ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Termination Security Checklist

Employee Termination Security Checklist

1. Purpose

The Employee Termination Security Checklist provides a structured process for securely managing the termination of an employee, contractor, intern, consultant, or other personnel.

The objective is to ensure that when employment or engagement ends:

  • Access is revoked at the appropriate time
  • Organizational information remains protected
  • Company assets are recovered
  • Privileged and production access is removed
  • Cloud, SaaS, source-code, and remote access are addressed
  • Credentials, tokens, and secrets are managed
  • Business responsibilities are transferred
  • Confidentiality obligations remain protected
  • Security incidents or investigations are not accidentally disrupted
  • Evidence of completion is retained

Core Principle

Identify → Notify → Assess → Revoke → Recover → Protect → Transfer → Verify → Record → Close


2. When to Use

Use this checklist when:

☐ Employee resignation
☐ Involuntary termination
☐ Contract completion
☐ Internship completion
☐ Consultant/contractor termination
☐ Immediate/high-risk termination
☐ Long-term leave requiring access suspension
☐ Organizational restructuring
☐ Role elimination
☐ Supplier/third-party personnel departure

The checklist should be adapted based on the person’s role, access, information handled, and security risk.


3. Employee Termination Information

FieldDetails
Employee Name
Employee ID
Department
Job Title
Manager
Employment Type
Termination Type
Notice Date
Effective Termination Date
Effective Termination Time
Risk Level
HR Owner
IT Owner
Security Reviewer
Checklist ID
Completion Date

4. Termination Type

☐ Voluntary resignation
☐ Involuntary termination
☐ Immediate termination
☐ Contract completion
☐ Internship completion
☐ Retirement
☐ Redundancy
☐ Role elimination
☐ Other: __________________________

Termination Risk

☐ Low
☐ Medium
☐ High
☐ Critical

Risk Factors

☐ Privileged access
☐ Production access
☐ AWS/cloud access
☐ Source-code access
☐ Database access
☐ Customer information
☐ Personal data
☐ Financial information
☐ Security administration
☐ Access to secrets/credentials
☐ Active security investigation
☐ Access to critical business systems
☐ Other: __________________________


5. Termination Notification

Confirm that the appropriate personnel have been notified.

☐ HR notified
☐ Manager notified
☐ IT notified
☐ Information Security notified where required
☐ System owners notified where required
☐ Facilities/security notified where required
☐ Relevant business owners notified
☐ Termination timing confirmed
☐ Immediate termination requirements identified

Notification Record

Person/TeamNotification DateMethodConfirmed By
HR
Manager
IT
Information Security
Facilities
System Owners

6. Termination Timing

Define when access must be removed.

Termination Date: __________________

Termination Time: __________________

Access Revocation Deadline: __________________

☐ Access removal scheduled
☐ Immediate access removal required
☐ Access removal coordinated with termination meeting
☐ After-hours termination process considered where required
☐ Time zone considered for remote employees

For high-risk termination, access removal should be coordinated so that unnecessary access does not remain available after termination.


7. Access Inventory

Identify all access held by the employee.

☐ Corporate identity
☐ Email
☐ VPN
☐ MFA
☐ SSO
☐ AWS/cloud
☐ Azure/GCP where applicable
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ Production systems
☐ Databases
☐ SaaS applications
☐ CRM
☐ HR systems
☐ Finance systems
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ Collaboration tools
☐ Password manager
☐ VPN/firewall
☐ Remote-access tools
☐ Physical access
☐ Other systems


8. Corporate Identity

☐ Corporate identity disabled
☐ Login access removed
☐ SSO access disabled
☐ MFA access revoked
☐ Recovery methods removed
☐ Authentication devices addressed
☐ Active sessions terminated where appropriate
☐ Authentication tokens revoked
☐ Account status verified

Evidence


9. Email and Collaboration

☐ Corporate email disabled
☐ Active email sessions terminated
☐ Email forwarding reviewed
☐ Automatic forwarding removed
☐ Mailbox ownership transferred where required
☐ Business-critical correspondence identified
☐ Shared mailbox access reviewed
☐ Slack/Teams access removed
☐ Collaboration groups reviewed
☐ Calendar ownership transferred
☐ Shared files reviewed

Email termination alone should not be treated as proof that all organizational access has been removed.


