1. Purpose
The Exit Security Acknowledgement records an employee’s, contractor’s, consultant’s, or other user’s confirmation of their continuing security obligations when their employment, contract, assignment, or access to the organization ends.
The acknowledgement helps demonstrate that the individual has been informed of their responsibilities regarding:
- Confidential information
- Personal and customer information
- Intellectual property
- Company assets
- Credentials and authentication information
- Source code and technical information
- Security-sensitive information
- Return or deletion of organizational information
- Continuing confidentiality obligations
- Unauthorized access after departure
- Security incident reporting
- Intellectual-property obligations
- Applicable contractual requirements
2. Applicability
This acknowledgement should be completed by:
☐ Employee
☐ Contractor
☐ Consultant
☐ Temporary worker
☐ Intern
☐ Supplier personnel
☐ Other: __________________________
Individual Information
| Field | Details |
|---|---|
| Name | |
| Employee/Contractor ID | |
| Job Title/Role | |
| Department/Project | |
| Manager/Business Owner | |
| Supplier/Agency | |
| Start Date | |
| Exit Date | |
| Exit Type | ☐ Resignation ☐ Termination ☐ Contract End ☐ Role Change ☐ Other |
| Acknowledgement Date |
3. Security Acknowledgement
I acknowledge that my access to the organization’s systems, information, facilities, applications, services, and assets is being terminated or changed as part of my exit or role change.
I understand and agree that:
3.1 Confidential Information
I will continue to protect confidential and restricted information obtained during my relationship with the organization.
This may include:
- Customer information
- Personal data
- Financial information
- Business plans
- Security information
- Credentials
- Source code
- Architecture information
- Product information
- Internal documentation
- Contracts
- Supplier information
- Vulnerability information
- Other confidential business information
I will not disclose, copy, publish, sell, transfer, or otherwise misuse such information.
☐ Acknowledged
4. Personal and Customer Information
I acknowledge that personal and customer information accessed during my engagement remains subject to applicable organizational, contractual, privacy, and legal requirements.
I will not retain, use, disclose, or transfer such information after my access has ended unless specifically authorized.
☐ Acknowledged
5. Company Information and Documents
I confirm that organizational documents and information in my possession or control have been:
☐ Returned
☐ Transferred to the organization
☐ Deleted as instructed
☐ Retained only where specifically authorized
☐ Not applicable
Examples include:
- Documents
- Reports
- Spreadsheets
- Presentations
- Emails
- Source code
- Architecture diagrams
- Project documentation
- Security assessments
- Customer information
- Supplier information
Comments
6. Credentials and Authentication Information
I confirm that I will not retain or use organizational authentication information after my access has been revoked.
This includes:
- Passwords
- API keys
- Access tokens
- SSH keys
- Cloud credentials
- VPN credentials
- Certificates
- Recovery codes
- Security keys
- Administrative credentials
- Other authentication information
☐ Acknowledged
I understand that attempting to access organizational systems after authorization has ended is prohibited.
☐ Acknowledged
7. Company Assets
I confirm that organizational assets provided to me have been returned or otherwise handled as instructed.
Examples include:
☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Monitor
☐ Security key/token
☐ Access card
☐ Keys
☐ Removable media
☐ Network equipment
☐ Development equipment
☐ Other: ______________________
Asset Status
☐ All assets returned
☐ Assets returned with exceptions
☐ No company assets assigned
Exceptions
8. Intellectual Property
I acknowledge that intellectual property created, developed, modified, or contributed to as part of my employment, contract, or engagement may be subject to applicable employment, contractor, supplier, or intellectual-property agreements.
I will not improperly retain, disclose, copy, transfer, or use organizational intellectual property after my relationship with the organization ends.
☐ Acknowledged
9. Source Code and Technical Information
If applicable, I confirm that I will not retain or use organizational:
- Source code
- Repository copies
- Development credentials
- Deployment information
- Architecture diagrams
- Infrastructure configurations
- Security configurations
- Database information
- CI/CD information
- Technical documentation
after access has ended, except where expressly authorized.
☐ Acknowledged
☐ Not Applicable
10. Security Systems and Administrative Access
I acknowledge that my access to organizational systems and services will be removed or adjusted.
