1. Purpose
The Employee Security Acknowledgement records that an employee has received, reviewed, and acknowledged the organization’s information-security responsibilities, policies, procedures, and applicable security requirements.
The acknowledgement provides evidence that security expectations have been communicated to personnel.
Core Principle
Communicate → Review → Understand → Acknowledge → Apply → Monitor → Reassess
2. Scope
This acknowledgement applies to:
- Employees
- Permanent personnel
- Temporary employees
- Interns
- Contractors where applicable
- Other personnel who are required to acknowledge security responsibilities
The exact acknowledgement requirements should be based on the person’s role, information access, system access, and organizational requirements.
3. Employee Information
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Department | |
| Job Title | |
| Manager | |
| Location | |
| Employment Type | |
| Joining Date | |
| Acknowledgement Date | |
| Next Review Date |
4. Security Documents Acknowledged
Identify the policies, procedures, and requirements communicated to the employee.
| Document | Version | Date Issued | Reviewed | Acknowledged |
|---|---|---|---|---|
| Information Security Policy | ☐ | ☐ | ||
| Acceptable Use Policy | ☐ | ☐ | ||
| Access Control Policy | ☐ | ☐ | ||
| Password/MFA Requirements | ☐ | ☐ | ||
| Data Classification Policy | ☐ | ☐ | ||
| Remote Working Policy | ☐ | ☐ | ||
| Incident Reporting Procedure | ☐ | ☐ | ||
| Employee Security Responsibilities | ☐ | ☐ | ||
| Privacy/Data Protection Requirements | ☐ | ☐ | ||
| AI/Generative AI Requirements | ☐ | ☐ | ||
| Other | ☐ | ☐ |
5. Employee Security Responsibilities
The employee confirms that they have been informed of their responsibility to:
☐ Protect organizational information
☐ Protect customer and personal information
☐ Follow applicable security policies and procedures
☐ Use company systems only for authorized purposes
☐ Protect usernames, passwords, tokens, API keys, and other credentials
☐ Use MFA where required
☐ Not share individual accounts
☐ Follow least-privilege requirements
☐ Protect company devices
☐ Follow secure remote-working requirements
☐ Report suspected security incidents
☐ Report phishing and suspicious communications
☐ Report suspected unauthorized access
☐ Report loss or theft of company assets
☐ Protect confidential and restricted information
☐ Follow approved information-transfer methods
☐ Follow data retention and disposal requirements
☐ Follow security requirements when using cloud and SaaS services
☐ Follow approved AI and Generative AI requirements
☐ Cooperate with authorized security investigations and audits
☐ Complete required security awareness training
6. Information Protection
The employee acknowledges that organizational information must be protected according to its classification.
Employee Responsibilities
☐ Understand applicable information classifications
☐ Access information only when authorized
☐ Share information only with authorized recipients
☐ Avoid storing sensitive information in unauthorized locations
☐ Use approved storage and collaboration systems
☐ Protect information when working remotely
☐ Securely dispose of information when no longer required
☐ Follow customer-specific information-security requirements where applicable
7. Account and Credential Security
The employee acknowledges that:
☐ Credentials are personal and must not be shared
☐ Passwords must meet organizational requirements
☐ MFA must not be bypassed
☐ Authentication requests must be protected
☐ Passwords must not be stored insecurely
☐ API keys and tokens must be protected
☐ Suspected credential compromise must be reported immediately
☐ Unauthorized use of another person’s account is prohibited
8. Access Responsibilities
The employee agrees to:
☐ Use only authorized systems
☐ Access only information required for their role
☐ Not attempt to bypass access controls
☐ Not use another person’s account
☐ Not attempt unauthorized privilege escalation
☐ Report unnecessary or incorrect access
☐ Return or surrender access when requested
☐ Follow access requirements during role changes
9. Production and Privileged Access
Where applicable, employees with privileged or production access acknowledge that:
☐ Privileged access is provided only for authorized business purposes
☐ Administrative accounts must be protected
☐ MFA must be used where required
☐ Production access must be limited to approved activities
☐ Administrative actions may be logged and monitored
☐ Production information must not be copied unnecessarily
☐ Emergency access requirements must be followed
☐ Privileged access must not be shared
☐ Access must be surrendered when no longer required
10. Cloud and SaaS Responsibilities
Where applicable:
☐ Use only approved cloud services
☐ Protect cloud credentials
☐ Follow cloud access requirements
☐ Do not create unauthorized cloud resources
☐ Do not share cloud accounts
☐ Protect cloud-stored information
☐ Report suspicious cloud activity
☐ Follow approved SaaS usage requirements
11. Security Incident Reporting
The employee acknowledges that suspected security incidents must be reported promptly.