10. Cloud Access

If the employee has cloud access:

☐ AWS access reviewed
☐ IAM users disabled/deleted where appropriate
☐ IAM roles reviewed
☐ Role assignments removed
☐ Access keys revoked
☐ MFA devices addressed
☐ Temporary credentials invalidated where applicable
☐ Console access removed
☐ CLI/API access addressed
☐ Cloud security groups/permissions reviewed where applicable
☐ Cloud ownership transferred
☐ Cloud logs preserved where required


11. Source-Code Access

If the employee has development access:

☐ GitHub access removed
☐ GitLab access removed
☐ Bitbucket access removed
☐ Repository permissions reviewed
☐ Organization membership removed
☐ Production repository access removed
☐ CI/CD access removed
☐ Deployment permissions removed
☐ Code-signing access reviewed
☐ Repository ownership transferred
☐ Pull-request responsibilities transferred
☐ Personal access tokens revoked


12. Production Access

For production access:

☐ Production access identified
☐ Production accounts disabled
☐ Privileged roles removed
☐ SSH access removed
☐ Bastion access removed
☐ Database access removed
☐ Kubernetes access removed
☐ Cloud production permissions removed
☐ Monitoring access removed
☐ Emergency access credentials reviewed
☐ Shared credentials rotated where necessary

Production Access Verification

SystemAccess TypeRevokedVerified ByDate
☐
☐
☐

13. Privileged Access

If the employee had privileged access:

☐ Administrator access identified
☐ Privileged accounts disabled
☐ Privileged roles removed
☐ Root-equivalent access reviewed
☐ Break-glass access reviewed
☐ Shared administrator credentials changed where necessary
☐ Privileged sessions terminated
☐ Privileged access logs preserved where appropriate
☐ New administrator assigned where required

Privileged Access Verification


14. SaaS Applications

Review all relevant SaaS platforms.

ApplicationAccess TypeRevokedVerified By
☐
☐
☐
☐

Examples may include:

  • CRM
  • HR platform
  • Accounting
  • Project management
  • Cloud security tools
  • Password manager
  • Customer support
  • Analytics
  • Marketing platforms
  • Communication platforms

15. Credentials, Tokens and Secrets

Identify credentials that may have been accessible to the employee.

☐ Passwords reviewed
☐ API keys reviewed
☐ Personal access tokens reviewed
☐ SSH keys reviewed
☐ Cloud credentials reviewed
☐ Database credentials reviewed
☐ Service-account access reviewed
☐ Certificates reviewed
☐ Encryption-key access reviewed
☐ Secrets stored in password manager reviewed
☐ Shared secrets rotated where necessary
☐ Credentials embedded in scripts/configuration reviewed

Secret Rotation Required?

☐ Yes
☐ No

Details


16. Customer and Supplier Access

If the employee had access to external organizations:

☐ Customer portals reviewed
☐ Customer accounts removed
☐ Supplier portals reviewed
☐ Third-party systems reviewed
☐ External collaboration accounts removed
☐ Customer contact responsibilities transferred
☐ Supplier responsibilities transferred
☐ External administrator access reviewed


17. Information Protection

Identify information handled by the employee.

☐ Customer information
☐ Personal data
☐ Confidential information
☐ Restricted information
☐ Source code
☐ Security information
☐ Financial information
☐ Contracts
☐ Credentials/secrets
☐ Intellectual property

Information Handling

☐ Information ownership transferred
☐ Business files transferred where required
☐ Unauthorized copies addressed where appropriate
☐ Local storage reviewed where permitted
☐ Cloud storage reviewed
☐ Shared folders reviewed
☐ Personal repositories reviewed where applicable and lawful
☐ Confidentiality requirements reiterated


18. Data Return and Deletion

Where applicable:

☐ Company information returned
☐ Company information transferred to authorized owner
☐ Unauthorized copies addressed
☐ Information deleted where authorized and required
☐ Cloud storage reviewed
☐ Local storage addressed
☐ Removable media addressed
☐ Data retention requirements considered

Do not delete information that must be retained for legal, regulatory, contractual, audit, or investigation purposes.


