ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Security Acknowledgement

Employee Security Acknowledgement

1. Purpose

The Employee Security Acknowledgement records that an employee has received, reviewed, and acknowledged the organization’s information-security responsibilities, policies, procedures, and applicable security requirements.

The acknowledgement provides evidence that security expectations have been communicated to personnel.

Core Principle

Communicate → Review → Understand → Acknowledge → Apply → Monitor → Reassess


2. Scope

This acknowledgement applies to:

  • Employees
  • Permanent personnel
  • Temporary employees
  • Interns
  • Contractors where applicable
  • Other personnel who are required to acknowledge security responsibilities

The exact acknowledgement requirements should be based on the person’s role, information access, system access, and organizational requirements.


3. Employee Information

FieldDetails
Employee Name
Employee ID
Department
Job Title
Manager
Location
Employment Type
Joining Date
Acknowledgement Date
Next Review Date

4. Security Documents Acknowledged

Identify the policies, procedures, and requirements communicated to the employee.

DocumentVersionDate IssuedReviewedAcknowledged
Information Security Policy☐☐
Acceptable Use Policy☐☐
Access Control Policy☐☐
Password/MFA Requirements☐☐
Data Classification Policy☐☐
Remote Working Policy☐☐
Incident Reporting Procedure☐☐
Employee Security Responsibilities☐☐
Privacy/Data Protection Requirements☐☐
AI/Generative AI Requirements☐☐
Other☐☐

5. Employee Security Responsibilities

The employee confirms that they have been informed of their responsibility to:

☐ Protect organizational information

☐ Protect customer and personal information

☐ Follow applicable security policies and procedures

☐ Use company systems only for authorized purposes

☐ Protect usernames, passwords, tokens, API keys, and other credentials

☐ Use MFA where required

☐ Not share individual accounts

☐ Follow least-privilege requirements

☐ Protect company devices

☐ Follow secure remote-working requirements

☐ Report suspected security incidents

☐ Report phishing and suspicious communications

☐ Report suspected unauthorized access

☐ Report loss or theft of company assets

☐ Protect confidential and restricted information

☐ Follow approved information-transfer methods

☐ Follow data retention and disposal requirements

☐ Follow security requirements when using cloud and SaaS services

☐ Follow approved AI and Generative AI requirements

☐ Cooperate with authorized security investigations and audits

☐ Complete required security awareness training


6. Information Protection

The employee acknowledges that organizational information must be protected according to its classification.

Employee Responsibilities

☐ Understand applicable information classifications

☐ Access information only when authorized

☐ Share information only with authorized recipients

☐ Avoid storing sensitive information in unauthorized locations

☐ Use approved storage and collaboration systems

☐ Protect information when working remotely

☐ Securely dispose of information when no longer required

☐ Follow customer-specific information-security requirements where applicable


7. Account and Credential Security

The employee acknowledges that:

☐ Credentials are personal and must not be shared

☐ Passwords must meet organizational requirements

☐ MFA must not be bypassed

☐ Authentication requests must be protected

☐ Passwords must not be stored insecurely

☐ API keys and tokens must be protected

☐ Suspected credential compromise must be reported immediately

☐ Unauthorized use of another person’s account is prohibited


8. Access Responsibilities

The employee agrees to:

☐ Use only authorized systems

☐ Access only information required for their role

☐ Not attempt to bypass access controls

☐ Not use another person’s account

☐ Not attempt unauthorized privilege escalation

☐ Report unnecessary or incorrect access

☐ Return or surrender access when requested

☐ Follow access requirements during role changes


9. Production and Privileged Access

Where applicable, employees with privileged or production access acknowledge that:

☐ Privileged access is provided only for authorized business purposes

☐ Administrative accounts must be protected

☐ MFA must be used where required

☐ Production access must be limited to approved activities

☐ Administrative actions may be logged and monitored

☐ Production information must not be copied unnecessarily

☐ Emergency access requirements must be followed

☐ Privileged access must not be shared

☐ Access must be surrendered when no longer required


10. Cloud and SaaS Responsibilities

Where applicable:

☐ Use only approved cloud services

☐ Protect cloud credentials

☐ Follow cloud access requirements

☐ Do not create unauthorized cloud resources

☐ Do not share cloud accounts

☐ Protect cloud-stored information

☐ Report suspicious cloud activity

☐ Follow approved SaaS usage requirements


11. Security Incident Reporting

The employee acknowledges that suspected security incidents must be reported promptly.