Examples include:
- Lost or stolen devices
- Phishing
- Malware
- Accidental information disclosure
- Unauthorized access
- Credential compromise
- Suspicious login
- Data leakage
- Incorrect recipient of confidential information
- Security-policy violation
- Suspicious cloud activity
Reporting Method
Security Contact: __________________________
Email/Portal: __________________________
Emergency Contact: __________________________
12. Phishing and Social Engineering
The employee acknowledges that they should:
☐ Verify unexpected requests
☐ Avoid opening suspicious attachments
☐ Avoid clicking suspicious links
☐ Verify unusual payment or information requests
☐ Report suspected phishing
☐ Never disclose passwords or MFA codes to unauthorized persons
☐ Follow identity-verification procedures
13. Company Devices
Where company devices are provided:
☐ Device must be protected from unauthorized use
☐ Screen must be locked when unattended
☐ Security updates must not be intentionally disabled
☐ Unauthorized software must not be installed
☐ Device encryption requirements must be followed
☐ Device must not be shared with unauthorized persons
☐ Lost or stolen devices must be reported immediately
☐ Company devices must be returned when required
14. Remote Working
When working remotely, the employee agrees to:
☐ Protect company information from unauthorized persons
☐ Use approved systems and communication channels
☐ Secure company devices
☐ Avoid exposing confidential information in public areas
☐ Follow VPN or secure-access requirements where applicable
☐ Lock screens when unattended
☐ Follow approved printing and disposal requirements
☐ Report suspected security incidents
15. Email and Communication
The employee acknowledges that:
☐ Business information must be shared using approved channels
☐ Sensitive information must not be sent to unauthorized recipients
☐ Unexpected requests should be verified
☐ Confidential information must be handled appropriately
☐ Personal email must not be used for unauthorized business information transfer
☐ Suspicious emails must be reported
16. AI and Generative AI
Where AI tools are permitted, the employee acknowledges that:
☐ Only approved AI tools may be used for organizational information
☐ Confidential or restricted information must not be submitted to unauthorized AI services
☐ Customer and personal information must be protected
☐ Source code must not be submitted to unauthorized AI systems
☐ AI-generated content must be reviewed where required
☐ Organizational AI security requirements must be followed
17. Intellectual Property
The employee acknowledges that:
☐ Company intellectual property must be protected
☐ Source code must be protected
☐ Proprietary documentation must not be disclosed without authorization
☐ Customer intellectual property must be protected
☐ Third-party licensed materials must be used according to applicable license requirements
18. Confidentiality
The employee acknowledges their obligation to protect confidential information.
This includes:
- Customer information
- Employee information
- Business information
- Source code
- Credentials
- Security information
- Architecture information
- Commercial information
- Proprietary information
Confidentiality obligations may continue after employment ends where required by applicable agreements or law.