19. Company Assets

Identify assets assigned to the employee.

☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Security token
☐ Smart card
☐ USB/removable media
☐ Hardware security key
☐ Monitor
☐ Other equipment

Asset Return Record

AssetAsset IDReturnedConditionVerified By
☐
☐
☐

20. Device Security

After asset recovery:

☐ Device received
☐ Device ownership verified
☐ Device condition recorded
☐ Device security status reviewed
☐ Corporate account removed
☐ Device management status reviewed
☐ Encryption status verified where applicable
☐ Device retained for investigation if required
☐ Secure wipe performed when authorized
☐ Device reassigned only after appropriate security processing


21. Mobile Devices

For company-managed mobile devices:

☐ Corporate account removed
☐ MDM access reviewed
☐ Device lock enforced where required
☐ Corporate applications removed
☐ Corporate certificates removed
☐ Corporate credentials removed
☐ Remote wipe performed where authorized
☐ SIM/eSIM addressed
☐ Device recovered


22. Physical Access

☐ Office access card returned
☐ Building access disabled
☐ Restricted-area access removed
☐ Data-center access removed
☐ Visitor privileges removed
☐ Parking access addressed
☐ Physical keys returned
☐ Security tokens returned

Physical Access Verification


23. Business Ownership Transfer

Identify business responsibilities that must continue.

☐ Projects reassigned
☐ Customer responsibilities transferred
☐ Supplier responsibilities transferred
☐ System ownership transferred
☐ Repository ownership transferred
☐ Documentation ownership transferred
☐ Security responsibilities transferred
☐ Incident-response responsibilities transferred
☐ Business continuity responsibilities transferred


24. Knowledge Transfer

Where required:

☐ Operational knowledge transferred
☐ Critical procedures documented
☐ System documentation updated
☐ Architecture knowledge transferred
☐ Customer knowledge transferred
☐ Supplier knowledge transferred
☐ Security knowledge transferred
☐ Emergency procedures transferred


25. Confidentiality

Confirm continuing confidentiality obligations.

☐ NDA/confidentiality agreement reviewed
☐ Continuing confidentiality obligations communicated
☐ Intellectual property obligations reviewed
☐ Customer confidentiality obligations reviewed
☐ Security responsibilities communicated
☐ Post-termination restrictions reviewed where applicable

Legal obligations should be reviewed by appropriate legal personnel.


26. Security Incident or Investigation Check

Before closing the termination:

☐ Employee involved in active security investigation?
☐ Employee involved in unresolved security incident?
☐ Relevant logs preserved?
☐ Evidence preserved?
☐ Investigation owner notified?
☐ Legal/HR notified where required?
☐ Account deletion coordinated with investigation requirements?

Investigation Reference

Do not destroy potentially relevant evidence solely because the employee has left the organization.


27. High-Risk Termination

For high-risk or immediate termination:

☐ Risk assessment completed
☐ Security/HR coordination completed
☐ Access revocation synchronized
☐ Privileged access removed first where appropriate
☐ Cloud access removed
☐ Production access removed
☐ Source-code access removed
☐ VPN access removed
☐ Email/session access addressed
☐ Credentials/secrets reviewed
☐ Relevant logs preserved
☐ Assets secured
☐ Investigation requirements assessed
☐ Independent verification completed


28. Remote Employee

For remote employees:

☐ Remote access disabled
☐ VPN access removed
☐ Cloud access removed
☐ SaaS access removed
☐ Device recovery arranged
☐ Shipping/collection documented
☐ Company information addressed
☐ BYOD access removed where applicable
☐ Authentication devices recovered or revoked


29. BYOD

If Bring Your Own Device was permitted:

☐ Corporate accounts removed
☐ MDM controls removed or updated
☐ Corporate applications removed
☐ Corporate certificates removed
☐ Corporate data removed where authorized
☐ Tokens/session access revoked
☐ Corporate storage access removed
☐ Personal data protected during corporate-data removal

BYOD actions should follow applicable law and the organization’s approved BYOD policy.


