1. Purpose
The Human Resources Security Policy establishes the organization’s requirements for managing information-security risks associated with employees, contractors, consultants, interns, temporary workers, and other personnel throughout the employment or engagement lifecycle.
The policy is intended to ensure that personnel:
- Are appropriately screened based on role and risk
- Understand their information-security responsibilities
- Protect organizational and customer information
- Receive appropriate security awareness and training
- Receive only authorized access
- Protect credentials and organizational assets
- Report security incidents promptly
- Follow applicable information-security policies
- Have access removed when no longer required
- Continue to protect confidential information after termination where applicable
Core Principle
Recruit → Screen → Define Responsibilities → Onboard → Train → Access → Monitor → Change → Offboard
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Interns
- Temporary workers
- Agency personnel
- Third-party personnel
- Remote workers
- Personnel with privileged access
- Personnel with access to customer information
- Personnel with access to production systems
- Personnel performing security-sensitive functions
The policy applies throughout the personnel lifecycle.
3. Policy Statement
The organization shall manage personnel-related information-security risks in a manner that is:
- Risk-based
- Proportionate
- Appropriate to the role
- Consistent with applicable law
- Consistent with contractual requirements
- Consistent with customer requirements
- Appropriate to information sensitivity and system access
Personnel shall be granted access and responsibilities based on legitimate business requirements and shall be expected to protect organizational information and systems.
4. Human Resources Security Objectives
The organization shall establish appropriate controls to:
- Identify personnel-security risks.
- Assess role sensitivity.
- Perform appropriate background verification.
- Define security responsibilities.
- Communicate security requirements.
- Provide appropriate security awareness.
- Control access throughout the personnel lifecycle.
- Protect confidential information.
- Manage contractors and third-party personnel.
- Address security violations.
- Revoke access when personnel leave or change roles.
- Retain appropriate evidence.
- Periodically review personnel-security controls.
5. Roles and Responsibilities
5.1 Management
Management shall:
- Support personnel-security requirements.
- Provide appropriate resources.
- Approve significant personnel-security requirements.
- Ensure significant personnel risks are addressed.
5.2 HR / People Function
HR shall:
- Coordinate personnel lifecycle processes.
- Support screening and verification.
- Maintain appropriate personnel records.
- Communicate employment-related security requirements.
- Coordinate onboarding and offboarding.
- Support disciplinary processes.
5.3 Information Security
Information Security shall:
- Define security requirements.
- Assess security risks.
- Identify sensitive roles with relevant stakeholders.
- Define security training requirements.
- Support access and privileged-access requirements.
- Monitor personnel-related security risks.
- Support investigations where appropriate.
5.4 Managers
Managers shall:
- Define business need for access.
- Identify role responsibilities.
- Approve appropriate access.
- Notify HR/IT of role changes.
- Support timely offboarding.
- Ensure personnel understand relevant responsibilities.
5.5 Personnel
Personnel shall:
- Protect organizational information.
- Follow applicable security policies.
- Protect authentication credentials.
- Use systems only for authorized purposes.
- Report security incidents.
- Complete required security training.
- Return organizational assets when required.
- Follow confidentiality obligations.
6. Role Risk Assessment
The organization shall consider role risk before assigning security-sensitive responsibilities.
Factors may include:
- Information accessed
- Information classification
- System access
- Privileged access
- Production access
- Customer-data access
- Personal-data access
- Financial authority
- Cloud administration
- Security-system administration
- Source-code access
- Credential/secret access
- Regulatory responsibility
- Business-critical responsibilities
Job title alone should not determine role sensitivity.
7. Sensitive Roles
The organization shall identify roles requiring enhanced security controls where appropriate.
Examples include:
- Cloud administrators
- System administrators
- Database administrators
- Security engineers
- SOC personnel
- VAPT personnel
- DevOps personnel
- Production administrators
- Source-code administrators
- Identity administrators
- Finance personnel with significant financial authority
- Personnel handling highly sensitive customer information
Sensitive roles may require additional:
- Screening
- Approval
- Training
- Access restrictions
- Monitoring
- Periodic review
- Re-screening where appropriate
8. Background Verification
Background verification shall be based on:
- Role risk
- Access level
- Information sensitivity
- Legal requirements
- Regulatory requirements
- Contractual requirements
- Customer requirements
Depending on the role and applicable law, verification may include:
- Identity verification
- Employment verification
- Education/qualification verification
- Professional references
- Professional certification
- Regulatory checks
- Sanctions screening
- Criminal checks where lawful and relevant
- Financial checks where lawful and relevant
The organization shall avoid collecting unnecessary sensitive personal information.
