident reporting
  • Protection of organizational information

The Human Resources Security Policy is not itself a universally prescribed ISO/IEC 27001 document title. The organization should determine the appropriate policies, procedures, records, and controls based on its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, and business needs.


50. Audit Evidence Checklist

The organization should be able to demonstrate appropriate evidence such as:

☐ Approved HR Security Policy
☐ Role risk assessments
☐ Sensitive Role Register
☐ Background Verification Register
☐ Screening records
☐ Employment/security agreements
☐ NDA records
☐ Security training records
☐ Policy acknowledgement records
☐ Access approvals
☐ Privileged-access approvals
☐ Access reviews
☐ Contractor records
☐ Offboarding records
☐ Asset-return records
☐ Exception records
☐ Security incident records
☐ HR supplier assessments
☐ Corrective-action records
☐ Policy review records


51. Final HR Security Audit Trail

The organization should be able to demonstrate:

Who works for or on behalf of the organization?
What security risks does each role introduce?
Which roles are sensitive?
Was appropriate screening performed?
Were security responsibilities defined?
Were confidentiality requirements established?
Was security awareness provided?
Was access appropriately authorized?
Was privileged access controlled?
Were role changes reviewed?
Were contractors and third parties controlled?
Were security incidents reported?
Was access removed when the relationship ended?
Were organizational assets and information protected?
Were personnel-security weaknesses corrected?

Final Principle

Human resources security is a lifecycle control, not simply a recruitment activity. The organization should manage security from role definition and screening through onboarding, employment, access, awareness, role changes, incidents, and offboarding—while applying controls proportionately to the actual risk and protecting personnel information throughout the process.