These may include:
☐ Corporate identity
☐ Email
☐ VPN
☐ Cloud platforms
☐ AWS
☐ Azure
☐ Google Cloud
☐ Production systems
☐ Databases
☐ Source-code repositories
☐ CI/CD
☐ SaaS applications
☐ Security systems
☐ Monitoring systems
☐ Customer systems
☐ Supplier systems
☐ Physical facilities
I will not attempt to bypass, circumvent, or regain access after authorization has ended.
☐ Acknowledged
11. Confidentiality After Exit
I understand that confidentiality obligations may continue after my employment, contract, or engagement ends.
I agree to continue protecting information that I am legally or contractually required to keep confidential.
☐ Acknowledged
12. Information Retention
I confirm that I will not intentionally retain organizational information for personal use or convenience.
If information is required to be retained for an authorized legal, contractual, regulatory, or other legitimate reason, I will follow the organization’s instructions.
☐ Acknowledged
13. Personal Devices
If I used a personal device to access organizational information, I understand that I must follow the organization’s applicable BYOD, information-security, and data-removal requirements.
I confirm that:
☐ Organizational accounts have been removed where instructed
☐ Organizational information has been returned/deleted where required
☐ Organizational credentials have not been retained
☐ Authentication tokens have been removed/revoked where applicable
☐ I have followed the organization’s instructions
☐ Not Applicable
14. Security Incident Reporting After Exit
I understand that if I become aware of a security incident, data breach, unauthorized disclosure, or accidental release of organizational information after my exit, I should report it through the organization’s designated contact or reporting channel where required.
Security Contact
Contact: ______________________________
Email/Phone: __________________________
15. Continuing Legal and Contractual Obligations
I acknowledge that my exit does not automatically terminate obligations that survive the end of my employment or engagement.
These may include:
☐ Confidentiality
☐ Intellectual-property obligations
☐ Data-protection obligations
☐ Customer confidentiality
☐ Supplier confidentiality
☐ Information-return obligations
☐ Information-deletion obligations
☐ Other contractual obligations
Relevant Agreement
Agreement/Reference: ______________________________
16. Confirmation of No Unauthorized Retention
I confirm, to the best of my knowledge, that I have not intentionally retained unauthorized copies of organizational confidential, restricted, personal, customer, security, or proprietary information.
☐ Confirmed
Exceptions or Disclosures
If any information remains in my possession or control, I have disclosed it below:
17. Confirmation of No Unauthorized Access
I understand that after my authorization ends, I must not:
- Attempt to log in to organizational systems
- Use old credentials
- Use retained access tokens
- Access customer environments
- Access cloud accounts
- Access source-code repositories
- Access databases
- Access VPNs
- Access administrative systems
- Circumvent access controls
- Ask another person to provide unauthorized access
☐ Acknowledged
18. Security Investigation and Evidence
I understand that organizational information, devices, accounts, logs, or other records may be subject to legitimate security, legal, regulatory, or investigative requirements.
I will not intentionally delete, alter, conceal, or destroy information or evidence that I have been instructed to preserve.
☐ Acknowledged
19. Exit Checklist Confirmation
The individual confirms that the following have been addressed where applicable:
| Area | Status |
|---|---|
| Organizational access | ☐ Complete ☐ N/A |
| Privileged access | ☐ Complete ☐ N/A |
| Cloud access | ☐ Complete ☐ N/A |
| Production access | ☐ Complete ☐ N/A |
| Source-code access | ☐ Complete ☐ N/A |
| Customer access | ☐ Complete ☐ N/A |
| Supplier access | ☐ Complete ☐ N/A |
| Company assets | ☐ Complete ☐ N/A |
| Organizational information | ☐ Complete ☐ N/A |
| Credentials/secrets | ☐ Complete ☐ N/A |
| Intellectual property | ☐ Complete ☐ N/A |
| Confidentiality obligations | ☐ Complete ☐ N/A |
| Data return/deletion | ☐ Complete ☐ N/A |
| Continuing obligations | ☐ Complete ☐ N/A |
20. Individual Declaration
I confirm that:
I have read and understood this Exit Security Acknowledgement. I understand that my access to the organization’s systems, information, facilities, and assets is being terminated or changed. I understand my continuing responsibilities regarding confidentiality, information protection, intellectual property, data protection, credentials, company assets, and unauthorized access. I confirm that I have followed the organization’s exit instructions and have disclosed any known exceptions or retained information.