9. Screening Authorization
Where background verification is performed:
☐ Appropriate authorization shall be obtained where required.
☐ Screening shall be performed through approved processes/providers.
☐ Information shall be protected against unauthorized access.
☐ Results shall be reviewed by authorized personnel.
☐ Material discrepancies shall be assessed appropriately.
☐ Exceptions shall be documented and approved.
10. Background Verification Records
The organization may maintain a controlled Background Verification Register containing appropriate information such as:
- Personnel/reference ID
- Role
- Risk level
- Screening level
- Required checks
- Completion status
- Completion date
- Exception status
- Review date
Complete background reports should not be stored in the register unless there is a documented need.
11. Screening Exceptions
Where required screening cannot be completed:
- The reason shall be documented.
- Security risk shall be assessed.
- Alternative verification shall be considered.
- Compensating controls shall be identified where appropriate.
- Appropriate approval shall be obtained.
- An expiry/review date shall be established.
- The exception shall be monitored until resolved.
An exception shall not be treated as a permanent cancellation of a required security control.
12. Employment Terms and Security Responsibilities
Employment or engagement terms shall address relevant security responsibilities.
Depending on the role, these may include:
- Confidentiality
- Acceptable use
- Information protection
- Security incident reporting
- Credential protection
- Intellectual property
- Customer information protection
- Personal-data protection
- Asset protection
- Compliance with security policies
- Return of organizational information and assets
13. Confidentiality
Personnel shall protect confidential information obtained through their employment or engagement.
Confidentiality requirements may apply to:
- Customer information
- Personal data
- Source code
- Business information
- Security information
- Credentials and secrets
- Intellectual property
- Financial information
- Internal documentation
Where appropriate, confidentiality agreements or contractual clauses shall be established.
Confidentiality obligations may continue after termination where applicable.
14. Security Awareness and Training
Personnel shall receive appropriate security awareness and training.
Training may cover:
- Information security
- Password security
- MFA
- Phishing
- Social engineering
- Data protection
- Confidential information
- Incident reporting
- Acceptable use
- Remote working
- Device security
- Secure use of cloud services
- AI/generative AI security
- Role-specific security responsibilities
Training shall be appropriate to the person’s responsibilities and risk.
15. Security Policy Communication
Personnel shall have access to applicable security policies and procedures.
The organization may require acknowledgement for selected policies.
Where acknowledgement is used:
- Applicable policies shall be identified.
- Personnel shall be provided access.
- Acknowledgement shall be recorded.
- Material changes shall be communicated.
- Overdue acknowledgements shall be tracked where required.
Acknowledgement demonstrates receipt/review and does not by itself demonstrate compliance.
16. Access Management
Access shall be:
- Authorized
- Based on business need
- Appropriate to the person’s role
- Limited to the required scope
- Reviewed periodically
- Removed when no longer required
The organization shall apply least privilege where appropriate.
17. Joiner Process
Before or during onboarding, as appropriate:
☐ Role is identified
☐ Role risk is assessed
☐ Required screening is determined
☐ Screening is completed or appropriately controlled
☐ Security responsibilities are communicated
☐ Required policies are provided
☐ Security training is completed
☐ Access is approved
☐ Accounts are created
☐ MFA is configured where required
18. Mover Process
When personnel change roles:
- Existing access shall be reviewed.
- Unnecessary access shall be removed.
- New access shall be approved.
- Role sensitivity shall be reassessed.
- Additional screening shall be considered where appropriate.
- Privileged access shall be separately reviewed.
19. Leaver Process
When employment or engagement ends:
- Access shall be identified.
- Accounts shall be disabled or removed.
- Privileged access shall be revoked.
- Cloud access shall be removed.
- SaaS access shall be removed.
- Production access shall be removed.
- Source-code access shall be removed.
- Physical access shall be revoked.
- Organizational assets shall be returned.
- Organizational information shall be returned or deleted where required.
- Credentials, tokens, keys, or secrets shall be addressed where necessary.
20. Privileged Access
Personnel with privileged access shall be subject to additional controls appropriate to risk.
These may include:
- Enhanced authorization
- MFA
- Named accounts
- Least privilege
- Privileged-access management
- Session logging
- Activity monitoring
- Periodic access review
- Temporary or just-in-time access
- Additional screening where appropriate
Privileged access shall not be granted merely because an employee holds a senior job title.