19. Security Awareness
The employee confirms that they have:
☐ Received required security awareness information
☐ Completed required security training
☐ Been informed about security reporting
☐ Been informed about applicable security policies
☐ Been informed about role-specific security responsibilities
☐ Understood where to obtain security guidance
20. Policy and Procedure Compliance
The employee acknowledges that they are expected to follow applicable:
- Security policies
- Security procedures
- Operating procedures
- Access requirements
- Privacy requirements
- Customer requirements
- Contractual requirements
- Legal and regulatory requirements
Failure to comply may result in investigation and appropriate action under applicable organizational processes.
21. Security Monitoring
Where permitted and appropriately communicated, the employee acknowledges that organizational systems and activities may be monitored for purposes such as:
- Security
- Fraud prevention
- Incident investigation
- Compliance
- Operational protection
- Access management
- Regulatory or contractual requirements
Monitoring should be performed in accordance with applicable law and organizational policy.
22. Employee Declaration
I confirm that:
☐ I have received access to the applicable information-security policies and requirements.
☐ I have reviewed the requirements applicable to my role.
☐ I understand my responsibility to protect organizational and customer information.
☐ I understand that I must use systems and information only for authorized purposes.
☐ I understand my responsibility to protect credentials and access.
☐ I understand how to report security incidents and suspected security weaknesses.
☐ I understand that I must comply with applicable security policies and procedures.
☐ I understand that security requirements may change and that I may be required to review updated requirements.
☐ I understand that my acknowledgement confirms receipt and review of the requirements and does not replace my responsibility to comply with them.
23. Employee Acknowledgement
Employee Name: __________________________________
Employee ID: __________________________________
Signature / Electronic Confirmation: __________________________________
Date: __________________________________
24. Manager Confirmation
The manager confirms that the employee has been informed of the security responsibilities applicable to their role.
Manager Name: __________________________________
Role: __________________________________
Signature / Electronic Confirmation: __________________________________
Date: __________________________________
25. HR / Security Confirmation
Reviewer: __________________________________
Function: ☐ HR ☐ Information Security ☐ Compliance ☐ Other
Acknowledgement Verified: ☐ Yes ☐ No
Outstanding Requirements: ______________________________
Date: __________________________________
26. Electronic Acknowledgement
Electronic acknowledgement may be recorded through an approved HR, training, compliance, or document-management system.
The record should capture, where appropriate:
| Field | Record |
|---|---|
| Employee | |
| Policy/Document | |
| Version | |
| Date Published | |
| Date Acknowledged | |
| Acknowledgement Status | |
| Training Completed | |
| System/User ID | |
| Timestamp | |
| Evidence Location |
The organization should protect acknowledgement records from unauthorized modification.
27. New Joiner Acknowledgement
Before or during onboarding, as applicable:
☐ Security policies provided
☐ Security responsibilities communicated
☐ Required security training assigned
☐ Confidentiality requirements communicated
☐ Acceptable-use requirements communicated
☐ Access requirements communicated
☐ Incident reporting process communicated
☐ Employee acknowledgement completed
☐ Evidence retained
28. Policy Change Acknowledgement
When a policy undergoes a material change:
☐ Change assessed
☐ Affected employees identified
☐ Updated policy communicated
☐ Training provided where necessary
☐ Re-acknowledgement required where appropriate
☐ Acknowledgement status tracked
☐ Overdue acknowledgements followed up
29. Annual Re-Acknowledgement
Where required by organizational policy or risk:
☐ Applicable policies identified
☐ Employees identified
☐ Updated policies distributed
☐ Employees notified
☐ Acknowledgement period established
☐ Completion monitored
☐ Overdue acknowledgements escalated
☐ Evidence retained
30. Role Change
When an employee changes roles:
☐ New responsibilities identified
☐ New security requirements identified
☐ New policies/procedures communicated
☐ Additional training assigned where required
☐ New access requirements assessed
☐ Previous access reviewed
☐ Re-acknowledgement completed where required
31. Overdue Acknowledgements
Track incomplete acknowledgements.
| Employee | Requirement | Due Date | Status | Reminder | Escalation |
|---|---|---|---|---|---|
Possible actions include:
- Reminder
- Manager notification
- Additional training
- Access review
- Escalation according to organizational policy
Any access restriction should be based on the organization’s defined risk and employment processes.
