ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Exit Security Acknowledgement

Exit Security Acknowledgement

1. Purpose

The Exit Security Acknowledgement records an employee’s, contractor’s, consultant’s, or other user’s confirmation of their continuing security obligations when their employment, contract, assignment, or access to the organization ends.

The acknowledgement helps demonstrate that the individual has been informed of their responsibilities regarding:

  • Confidential information
  • Personal and customer information
  • Intellectual property
  • Company assets
  • Credentials and authentication information
  • Source code and technical information
  • Security-sensitive information
  • Return or deletion of organizational information
  • Continuing confidentiality obligations
  • Unauthorized access after departure
  • Security incident reporting
  • Intellectual-property obligations
  • Applicable contractual requirements

2. Applicability

This acknowledgement should be completed by:

☐ Employee
☐ Contractor
☐ Consultant
☐ Temporary worker
☐ Intern
☐ Supplier personnel
☐ Other: __________________________

Individual Information

FieldDetails
Name
Employee/Contractor ID
Job Title/Role
Department/Project
Manager/Business Owner
Supplier/Agency
Start Date
Exit Date
Exit Type☐ Resignation ☐ Termination ☐ Contract End ☐ Role Change ☐ Other
Acknowledgement Date

3. Security Acknowledgement

I acknowledge that my access to the organization’s systems, information, facilities, applications, services, and assets is being terminated or changed as part of my exit or role change.

I understand and agree that:

3.1 Confidential Information

I will continue to protect confidential and restricted information obtained during my relationship with the organization.

This may include:

  • Customer information
  • Personal data
  • Financial information
  • Business plans
  • Security information
  • Credentials
  • Source code
  • Architecture information
  • Product information
  • Internal documentation
  • Contracts
  • Supplier information
  • Vulnerability information
  • Other confidential business information

I will not disclose, copy, publish, sell, transfer, or otherwise misuse such information.

☐ Acknowledged


4. Personal and Customer Information

I acknowledge that personal and customer information accessed during my engagement remains subject to applicable organizational, contractual, privacy, and legal requirements.

I will not retain, use, disclose, or transfer such information after my access has ended unless specifically authorized.

☐ Acknowledged


5. Company Information and Documents

I confirm that organizational documents and information in my possession or control have been:

☐ Returned
☐ Transferred to the organization
☐ Deleted as instructed
☐ Retained only where specifically authorized
☐ Not applicable

Examples include:

  • Documents
  • Reports
  • Spreadsheets
  • Presentations
  • Emails
  • Source code
  • Architecture diagrams
  • Project documentation
  • Security assessments
  • Customer information
  • Supplier information

Comments


6. Credentials and Authentication Information

I confirm that I will not retain or use organizational authentication information after my access has been revoked.

This includes:

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Cloud credentials
  • VPN credentials
  • Certificates
  • Recovery codes
  • Security keys
  • Administrative credentials
  • Other authentication information

☐ Acknowledged

I understand that attempting to access organizational systems after authorization has ended is prohibited.

☐ Acknowledged


7. Company Assets

I confirm that organizational assets provided to me have been returned or otherwise handled as instructed.

Examples include:

☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Monitor
☐ Security key/token
☐ Access card
☐ Keys
☐ Removable media
☐ Network equipment
☐ Development equipment
☐ Other: ______________________

Asset Status

☐ All assets returned
☐ Assets returned with exceptions
☐ No company assets assigned

Exceptions


8. Intellectual Property

I acknowledge that intellectual property created, developed, modified, or contributed to as part of my employment, contract, or engagement may be subject to applicable employment, contractor, supplier, or intellectual-property agreements.

I will not improperly retain, disclose, copy, transfer, or use organizational intellectual property after my relationship with the organization ends.

☐ Acknowledged


9. Source Code and Technical Information

If applicable, I confirm that I will not retain or use organizational:

  • Source code
  • Repository copies
  • Development credentials
  • Deployment information
  • Architecture diagrams
  • Infrastructure configurations
  • Security configurations
  • Database information
  • CI/CD information
  • Technical documentation

after access has ended, except where expressly authorized.