21. Production Access
Personnel requiring production access shall have:
- Documented business need
- Appropriate approval
- Appropriate authentication
- Least-privilege access
- Appropriate logging/monitoring
- Periodic review
Production access should be limited to personnel who require it to perform their responsibilities.
22. Remote Working
Personnel working remotely shall protect organizational information and systems.
Requirements may include:
- Secure authentication
- MFA
- Approved devices
- Device encryption
- Secure network access
- VPN or equivalent controls where appropriate
- Protection of confidential information
- Secure physical environment
- Prompt reporting of lost or stolen devices
23. Mobile Devices
Where organizational information is accessed through mobile devices:
- Appropriate authentication shall be used.
- Device security shall be enabled.
- Encryption shall be used where appropriate.
- Approved applications shall be used where required.
- Lost or stolen devices shall be reported.
- Remote-wipe capability shall be considered where appropriate.
24. Acceptable Use
Personnel shall use organizational systems and information only for authorized purposes.
The organization may define requirements for:
- Internet access
- SaaS applications
- Cloud services
- Corporate devices
- Personal devices
- Removable media
- Software installation
- Social media
- AI/generative AI services
25. AI and Generative AI
Personnel using AI services shall follow organizational requirements concerning:
- Confidential information
- Customer information
- Personal data
- Source code
- Credentials
- Security information
- Approved AI services
- Data retention
- Use of submitted information for training where relevant
- Human review of AI-generated output
Sensitive information shall not be submitted to AI services unless the use is authorized and appropriate safeguards are in place.
26. Contractor and Third-Party Personnel
Contractors and third-party personnel shall be subject to appropriate security requirements.
Depending on risk:
- Screening may be required.
- Confidentiality requirements may apply.
- Security training may be required.
- Access shall be approved.
- Access shall be restricted.
- Temporary access should be used where appropriate.
- Access shall be reviewed.
- Supplier responsibilities shall be defined.
- Offboarding shall be completed.
27. Security Incident Reporting
Personnel shall promptly report suspected or actual security incidents.
Examples include:
- Phishing
- Lost device
- Stolen device
- Unauthorized access
- Accidental information disclosure
- Malware
- Credential compromise
- Suspicious activity
- Data leakage
- Security-policy violation
Personnel should not delay reporting while attempting to determine the complete impact of an event.
28. Disciplinary Process
The organization shall maintain an appropriate process for addressing intentional or negligent violations of information-security requirements.
The process shall:
- Follow applicable law
- Be appropriately documented
- Protect confidentiality
- Consider the nature and severity of the violation
- Involve appropriate HR and management personnel
- Involve Information Security where necessary
- Provide appropriate escalation
Disciplinary action should be handled through the organization’s established employment and legal processes.
29. Personnel Security During Investigations
Where a personnel-related security investigation occurs:
- Access may be restricted where authorized.
- Relevant evidence shall be protected.
- Confidentiality shall be maintained.
- HR, Information Security, Legal, and management responsibilities shall be coordinated as appropriate.
- Investigations shall follow applicable law and organizational procedures.
30. Role Changes and Re-Screening
The organization shall reassess security requirements when personnel:
- Move to a sensitive role
- Receive privileged access
- Receive production access
- Receive access to restricted information
- Assume financial authority
- Assume security responsibilities
- Change geographic location where relevant
- Take on materially different responsibilities
Re-screening shall be performed where justified by risk, law, regulation, contract, or organizational requirements.
31. Personnel Records Protection
HR and personnel records shall be appropriately protected.
Controls may include:
- Access restriction
- Role-based access
- Secure storage
- Encryption where appropriate
- Data minimization
- Retention requirements
- Secure disposal
- Access logging where appropriate
Personnel records shall not be accessible to unauthorized employees.
32. HR Systems Security
Systems containing personnel information shall receive appropriate security controls.
Examples include:
- HRIS
- Payroll systems
- Recruitment platforms
- Background verification systems
- Learning platforms
- Employee document repositories
- Performance-management systems
Controls may include:
- MFA
- Role-based access
- Least privilege
- Logging
- Supplier due diligence
- Backup
- Data protection
- Retention and disposal
33. HR Suppliers
HR-related suppliers shall be assessed according to their risk.