32. Declined Acknowledgement
If an employee declines to acknowledge a required security requirement:
☐ Employee contacted
☐ Reason documented
☐ Requirement explained
☐ Manager notified
☐ HR notified where appropriate
☐ Security notified where appropriate
☐ Risk assessed
☐ Corrective action determined
☐ Final outcome recorded
Declining acknowledgement does not automatically mean that the employee is exempt from applicable security requirements.
33. Acknowledgement Exceptions
Where acknowledgement cannot be completed:
☐ Reason documented
☐ Alternative communication method used
☐ Requirement communicated through an approved method
☐ Risk assessed where necessary
☐ Exception approved where required
☐ Completion tracked
☐ Exception closure date defined
34. Third-Party Personnel
Where applicable, contractors and third-party personnel may be required to acknowledge:
☐ Confidentiality requirements
☐ Security responsibilities
☐ Acceptable use
☐ Access restrictions
☐ Customer requirements
☐ Incident reporting
☐ Data protection requirements
☐ Security testing requirements
☐ Contractual security requirements
The organization’s supplier and contractual requirements should define responsibility for obtaining and retaining such acknowledgements.
35. Sensitive and Privileged Roles
Personnel with elevated access may require additional acknowledgement of:
☐ Privileged access responsibilities
☐ Production access requirements
☐ Cloud security responsibilities
☐ Source-code protection
☐ Database security
☐ Security monitoring
☐ Change-management requirements
☐ Incident escalation
☐ Confidentiality obligations
☐ Additional role-specific security controls
36. Evidence Requirements
Maintain appropriate evidence such as:
- Signed acknowledgement
- Electronic acknowledgement
- Policy version
- Distribution record
- Training record
- Employee notification
- Completion report
- Reminder records
- Exception records
- Manager confirmation
- Re-acknowledgement record
Avoid retaining unnecessary sensitive personal information.
37. Acknowledgement Register
Maintain a centralized register where appropriate.
| Employee | Department | Policy | Version | Date Issued | Date Acknowledged | Status | Evidence |
|---|---|---|---|---|---|---|---|
Status
- Pending
- Completed
- Overdue
- Exception
- Not Applicable
38. Acknowledgement Metrics
Management may monitor:
- Overall acknowledgement completion
- Overdue acknowledgements
- Completion by department
- Completion by policy
- New-joiner completion
- Annual completion
- Material-change re-acknowledgement
- Exceptions
- Declined acknowledgements
- Repeat overdue cases
Example Dashboard
| Metric | Result |
|---|---|
| Total Applicable Employees | |
| Completed | |
| Pending | |
| Overdue | |
| Exceptions | |
| Completion % |
39. Review and Monitoring
The organization should periodically review whether:
☐ Applicable personnel are identified
☐ Required policies are assigned
☐ Current versions are distributed
☐ Acknowledgements are completed
☐ Overdue items are followed up
☐ Material policy changes trigger appropriate re-acknowledgement
☐ Evidence is retained
☐ Exceptions are controlled
☐ Acknowledgement records remain accurate
40. AWS SaaS Startup Example
An AWS-based SaaS startup has 25 employees.
Employees receive:
- Information Security Policy
- Acceptable Use Policy
- Access Control Policy
- Incident Response Procedure
- Data Classification Policy
- Remote Working Policy
- AI Usage Requirements
Standard Employees
Employees acknowledge general security requirements during onboarding.
Developers
Developers additionally acknowledge:
- Source-code security
- Secrets protection
- Secure development requirements
- Production access restrictions
DevOps / Cloud Administrators
Administrators additionally acknowledge:
- AWS privileged-access requirements
- Production access
- MFA
- Logging and monitoring
- Emergency access
- Change management
Evidence
The company retains:
Employee → Policy → Version → Communication → Training → Acknowledgement → Date → Evidence
This provides a simple and defensible audit trail.