30. Final Access Verification

A second person should verify termination activities for sensitive or high-risk roles where practical.

☐ Identity disabled
☐ Email disabled
☐ VPN disabled
☐ MFA addressed
☐ Cloud access removed
☐ AWS access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Physical access removed
☐ Customer access removed
☐ Supplier access removed

Verification

Verified By: __________________________

Date/Time: __________________________

Result: ☐ Complete ☐ Exceptions Identified


31. Exceptions

Document any access or activity that could not be completed immediately.

ExceptionReasonRiskCompensating ControlOwnerDue DateStatus

All exceptions should be risk-assessed and formally approved where required.


32. Termination Completion Record

ActivityCompletedEvidenceVerified By
HR notification☐
Access review☐
Identity revocation☐
Cloud access removal☐
Production access removal☐
Source-code access removal☐
SaaS access removal☐
Credential review☐
Asset recovery☐
Physical access removal☐
Information protection☐
Ownership transfer☐
Final verification☐

33. Evidence Retention

Retain appropriate evidence such as:

☐ Termination notification
☐ Access-revocation records
☐ IAM evidence
☐ SaaS deactivation evidence
☐ Asset-return record
☐ Physical-access removal evidence
☐ Credential-rotation evidence
☐ Ownership-transfer record
☐ Final verification
☐ Approved exceptions
☐ Investigation records where applicable

Do not unnecessarily retain passwords, private keys, authentication secrets, or other sensitive credentials as evidence.


34. Termination Register

Maintain a record of completed terminations where appropriate.

Employee IDTermination DateRiskAccess RevokedAssets ReturnedVerifiedStatus
☐☐☐
☐☐☐

35. Completion Criteria

The termination should not be marked Complete until:

☐ Required access has been revoked
☐ Privileged access has been addressed
☐ Cloud and SaaS access has been addressed
☐ Production/source-code access has been addressed
☐ Assets have been recovered or exception approved
☐ Information responsibilities have been transferred
☐ Credentials/secrets have been reviewed
☐ Physical access has been removed
☐ Investigation requirements have been addressed
☐ Exceptions have been documented
☐ Final verification has been completed
☐ Evidence has been retained


36. Final Approval

Employee: ______________________________

Manager: ______________________________

HR Representative: ______________________________

IT Representative: ______________________________

Security Reviewer: ______________________________

Termination Date: ______________________________

Checklist Completion Date: ______________________________

Overall Status:

☐ Complete
☐ Complete with Approved Exceptions
☐ Further Action Required

Comments


37. AWS SaaS Startup Example

A DevOps engineer leaves a SaaS startup and has access to:

  • AWS production
  • GitHub
  • CI/CD
  • Production database
  • Monitoring
  • VPN
  • Slack
  • Corporate email
  • Password manager

Termination Actions

HR → confirms termination time.

Manager → identifies responsibilities and replacement owners.

IT → disables corporate identity, VPN, email, and collaboration access.

Security → verifies privileged-access removal.

Cloud Owner → revokes AWS IAM access, access keys, roles, and MFA-related access as applicable.

Engineering → removes GitHub, CI/CD, deployment, and repository permissions.

Database Owner → removes production database access.

Security → reviews whether shared credentials, tokens, or secrets require rotation.

Asset Team → recovers company laptop and security keys.

Second Reviewer → independently verifies that critical access has been removed.

Audit Trail

Termination Notice → Risk Assessment → Access Inventory → Revoke Access → Rotate Required Secrets → Recover Assets → Transfer Ownership → Verify → Record


38. Startup-Friendly Termination Model

For a small startup, the process can remain simple:

Step 1 — HR Notification

Notify the manager and IT/security.

Step 2 — Access Inventory

Check:

  • Email
  • Google/Microsoft account
  • AWS
  • GitHub
  • VPN
  • SaaS
  • Production
  • Database
  • Password manager

Step 3 — Revoke

Disable accounts and remove permissions.

