ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Confidentiality and Non-Disclosure Policy

Confidentiality and Non-Disclosure Policy

1. Purpose

The Confidentiality and Non-Disclosure Policy establishes requirements for protecting confidential, sensitive, proprietary, personal, customer, security, and other non-public information from unauthorized access, disclosure, use, copying, transfer, or retention.

The policy defines how confidentiality obligations apply to employees, contractors, consultants, temporary workers, suppliers, partners, and other parties who may have access to organizational information.

Core Principle

Identify → Classify → Authorize → Protect → Share Carefully → Monitor → Return/Delete → Maintain Confidentiality


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Interns
  • Temporary workers
  • Supplier personnel
  • Business partners
  • Service providers
  • Advisors
  • Auditors
  • Other third parties

It applies to information in:

  • Paper documents
  • Email
  • Chat and collaboration platforms
  • Source-code repositories
  • Databases
  • Cloud platforms
  • SaaS applications
  • File-storage systems
  • Customer environments
  • Mobile devices
  • Laptops and workstations
  • Removable media
  • Backups
  • Logs
  • Printed material
  • Verbal communications
  • Other information-storage or communication methods

3. Policy Objectives

The organization shall:

  • Identify information requiring confidentiality protection.
  • Define confidentiality responsibilities.
  • Restrict information access to authorized individuals.
  • Use appropriate contractual protections.
  • Protect information during storage and transmission.
  • Control information sharing with external parties.
  • Prevent unauthorized copying and disclosure.
  • Address confidentiality during onboarding, role changes, and offboarding.
  • Protect customer and personal information.
  • Manage confidentiality exceptions.
  • Monitor and investigate suspected unauthorized disclosure.
  • Maintain evidence of relevant confidentiality obligations.

4. Information Covered

Confidentiality requirements may apply to:

Business Information

  • Business plans
  • Financial information
  • Pricing
  • Strategy
  • Contracts
  • Commercial information
  • Supplier information
  • Customer information
  • Sales information
  • Product roadmaps

Technical Information

  • Source code
  • Architecture
  • Infrastructure configuration
  • Cloud configuration
  • Database information
  • API specifications
  • CI/CD configuration
  • Technical documentation
  • System credentials
  • Security configurations

Security Information

  • Vulnerability information
  • Penetration-test results
  • Security assessments
  • Incident information
  • Security logs
  • Threat information
  • Security architecture
  • Encryption information
  • Security procedures

Personal and Customer Information

  • Personal data
  • Customer records
  • Employee information
  • Financial information
  • Authentication information
  • Support records
  • Customer communications

5. Information Classification

Information shall be classified according to the organization’s approved information-classification scheme.

Example classifications:

ClassificationDescriptionTypical Protection
PublicApproved for public disclosureNormal business controls
InternalIntended for internal useAuthorized workforce access
ConfidentialUnauthorized disclosure could cause harmRestricted access and controlled sharing
RestrictedHighly sensitive or regulated informationStrict access, enhanced controls, monitoring

The organization may use different classification names where defined by its information-classification policy.


6. Confidentiality Responsibilities

Individuals with access to confidential information shall:

  • Use information only for authorized business purposes.
  • Access only information required for their role.
  • Protect information from unauthorized disclosure.
  • Avoid unnecessary copying.
  • Use approved communication and storage systems.
  • Follow information-classification requirements.
  • Follow secure-transfer requirements.
  • Report suspected disclosure or loss.
  • Return or delete information when instructed.
  • Continue to protect information after their engagement ends where applicable.

7. Need-to-Know Principle

Access to confidential information shall be based on business need.

Individuals shall not access information simply because they technically can.

Access should be:

  • Authorized
  • Role-appropriate
  • Limited to business requirements
  • Reviewed periodically
  • Removed when no longer required

Principle

Need to know, not merely ability to access.


8. Confidentiality Agreements

Where appropriate, the organization shall establish confidentiality obligations through:

  • Employment agreements
  • Confidentiality clauses
  • Non-Disclosure Agreements (NDAs)
  • Contractor agreements
  • Supplier agreements
  • Data Processing Agreements
  • Customer agreements
  • Partner agreements
  • Security agreements

The appropriate agreement should be determined based on the relationship, information involved, legal requirements, and risk.


9. Employee Confidentiality

Employees shall be informed of their confidentiality responsibilities as part of onboarding.

Where applicable, employees shall acknowledge:

☐ Confidentiality obligations
☐ Information-classification requirements
☐ Acceptable-use requirements
☐ Data-protection responsibilities
☐ Security responsibilities
☐ Reporting obligations

Confidentiality obligations may continue after employment ends where required by applicable agreements, law, or organizational requirements.


10. Contractor Confidentiality

Contractors and consultants shall be subject to appropriate confidentiality requirements before receiving access to confidential information.

Where applicable:

☐ NDA executed
☐ Contractual confidentiality clause included
☐ Information-access scope defined
☐ Customer confidentiality requirements addressed
☐ Data-protection requirements addressed
☐ Access limited to business need
☐ Exit requirements defined

Contractors shall not retain confidential organizational information after their engagement ends unless specifically authorized.


11. Supplier and Third-Party Confidentiality

Before sharing confidential information with suppliers or other third parties, the organization shall determine whether appropriate contractual protections are required.

Consider:

  • NDA
  • Confidentiality clause
  • Supplier security agreement
  • Data Processing Agreement
  • Customer contractual requirements
  • Data-location requirements
  • Subprocessor requirements

Confidential information shall only be shared with authorized third parties for approved purposes.