41. Startup-Friendly Acknowledgement Model
A startup does not need to create excessive acknowledgement administration.
New Joiner
Day 1–7
- Security policies
- Security responsibilities
- Confidentiality
- Acceptable use
- Incident reporting
- Required training
- Employee acknowledgement
Role Change
Perform a targeted review when:
- Access increases
- Privileged access is granted
- Production access is granted
- Sensitive information becomes accessible
- Security responsibilities change
Annual
Review and re-acknowledge material security requirements where appropriate.
Policy Change
Trigger re-acknowledgement when a change materially affects employee responsibilities.
42. Common Mistakes
Avoid:
- Treating acknowledgement as proof of compliance.
- Collecting acknowledgements without communicating the policy.
- Using outdated policy versions.
- Failing to track overdue acknowledgements.
- Requiring acknowledgement for every document without considering relevance.
- Failing to re-acknowledge material policy changes.
- Not maintaining evidence of the policy version acknowledged.
- Ignoring contractors and third-party personnel where applicable.
- Storing unnecessary sensitive employee information.
- Assuming a signed acknowledgement means employees actually understand the requirements.
- Using acknowledgement as a substitute for security awareness training.
43. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Defines overarching security expectations |
| Employee Security Responsibilities | Defines individual responsibilities |
| Security Awareness Procedure | Defines security awareness activities |
| Security Awareness Training Register | Records training |
| Policy Acknowledgement Register | Tracks acknowledgements |
| Access Management Procedure | Controls employee access |
| Employee Screening Procedure | Addresses personnel screening |
| Employment Security Clause | Establishes contractual obligations |
| Incident Response Procedure | Defines incident reporting |
| HR Security Policy | Defines personnel security requirements |
| Employee Offboarding Procedure | Removes responsibilities and access |
44. ISO/IEC 27001 Connection
Employee security acknowledgement can provide evidence that applicable information-security responsibilities and requirements have been communicated to personnel.
However, an Employee Security Acknowledgement is not itself a universally prescribed ISO/IEC 27001 document or form.
The organization should determine:
- Which personnel require acknowledgement
- Which documents require acknowledgement
- When acknowledgement is required
- Whether re-acknowledgement is necessary
- What evidence should be retained
- How exceptions are handled
based on the organization’s ISMS scope, risks, applicable controls, contractual requirements, legal/regulatory obligations, and business needs.
Acknowledgement should also not be confused with security awareness or competence. Acknowledgement demonstrates that a requirement was communicated and reviewed; it does not, by itself, demonstrate that the employee understood or followed it.
45. Audit Evidence Checklist
☐ Approved policy
☐ Current policy version
☐ Policy distribution evidence
☐ Employee acknowledgement
☐ Electronic acknowledgement record
☐ Security training record
☐ New-joiner evidence
☐ Material-change re-acknowledgement
☐ Overdue tracking
☐ Exception records
☐ Manager follow-up
☐ Third-party acknowledgement where applicable
☐ Privileged-role acknowledgement where applicable
☐ Acknowledgement register
☐ Management reporting
46. Final Employee Security Acknowledgement Audit Trail
For an employee, the organization should be able to demonstrate:
Who is the employee?
What role do they perform?
What information and systems can they access?
What security responsibilities apply to them?
Which policies were provided?
Which version was provided?
When was it communicated?
Was required training completed?
Did the employee acknowledge the requirements?
Were material changes communicated?
Were overdue acknowledgements followed up?
What evidence was retained?
Final Principle
An acknowledgement is evidence of communication and review—not proof of security compliance.
The organization should combine acknowledgement with security awareness, training, access controls, monitoring, compliance reviews, and actual evidence of secure behavior.