☐ Acknowledged
☐ Not Applicable


10. Security Systems and Administrative Access

I acknowledge that my access to organizational systems and services will be removed or adjusted.

These may include:

☐ Corporate identity
☐ Email
☐ VPN
☐ Cloud platforms
☐ AWS
☐ Azure
☐ Google Cloud
☐ Production systems
☐ Databases
☐ Source-code repositories
☐ CI/CD
☐ SaaS applications
☐ Security systems
☐ Monitoring systems
☐ Customer systems
☐ Supplier systems
☐ Physical facilities

I will not attempt to bypass, circumvent, or regain access after authorization has ended.

☐ Acknowledged


11. Confidentiality After Exit

I understand that confidentiality obligations may continue after my employment, contract, or engagement ends.

I agree to continue protecting information that I am legally or contractually required to keep confidential.

☐ Acknowledged


12. Information Retention

I confirm that I will not intentionally retain organizational information for personal use or convenience.

If information is required to be retained for an authorized legal, contractual, regulatory, or other legitimate reason, I will follow the organization’s instructions.

☐ Acknowledged


13. Personal Devices

If I used a personal device to access organizational information, I understand that I must follow the organization’s applicable BYOD, information-security, and data-removal requirements.

I confirm that:

☐ Organizational accounts have been removed where instructed
☐ Organizational information has been returned/deleted where required
☐ Organizational credentials have not been retained
☐ Authentication tokens have been removed/revoked where applicable
☐ I have followed the organization’s instructions

☐ Not Applicable


14. Security Incident Reporting After Exit

I understand that if I become aware of a security incident, data breach, unauthorized disclosure, or accidental release of organizational information after my exit, I should report it through the organization’s designated contact or reporting channel where required.

Security Contact

Contact: ______________________________

Email/Phone: __________________________


15. Continuing Legal and Contractual Obligations

I acknowledge that my exit does not automatically terminate obligations that survive the end of my employment or engagement.

These may include:

☐ Confidentiality
☐ Intellectual-property obligations
☐ Data-protection obligations
☐ Customer confidentiality
☐ Supplier confidentiality
☐ Information-return obligations
☐ Information-deletion obligations
☐ Other contractual obligations

Relevant Agreement

Agreement/Reference: ______________________________


16. Confirmation of No Unauthorized Retention

I confirm, to the best of my knowledge, that I have not intentionally retained unauthorized copies of organizational confidential, restricted, personal, customer, security, or proprietary information.

☐ Confirmed

Exceptions or Disclosures

If any information remains in my possession or control, I have disclosed it below:


17. Confirmation of No Unauthorized Access

I understand that after my authorization ends, I must not:

  • Attempt to log in to organizational systems
  • Use old credentials
  • Use retained access tokens
  • Access customer environments
  • Access cloud accounts
  • Access source-code repositories
  • Access databases
  • Access VPNs
  • Access administrative systems
  • Circumvent access controls
  • Ask another person to provide unauthorized access

☐ Acknowledged


18. Security Investigation and Evidence

I understand that organizational information, devices, accounts, logs, or other records may be subject to legitimate security, legal, regulatory, or investigative requirements.

I will not intentionally delete, alter, conceal, or destroy information or evidence that I have been instructed to preserve.

☐ Acknowledged


19. Exit Checklist Confirmation

The individual confirms that the following have been addressed where applicable:

AreaStatus
Organizational access☐ Complete ☐ N/A
Privileged access☐ Complete ☐ N/A
Cloud access☐ Complete ☐ N/A
Production access☐ Complete ☐ N/A
Source-code access☐ Complete ☐ N/A
Customer access☐ Complete ☐ N/A
Supplier access☐ Complete ☐ N/A
Company assets☐ Complete ☐ N/A
Organizational information☐ Complete ☐ N/A
Credentials/secrets☐ Complete ☐ N/A
Intellectual property☐ Complete ☐ N/A
Confidentiality obligations☐ Complete ☐ N/A
Data return/deletion☐ Complete ☐ N/A
Continuing obligations☐ Complete ☐ N/A

20. Individual Declaration

I confirm that:

I have read and understood this Exit Security Acknowledgement. I understand that my access to the organization’s systems, information, facilities, and assets is being terminated or changed. I understand my continuing responsibilities regarding confidentiality, information protection, intellectual property, data protection, credentials, company assets, and unauthorized access. I confirm that I have followed the organization’s exit instructions and have disclosed any known exceptions or retained information.