Examples include:
- Payroll providers
- HRIS providers
- Recruitment agencies
- Background verification providers
- Benefits providers
- Learning platforms
- Contractor management platforms
Where applicable, contracts shall address:
- Confidentiality
- Information security
- Personal-data protection
- Incident notification
- Access control
- Data location
- Subprocessors
- Data retention
- Data deletion/return
34. Security Responsibilities After Termination
Where applicable, personnel shall continue to comply with obligations relating to:
- Confidentiality
- Intellectual property
- Customer information
- Personal data
- Trade secrets
- Organizational information
- Security information
The applicable obligations shall be communicated through appropriate contractual or employment arrangements.
35. Monitoring and Compliance
The organization shall periodically assess compliance with this policy.
Monitoring may include:
- Background verification completion
- Security training completion
- Policy acknowledgement
- Access reviews
- Privileged-access reviews
- Offboarding reviews
- Sensitive-role reviews
- Security incidents involving personnel
- Policy violations
- Contractor security
- HR-system access reviews
36. Exceptions
Exceptions to this policy shall:
- Be documented
- Have a valid business justification
- Be risk-assessed
- Have appropriate compensating controls where required
- Have an owner
- Have an expiry/review date
- Be approved by authorized personnel
Legal or regulatory requirements shall not be bypassed through an internal policy exception.
37. Policy Violations
Potential violations shall be handled according to the organization’s established processes.
Examples include:
- Unauthorized access
- Sharing credentials
- Unauthorized disclosure
- Circumventing security controls
- Unauthorized software installation
- Improper handling of customer information
- Deliberate security-policy violations
Significant violations shall be escalated appropriately.
38. Business Continuity
Personnel-security arrangements shall support business continuity.
The organization should identify appropriate alternatives for critical personnel responsibilities.
Consider:
☐ Backup personnel
☐ Cross-training
☐ Emergency contacts
☐ Emergency access
☐ Critical-role succession
☐ Knowledge transfer
☐ Recovery responsibilities
The objective is to avoid excessive dependency on a single individual for critical security or operational activities.
39. Records
Appropriate records may include:
- Background Verification Register
- Screening records
- Sensitive Role Register
- Employment agreements
- NDA records
- Training records
- Policy acknowledgements
- Access approvals
- Access reviews
- Contractor records
- Offboarding records
- Asset-return records
- Security incident records
- Disciplinary records where appropriate
- Exception records
- Re-screening records
Records shall be protected according to their sensitivity.
40. Privacy and Data Protection
Personnel-security activities shall respect applicable privacy and data-protection requirements.
The organization shall consider:
- Purpose limitation
- Data minimization
- Lawful processing
- Access restrictions
- Retention
- Secure disposal
- Data-subject rights where applicable
- Cross-border transfer requirements where applicable
- Supplier/subprocessor requirements
Screening shall be proportionate to the role and risk.
41. Security Awareness Effectiveness
The organization should evaluate whether security awareness is effective rather than relying solely on attendance.
Possible indicators include:
- Training completion
- Knowledge assessments
- Phishing exercise results
- Incident reporting behavior
- Policy violations
- Repeated security mistakes
- Security incident trends
Results may be used to improve awareness programs.
42. Management Review
Management should receive relevant information regarding personnel-security performance.
Possible inputs include:
- Screening coverage
- High-risk role status
- Security-training status
- Access-control issues
- Privileged-access findings
- Personnel-related incidents
- Policy violations
- Offboarding issues
- Contractor risks
- Open corrective actions
- Repeated findings
43. Policy Review
This policy shall be reviewed periodically and when significant changes occur.
Review triggers may include:
☐ Organizational restructuring
☐ Major technology changes
☐ New regulatory requirements
☐ New customer requirements
☐ Major security incident
☐ Significant personnel-security finding
☐ New remote-working model
☐ New AI usage
☐ Significant changes in HR systems
☐ Changes to sensitive roles
☐ Changes to business operations
Review Frequency: __________________
Policy Owner: ______________________
44. Policy Compliance
Compliance with this policy may be assessed through:
- Internal audits
- HR security audits
- Access reviews
- Security compliance monitoring
- Management reviews
- Risk assessments
- Incident investigations
- Supplier assessments
Non-compliance shall be recorded and addressed through the organization’s corrective-action and risk-management processes.