Individual
Name: ______________________________________
Signature: ___________________________________
Date: _______________________________________
21. Organization Confirmation
The organization confirms that the exit security requirements applicable to the individual have been reviewed.
Manager/Business Owner
Name: ______________________________________
Signature/Approval: ___________________________
Date: _______________________________________
HR/People/Supplier Owner
Name: ______________________________________
Signature/Approval: ___________________________
Date: _______________________________________
Security/IT Reviewer
Name: ______________________________________
Signature/Approval: ___________________________
Date: _______________________________________
22. Exceptions and Follow-Up Actions
| Exception | Risk | Action Required | Owner | Due Date | Status |
|---|---|---|---|---|---|
No exit record should be marked fully closed while significant security exceptions remain unresolved unless they have been formally accepted through the organization’s risk-acceptance process.
23. Record Retention
The completed acknowledgement should be retained according to the organization’s document-retention requirements.
The record may be associated with:
- Employee/contractor exit record
- Access revocation evidence
- Asset return record
- Supplier offboarding record
- Security investigation record where applicable
- HR record where appropriate
The acknowledgement should not contain passwords, API keys, private keys, recovery codes, or other authentication secrets.
24. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Employee Offboarding Policy | Defines overall employee exit requirements |
| Employee Termination Security Checklist | Provides termination security checks |
| Contractor Offboarding Procedure | Defines contractor exit process |
| Privileged User Offboarding Checklist | Handles privileged-user exit |
| Access Revocation Checklist | Provides detailed access removal |
| Asset Return Checklist | Handles organizational asset recovery |
| Confidentiality Agreement | Defines confidentiality obligations |
| Employment Security Clause | Establishes personnel security obligations |
| Supplier Offboarding Checklist | Handles supplier-level exit |
| Incident Response Procedure | Handles security incidents |
| Evidence Preservation Procedure | Protects investigation evidence |
25. ISO 27001 / SOC 2 Connection
An Exit Security Acknowledgement supports the organization’s personnel-security, access-control, information-protection, asset-management, confidentiality, and offboarding processes.
For ISO 27001, the exact applicable controls and evidence should be determined through the organization’s risk assessment and Statement of Applicability.
For SOC 2, the acknowledgement can provide supporting evidence that individuals were informed of their continuing security obligations and that the organization formally documented the exit process.
The acknowledgement should complement—not replace—the technical access-revocation, asset-return, and offboarding procedures.
26. Quick Audit Checklist
☐ Exit date confirmed
☐ Individual identified
☐ Employee/contractor status identified
☐ Confidentiality obligations acknowledged
☐ Personal/customer information obligations acknowledged
☐ Organizational information addressed
☐ Credentials addressed
☐ Source code addressed
☐ Intellectual property addressed
☐ Company assets addressed
☐ Personal-device requirements addressed
☐ Unauthorized access prohibition acknowledged
☐ Continuing obligations acknowledged
☐ Security incident reporting requirement communicated
☐ Investigation/evidence requirements considered
☐ Exceptions documented
☐ Individual acknowledgement obtained
☐ Organization approval completed
☐ Record retained
27. Final Audit Trail
For an individual leaving the organization, the organization should be able to demonstrate:
Who left the organization?
When did the relationship end?
What security obligations applied?
Were continuing confidentiality obligations acknowledged?
Was organizational information returned, transferred, or deleted?
Were credentials and access addressed?
Were company assets returned?
Were customer and personal-data obligations addressed?
Were intellectual-property obligations communicated?
Was unauthorized post-exit access prohibited?
Were exceptions documented?
Did the individual acknowledge the requirements?
Who from the organization reviewed and approved the exit?
Final Principle
Exit security is not complete when a person leaves the organization. It is complete when access is removed, information and assets are protected, continuing obligations are acknowledged, exceptions are addressed, and the organization can demonstrate the entire process through evidence.