Individual

Name: ______________________________________

Signature: ___________________________________

Date: _______________________________________


21. Organization Confirmation

The organization confirms that the exit security requirements applicable to the individual have been reviewed.

Manager/Business Owner

Name: ______________________________________

Signature/Approval: ___________________________

Date: _______________________________________

HR/People/Supplier Owner

Name: ______________________________________

Signature/Approval: ___________________________

Date: _______________________________________

Security/IT Reviewer

Name: ______________________________________

Signature/Approval: ___________________________

Date: _______________________________________


22. Exceptions and Follow-Up Actions

ExceptionRiskAction RequiredOwnerDue DateStatus

No exit record should be marked fully closed while significant security exceptions remain unresolved unless they have been formally accepted through the organization’s risk-acceptance process.


23. Record Retention

The completed acknowledgement should be retained according to the organization’s document-retention requirements.

The record may be associated with:

  • Employee/contractor exit record
  • Access revocation evidence
  • Asset return record
  • Supplier offboarding record
  • Security investigation record where applicable
  • HR record where appropriate

The acknowledgement should not contain passwords, API keys, private keys, recovery codes, or other authentication secrets.


24. Relationship With Other ISMS Documents

DocumentRelationship
Employee Offboarding PolicyDefines overall employee exit requirements
Employee Termination Security ChecklistProvides termination security checks
Contractor Offboarding ProcedureDefines contractor exit process
Privileged User Offboarding ChecklistHandles privileged-user exit
Access Revocation ChecklistProvides detailed access removal
Asset Return ChecklistHandles organizational asset recovery
Confidentiality AgreementDefines confidentiality obligations
Employment Security ClauseEstablishes personnel security obligations
Supplier Offboarding ChecklistHandles supplier-level exit
Incident Response ProcedureHandles security incidents
Evidence Preservation ProcedureProtects investigation evidence

25. ISO 27001 / SOC 2 Connection

An Exit Security Acknowledgement supports the organization’s personnel-security, access-control, information-protection, asset-management, confidentiality, and offboarding processes.

For ISO 27001, the exact applicable controls and evidence should be determined through the organization’s risk assessment and Statement of Applicability.

For SOC 2, the acknowledgement can provide supporting evidence that individuals were informed of their continuing security obligations and that the organization formally documented the exit process.

The acknowledgement should complement—not replace—the technical access-revocation, asset-return, and offboarding procedures.


26. Quick Audit Checklist

☐ Exit date confirmed
☐ Individual identified
☐ Employee/contractor status identified
☐ Confidentiality obligations acknowledged
☐ Personal/customer information obligations acknowledged
☐ Organizational information addressed
☐ Credentials addressed
☐ Source code addressed
☐ Intellectual property addressed
☐ Company assets addressed
☐ Personal-device requirements addressed
☐ Unauthorized access prohibition acknowledged
☐ Continuing obligations acknowledged
☐ Security incident reporting requirement communicated
☐ Investigation/evidence requirements considered
☐ Exceptions documented
☐ Individual acknowledgement obtained
☐ Organization approval completed
☐ Record retained


27. Final Audit Trail

For an individual leaving the organization, the organization should be able to demonstrate:

Who left the organization?
When did the relationship end?
What security obligations applied?
Were continuing confidentiality obligations acknowledged?
Was organizational information returned, transferred, or deleted?
Were credentials and access addressed?
Were company assets returned?
Were customer and personal-data obligations addressed?
Were intellectual-property obligations communicated?
Was unauthorized post-exit access prohibited?
Were exceptions documented?
Did the individual acknowledge the requirements?
Who from the organization reviewed and approved the exit?

Final Principle

Exit security is not complete when a person leaves the organization. It is complete when access is removed, information and assets are protected, continuing obligations are acknowledged, exceptions are addressed, and the organization can demonstrate the entire process through evidence.