Examples include:

  • Lost or stolen devices
  • Phishing
  • Malware
  • Accidental information disclosure
  • Unauthorized access
  • Credential compromise
  • Suspicious login
  • Data leakage
  • Incorrect recipient of confidential information
  • Security-policy violation
  • Suspicious cloud activity

Reporting Method

Security Contact: __________________________

Email/Portal: __________________________

Emergency Contact: __________________________


12. Phishing and Social Engineering

The employee acknowledges that they should:

☐ Verify unexpected requests

☐ Avoid opening suspicious attachments

☐ Avoid clicking suspicious links

☐ Verify unusual payment or information requests

☐ Report suspected phishing

☐ Never disclose passwords or MFA codes to unauthorized persons

☐ Follow identity-verification procedures


13. Company Devices

Where company devices are provided:

☐ Device must be protected from unauthorized use

☐ Screen must be locked when unattended

☐ Security updates must not be intentionally disabled

☐ Unauthorized software must not be installed

☐ Device encryption requirements must be followed

☐ Device must not be shared with unauthorized persons

☐ Lost or stolen devices must be reported immediately

☐ Company devices must be returned when required


14. Remote Working

When working remotely, the employee agrees to:

☐ Protect company information from unauthorized persons

☐ Use approved systems and communication channels

☐ Secure company devices

☐ Avoid exposing confidential information in public areas

☐ Follow VPN or secure-access requirements where applicable

☐ Lock screens when unattended

☐ Follow approved printing and disposal requirements

☐ Report suspected security incidents


15. Email and Communication

The employee acknowledges that:

☐ Business information must be shared using approved channels

☐ Sensitive information must not be sent to unauthorized recipients

☐ Unexpected requests should be verified

☐ Confidential information must be handled appropriately

☐ Personal email must not be used for unauthorized business information transfer

☐ Suspicious emails must be reported


16. AI and Generative AI

Where AI tools are permitted, the employee acknowledges that:

☐ Only approved AI tools may be used for organizational information

☐ Confidential or restricted information must not be submitted to unauthorized AI services

☐ Customer and personal information must be protected

☐ Source code must not be submitted to unauthorized AI systems

☐ AI-generated content must be reviewed where required

☐ Organizational AI security requirements must be followed


17. Intellectual Property

The employee acknowledges that:

☐ Company intellectual property must be protected

☐ Source code must be protected

☐ Proprietary documentation must not be disclosed without authorization

☐ Customer intellectual property must be protected

☐ Third-party licensed materials must be used according to applicable license requirements


18. Confidentiality

The employee acknowledges their obligation to protect confidential information.

This includes:

  • Customer information
  • Employee information
  • Business information
  • Source code
  • Credentials
  • Security information
  • Architecture information
  • Commercial information
  • Proprietary information

Confidentiality obligations may continue after employment ends where required by applicable agreements or law.


19. Security Awareness

The employee confirms that they have:

☐ Received required security awareness information

☐ Completed required security training

☐ Been informed about security reporting

☐ Been informed about applicable security policies

☐ Been informed about role-specific security responsibilities

☐ Understood where to obtain security guidance


20. Policy and Procedure Compliance

The employee acknowledges that they are expected to follow applicable:

  • Security policies
  • Security procedures
  • Operating procedures
  • Access requirements
  • Privacy requirements
  • Customer requirements
  • Contractual requirements
  • Legal and regulatory requirements

Failure to comply may result in investigation and appropriate action under applicable organizational processes.


21. Security Monitoring

Where permitted and appropriately communicated, the employee acknowledges that organizational systems and activities may be monitored for purposes such as:

  • Security
  • Fraud prevention
  • Incident investigation
  • Compliance
  • Operational protection
  • Access management
  • Regulatory or contractual requirements

Monitoring should be performed in accordance with applicable law and organizational policy.


22. Employee Declaration

I confirm that:

☐ I have received access to the applicable information-security policies and requirements.

☐ I have reviewed the requirements applicable to my role.

☐ I understand my responsibility to protect organizational and customer information.

☐ I understand that I must use systems and information only for authorized purposes.

☐ I understand my responsibility to protect credentials and access.

☐ I understand how to report security incidents and suspected security weaknesses.

☐ I understand that I must comply with applicable security policies and procedures.

☐ I understand that security requirements may change and that I may be required to review updated requirements.

☐ I understand that my acknowledgement confirms receipt and review of the requirements and does not replace my responsibility to comply with them.


23. Employee Acknowledgement

Employee Name: __________________________________

Employee ID: __________________________________

Signature / Electronic Confirmation: __________________________________

Date: __________________________________


24. Manager Confirmation

The manager confirms that the employee has been informed of the security responsibilities applicable to their role.

Manager Name: __________________________________

Role: __________________________________

Signature / Electronic Confirmation: __________________________________

Date: __________________________________


25. HR / Security Confirmation

Reviewer: __________________________________

Function: ☐ HR ☐ Information Security ☐ Compliance ☐ Other

Acknowledgement Verified: ☐ Yes ☐ No

Outstanding Requirements: ______________________________

Date: __________________________________


26. Electronic Acknowledgement

Electronic acknowledgement may be recorded through an approved HR, training, compliance, or document-management system.