Step 4 — Protect

Review tokens, API keys, shared passwords, secrets, and sensitive information.

Step 5 — Recover

Recover laptop, phone, security keys, cards, and other assets.

Step 6 — Transfer

Transfer projects, repositories, customer relationships, and system ownership.

Step 7 — Verify

A second person verifies critical access removal.

Step 8 — Record

Store evidence and close the termination record.


39. Common Mistakes

Avoid:

  • Disabling only the email account.
  • Waiting until the next business day for access removal.
  • Forgetting AWS/cloud accounts.
  • Forgetting GitHub/GitLab access.
  • Forgetting CI/CD permissions.
  • Forgetting production databases.
  • Forgetting VPN access.
  • Forgetting SaaS applications.
  • Forgetting physical access.
  • Forgetting API keys and tokens.
  • Forgetting shared credentials.
  • Failing to transfer system ownership.
  • Deleting evidence needed for an investigation.
  • Wiping a device before checking whether evidence must be preserved.
  • Marking termination complete without independent verification.
  • Leaving undocumented exceptions.
  • Assuming HR notification automatically removes technical access.

40. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security requirements
Employee Offboarding PolicyDefines overall offboarding requirements
Employee Offboarding ChecklistProvides broader operational offboarding steps
Joiner-Mover-Leaver ProcedureManages personnel lifecycle
Access Management ProcedureControls account and access lifecycle
Privileged Access ProcedureControls administrative access
Cloud Access Review ChecklistVerifies cloud access
Source Code Access Review ChecklistVerifies development access
Asset Return ProcedureControls company asset recovery
Confidentiality AgreementDefines confidentiality obligations
Information Classification PolicyDefines information protection requirements
Security Investigation ProcedureProtects investigation evidence
Security Incident Management PolicyAddresses security incidents
Security Violation Investigation ProcedureHandles suspected personnel violations
Risk RegisterRecords significant termination-related risks
Corrective Action TrackerTracks unresolved termination findings

41. ISO 27001 Connection

Employee termination security supports the organization’s management of personnel security, access rights, authentication, information protection, asset handling, and organizational responsibilities throughout the employment lifecycle.

The Employee Termination Security Checklist is not itself a universally mandatory ISO 27001 form. The organization should determine the appropriate termination controls based on:

  • ISMS scope
  • Risk assessment
  • Personnel roles
  • Information handled
  • System access
  • Privileged access
  • Legal and regulatory requirements
  • Customer requirements
  • Contractual obligations
  • Business requirements

The organization should be able to demonstrate that termination or change of employment does not leave inappropriate access or uncontrolled information behind.


42. Final Audit Checklist

Before closing the termination, confirm:

☐ Termination formally authorized
☐ Termination date/time recorded
☐ Risk assessed
☐ Access inventory completed
☐ Corporate identity disabled
☐ Email disabled
☐ VPN removed
☐ MFA addressed
☐ Cloud access removed
☐ AWS access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Customer access removed
☐ Supplier access removed
☐ Tokens/API keys reviewed
☐ Shared credentials rotated where necessary
☐ Company assets recovered
☐ Physical access removed
☐ Information transferred/protected
☐ Business ownership transferred
☐ Confidentiality obligations confirmed
☐ Investigation requirements checked
☐ Exceptions documented
☐ Final verification completed
☐ Evidence retained
☐ Termination record closed


43. Final Audit Trail

For every significant termination, the organization should be able to demonstrate:

When was the employee terminated?
Who authorized the termination?
What was the termination risk?
What access did the employee have?
When was access revoked?
Was privileged access removed?
Was cloud/AWS access removed?
Was production access removed?
Was source-code access removed?
Were SaaS and VPN accounts removed?
Were credentials, tokens, and secrets reviewed?
Were company assets recovered?
Was organizational information protected?
Were responsibilities transferred?
Were investigation requirements considered?
Who verified completion?
Were exceptions documented and approved?
What evidence proves the termination was completed?

Final Principle

An employee termination is not complete when HR records the departure. It is complete when access, information, assets, responsibilities, credentials, physical access, and security dependencies have been appropriately addressed, verified, and recorded.