45. AWS SaaS Startup Example
For an AWS-based SaaS startup, personnel security should give additional attention to roles such as:
- AWS Administrator
- DevOps Engineer
- Production Engineer
- Database Administrator
- Security Engineer
- Developer with production access
- CI/CD Administrator
- VAPT Consultant
For example, an AWS Administrator may require:
Sensitive-role assessment → Enhanced screening where justified → Confidentiality obligations → Security training → Named account → MFA → Least privilege → Privileged-access controls → Logging → Periodic review → Controlled offboarding
The same level of control would not necessarily be appropriate for every employee.
46. Startup-Friendly HR Security Model
A startup can implement this policy using five lifecycle stages:
Before Joining
- Role risk assessment
- Background verification
- Employment terms
- Confidentiality
Joining
- Security responsibilities
- Security awareness
- Policy communication
- Access approval
- MFA
During Employment
- Access reviews
- Security awareness
- Role changes
- Incident reporting
- Policy compliance
Sensitive Roles
- Enhanced controls based on risk
- Privileged-access management
- Production-access controls
- Additional monitoring
- Periodic review
Leaving
- Access revocation
- Asset return
- Information protection
- Credential/token handling
- Continuing confidentiality obligations
47. Common Mistakes
Avoid:
- Treating HR security as only an HR responsibility
- Applying identical screening to every role
- Granting access before required controls are completed
- Ignoring contractors
- Ignoring third-party personnel
- Failing to identify sensitive roles
- Failing to review role changes
- Not testing offboarding
- Relying only on training attendance
- Storing excessive personal information
- Ignoring HR-system security
- Ignoring HR suppliers
- Granting privileged access without additional controls
- Failing to document exceptions
- Applying intrusive screening without a lawful and proportionate basis
- Failing to review personnel-security incidents and recurring issues
48. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Screening Policy | Defines screening principles |
| Background Verification Procedure | Defines verification process |
| Background Verification Register | Tracks screening |
| Sensitive Role Identification Checklist | Identifies sensitive roles |
| Role-Based Screening Matrix | Determines screening level |
| HR Security Audit Checklist | Audits personnel-security controls |
| Security Awareness Procedure | Defines security training |
| Security Policy Acknowledgement Register | Tracks acknowledgements |
| Access Management Procedure | Controls access |
| Privileged Access Procedure | Controls privileged access |
| Employee Onboarding Procedure | Controls joining |
| Employee Offboarding Procedure | Controls termination |
| Contractor Screening Procedure | Controls contractors |
| Incident Response Procedure | Handles security incidents |
| Risk Register | Tracks significant personnel risks |
49. ISO/IEC 27001 Connection
This policy supports the organization’s management of information-security risks associated with personnel throughout the employment and engagement lifecycle.
Relevant areas may include:
- Personnel screening
- Employment terms and conditions
- Security awareness and training
- Confidentiality
- Access control
- Privileged access
- Remote working
- Personnel changes
- Termination or change of employment
- Contractor and third-party personnel
- Incident reporting
- Protection of organizational information
The Human Resources Security Policy is not itself a universally prescribed ISO/IEC 27001 document title. The organization should determine the appropriate policies, procedures, records, and controls based on its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, and business needs.
50. Audit Evidence Checklist
The organization should be able to demonstrate appropriate evidence such as:
☐ Approved HR Security Policy
☐ Role risk assessments
☐ Sensitive Role Register
☐ Background Verification Register
☐ Screening records
☐ Employment/security agreements
☐ NDA records
☐ Security training records
☐ Policy acknowledgement records
☐ Access approvals
☐ Privileged-access approvals
☐ Access reviews
☐ Contractor records
☐ Offboarding records
☐ Asset-return records
☐ Exception records
☐ Security incident records
☐ HR supplier assessments
☐ Corrective-action records
☐ Policy review records
51. Final HR Security Audit Trail
The organization should be able to demonstrate:
Who works for or on behalf of the organization?
What security risks does each role introduce?
Which roles are sensitive?
Was appropriate screening performed?
Were security responsibilities defined?
Were confidentiality requirements established?
Was security awareness provided?
Was access appropriately authorized?
Was privileged access controlled?
Were role changes reviewed?
Were contractors and third parties controlled?
Were security incidents reported?
Was access removed when the relationship ended?
Were organizational assets and information protected?
Were personnel-security weaknesses corrected?
Final Principle
Human resources security is a lifecycle control, not simply a recruitment activity. The organization should manage security from role definition and screening through onboarding, employment, access, awareness, role changes, incidents, and offboarding—while applying controls proportionately to the actual risk and protecting personnel information throughout the process.