The record should capture, where appropriate:

FieldRecord
Employee
Policy/Document
Version
Date Published
Date Acknowledged
Acknowledgement Status
Training Completed
System/User ID
Timestamp
Evidence Location

The organization should protect acknowledgement records from unauthorized modification.


27. New Joiner Acknowledgement

Before or during onboarding, as applicable:

☐ Security policies provided

☐ Security responsibilities communicated

☐ Required security training assigned

☐ Confidentiality requirements communicated

☐ Acceptable-use requirements communicated

☐ Access requirements communicated

☐ Incident reporting process communicated

☐ Employee acknowledgement completed

☐ Evidence retained


28. Policy Change Acknowledgement

When a policy undergoes a material change:

☐ Change assessed

☐ Affected employees identified

☐ Updated policy communicated

☐ Training provided where necessary

☐ Re-acknowledgement required where appropriate

☐ Acknowledgement status tracked

☐ Overdue acknowledgements followed up


29. Annual Re-Acknowledgement

Where required by organizational policy or risk:

☐ Applicable policies identified

☐ Employees identified

☐ Updated policies distributed

☐ Employees notified

☐ Acknowledgement period established

☐ Completion monitored

☐ Overdue acknowledgements escalated

☐ Evidence retained


30. Role Change

When an employee changes roles:

☐ New responsibilities identified

☐ New security requirements identified

☐ New policies/procedures communicated

☐ Additional training assigned where required

☐ New access requirements assessed

☐ Previous access reviewed

☐ Re-acknowledgement completed where required


31. Overdue Acknowledgements

Track incomplete acknowledgements.

EmployeeRequirementDue DateStatusReminderEscalation

Possible actions include:

  • Reminder
  • Manager notification
  • Additional training
  • Access review
  • Escalation according to organizational policy

Any access restriction should be based on the organization’s defined risk and employment processes.


32. Declined Acknowledgement

If an employee declines to acknowledge a required security requirement:

☐ Employee contacted

☐ Reason documented

☐ Requirement explained

☐ Manager notified

☐ HR notified where appropriate

☐ Security notified where appropriate

☐ Risk assessed

☐ Corrective action determined

☐ Final outcome recorded

Declining acknowledgement does not automatically mean that the employee is exempt from applicable security requirements.


33. Acknowledgement Exceptions

Where acknowledgement cannot be completed:

☐ Reason documented

☐ Alternative communication method used

☐ Requirement communicated through an approved method

☐ Risk assessed where necessary

☐ Exception approved where required

☐ Completion tracked

☐ Exception closure date defined


34. Third-Party Personnel

Where applicable, contractors and third-party personnel may be required to acknowledge:

☐ Confidentiality requirements

☐ Security responsibilities

☐ Acceptable use

☐ Access restrictions

☐ Customer requirements

☐ Incident reporting

☐ Data protection requirements

☐ Security testing requirements

☐ Contractual security requirements

The organization’s supplier and contractual requirements should define responsibility for obtaining and retaining such acknowledgements.


35. Sensitive and Privileged Roles

Personnel with elevated access may require additional acknowledgement of:

☐ Privileged access responsibilities

☐ Production access requirements

☐ Cloud security responsibilities

☐ Source-code protection

☐ Database security

☐ Security monitoring

☐ Change-management requirements

☐ Incident escalation

☐ Confidentiality obligations

☐ Additional role-specific security controls


36. Evidence Requirements

Maintain appropriate evidence such as:

  • Signed acknowledgement
  • Electronic acknowledgement
  • Policy version
  • Distribution record
  • Training record
  • Employee notification
  • Completion report
  • Reminder records
  • Exception records
  • Manager confirmation
  • Re-acknowledgement record

Avoid retaining unnecessary sensitive personal information.


37. Acknowledgement Register

Maintain a centralized register where appropriate.

EmployeeDepartmentPolicyVersionDate IssuedDate AcknowledgedStatusEvidence

Status

  • Pending
  • Completed
  • Overdue
  • Exception
  • Not Applicable

38. Acknowledgement Metrics

Management may monitor:

  • Overall acknowledgement completion
  • Overdue acknowledgements
  • Completion by department
  • Completion by policy
  • New-joiner completion
  • Annual completion
  • Material-change re-acknowledgement
  • Exceptions
  • Declined acknowledgements
  • Repeat overdue cases

Example Dashboard

MetricResult
Total Applicable Employees
Completed
Pending
Overdue
Exceptions
Completion %

39. Review and Monitoring

The organization should periodically review whether:

☐ Applicable personnel are identified

☐ Required policies are assigned

☐ Current versions are distributed

☐ Acknowledgements are completed

☐ Overdue items are followed up

☐ Material policy changes trigger appropriate re-acknowledgement

☐ Evidence is retained

☐ Exceptions are controlled

☐ Acknowledgement records remain accurate


40. AWS SaaS Startup Example

An AWS-based SaaS startup has 25 employees.

Employees receive:

  • Information Security Policy
  • Acceptable Use Policy
  • Access Control Policy
  • Incident Response Procedure
  • Data Classification Policy
  • Remote Working Policy
  • AI Usage Requirements

Standard Employees

Employees acknowledge general security requirements during onboarding.

Developers

Developers additionally acknowledge:

  • Source-code security
  • Secrets protection
  • Secure development requirements
  • Production access restrictions

DevOps / Cloud Administrators

Administrators additionally acknowledge:

  • AWS privileged-access requirements
  • Production access
  • MFA
  • Logging and monitoring
  • Emergency access
  • Change management

Evidence

The company retains:

Employee → Policy → Version → Communication → Training → Acknowledgement → Date → Evidence

This provides a simple and defensible audit trail.


41. Startup-Friendly Acknowledgement Model

A startup does not need to create excessive acknowledgement administration.

New Joiner

Day 1–7

  • Security policies
  • Security responsibilities
  • Confidentiality
  • Acceptable use
  • Incident reporting
  • Required training
  • Employee acknowledgement

Role Change

Perform a targeted review when:

  • Access increases
  • Privileged access is granted
  • Production access is granted
  • Sensitive information becomes accessible
  • Security responsibilities change

Annual

Review and re-acknowledge material security requirements where appropriate.

Policy Change

Trigger re-acknowledgement when a change materially affects employee responsibilities.


42. Common Mistakes

Avoid:

  • Treating acknowledgement as proof of compliance.
  • Collecting acknowledgements without communicating the policy.
  • Using outdated policy versions.
  • Failing to track overdue acknowledgements.
  • Requiring acknowledgement for every document without considering relevance.
  • Failing to re-acknowledge material policy changes.
  • Not maintaining evidence of the policy version acknowledged.
  • Ignoring contractors and third-party personnel where applicable.
  • Storing unnecessary sensitive employee information.
  • Assuming a signed acknowledgement means employees actually understand the requirements.
  • Using acknowledgement as a substitute for security awareness training.

43. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyDefines overarching security expectations
Employee Security ResponsibilitiesDefines individual responsibilities
Security Awareness ProcedureDefines security awareness activities
Security Awareness Training RegisterRecords training
Policy Acknowledgement RegisterTracks acknowledgements
Access Management ProcedureControls employee access
Employee Screening ProcedureAddresses personnel screening
Employment Security ClauseEstablishes contractual obligations
Incident Response ProcedureDefines incident reporting
HR Security PolicyDefines personnel security requirements
Employee Offboarding ProcedureRemoves responsibilities and access

44. ISO/IEC 27001 Connection

Employee security acknowledgement can provide evidence that applicable information-security responsibilities and requirements have been communicated to personnel.

However, an Employee Security Acknowledgement is not itself a universally prescribed ISO/IEC 27001 document or form.

The organization should determine:

  • Which personnel require acknowledgement
  • Which documents require acknowledgement
  • When acknowledgement is required
  • Whether re-acknowledgement is necessary
  • What evidence should be retained
  • How exceptions are handled

based on the organization’s ISMS scope, risks, applicable controls, contractual requirements, legal/regulatory obligations, and business needs.

Acknowledgement should also not be confused with security awareness or competence. Acknowledgement demonstrates that a requirement was communicated and reviewed; it does not, by itself, demonstrate that the employee understood or followed it.


45. Audit Evidence Checklist

☐ Approved policy

☐ Current policy version

☐ Policy distribution evidence

☐ Employee acknowledgement

☐ Electronic acknowledgement record

☐ Security training record

☐ New-joiner evidence

☐ Material-change re-acknowledgement

☐ Overdue tracking

☐ Exception records

☐ Manager follow-up

☐ Third-party acknowledgement where applicable

☐ Privileged-role acknowledgement where applicable

☐ Acknowledgement register

☐ Management reporting


46. Final Employee Security Acknowledgement Audit Trail

For an employee, the organization should be able to demonstrate:

Who is the employee?
What role do they perform?
What information and systems can they access?
What security responsibilities apply to them?
Which policies were provided?
Which version was provided?
When was it communicated?
Was required training completed?
Did the employee acknowledge the requirements?
Were material changes communicated?
Were overdue acknowledgements followed up?
What evidence was retained?

Final Principle

An acknowledgement is evidence of communication and review—not proof of security compliance.

The organization should combine acknowledgement with security awareness, training, access controls, monitoring, compliance reviews, and actual evidence of secure behavior.