12. Customer Information

Customer information shall be treated according to:

  • Contractual requirements
  • Information classification
  • Privacy requirements
  • Security requirements
  • Applicable laws and regulations

Employees, contractors, and suppliers shall not disclose customer information outside authorized business purposes.

Customer information shall not be used for personal purposes, unauthorized testing, marketing, training, demonstrations, or other activities without appropriate authorization.


13. Personal Data

Personal data shall be handled according to applicable privacy requirements and the organization’s privacy and information-security procedures.

Individuals shall:

  • Access only required personal data.
  • Avoid unnecessary copying.
  • Use approved storage systems.
  • Use approved transfer mechanisms.
  • Prevent unauthorized disclosure.
  • Report suspected personal-data incidents.

Additional contractual or regulatory requirements may apply depending on the nature and location of the data.


14. Source Code Confidentiality

Source code shall be treated according to its classification and business sensitivity.

Employees and contractors shall:

☐ Use approved repositories
☐ Use authorized accounts
☐ Avoid unauthorized copies
☐ Avoid uploading source code to personal repositories
☐ Avoid sharing source code through unauthorized channels
☐ Protect repository credentials
☐ Follow open-source requirements
☐ Follow customer contractual restrictions

Source code shall not be disclosed to external parties without authorization.


15. Security and Vulnerability Information

Security-sensitive information shall receive appropriate protection.

Examples include:

  • Vulnerability reports
  • Penetration-test results
  • Security weaknesses
  • Incident reports
  • Security architecture
  • Security configurations
  • Credentials
  • Encryption details
  • Threat intelligence
  • Security monitoring information

Such information shall not be shared publicly or with unauthorized parties.


16. Credentials and Secrets

Credentials and secrets shall receive enhanced protection.

Examples include:

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Cloud credentials
  • Encryption keys
  • Certificates
  • Recovery codes
  • Service-account credentials

Individuals shall:

  • Never disclose credentials unnecessarily.
  • Never share personal credentials.
  • Use approved secret-management systems.
  • Avoid storing secrets in source code.
  • Avoid sending secrets through unsecured channels.
  • Report suspected credential disclosure immediately.

Actual credentials shall never be included in confidentiality records or audit evidence.


17. Verbal Confidentiality

Confidential information may also be disclosed verbally.

Individuals shall take appropriate precautions during:

  • Meetings
  • Phone calls
  • Video conferences
  • Customer discussions
  • Public events
  • Conferences
  • Travel
  • Shared workspaces

Confidential discussions should not be conducted where unauthorized individuals can reasonably overhear them.


18. Email and Messaging

Confidential information sent through email or messaging systems shall use approved organizational channels.

Before sending confidential information, the sender should verify:

  • Recipient identity
  • Recipient authorization
  • Correct email address
  • Required attachments
  • Information classification
  • Need-to-know
  • Appropriate encryption or secure-transfer mechanism where required

Avoid sending confidential information to personal email accounts unless explicitly authorized.


19. File Sharing

Confidential information shall be shared using approved systems.

Examples:

  • Approved cloud storage
  • Secure file-transfer systems
  • Approved collaboration platforms
  • Customer-approved portals
  • Controlled document repositories

Public or unrestricted file-sharing links shall not be used for confidential or restricted information unless specifically approved and appropriately controlled.


20. External Disclosure

Confidential information shall not be disclosed externally without appropriate authorization.

Examples of external disclosure include:

  • Customers
  • Suppliers
  • Partners
  • Investors
  • Consultants
  • Media
  • Public websites
  • Social media
  • Conferences
  • Public repositories
  • Online forums
  • AI tools or external services

The individual shall confirm that the recipient is authorized to receive the information before disclosure.


21. Public Disclosure

Confidential or restricted information shall not be published through:

  • Websites
  • Social media
  • Blogs
  • Public repositories
  • Public forums
  • Presentations
  • Marketing materials
  • Press releases
  • Public documents

unless it has gone through the organization’s approved disclosure process.


22. Use of AI and External Services

Employees and contractors shall not submit confidential, restricted, customer, personal, source-code, security, or proprietary information to external AI tools or other third-party services unless the service and use case have been approved.

Before using an external AI service, consider:

☐ Information classification
☐ Customer restrictions
☐ Privacy requirements
☐ Contractual restrictions
☐ Data retention
☐ Provider use of submitted information
☐ Security controls
☐ Organizational approval

Principle

Do not assume that an AI or online service is approved merely because it is publicly available.


23. Remote Working

Confidential information accessed remotely shall be protected against unauthorized disclosure.

Individuals shall:

  • Use approved devices where required.
  • Protect screens from unauthorized viewing.
  • Use secure networks.
  • Avoid discussing confidential matters in public places.
  • Use approved collaboration tools.
  • Secure physical documents.
  • Protect devices from unauthorized access.

24. Physical Documents

Confidential documents shall be appropriately protected.

Individuals shall:

☐ Avoid leaving confidential documents unattended
☐ Store documents securely
☐ Limit printing
☐ Collect printed documents promptly
☐ Dispose of documents securely
☐ Prevent unauthorized viewing
☐ Follow clean-desk requirements where applicable


25. Removable Media

Confidential information should not be copied to removable media unless authorized and necessary.

Where removable media is approved:

  • Use organization-approved devices.
  • Apply encryption where required.
  • Restrict access.
  • Track sensitive transfers where appropriate.
  • Securely erase or dispose of media when no longer required.

26. Information Transfer

Before transferring confidential information externally, verify:

☐ Business purpose
☐ Recipient authorization
☐ Information classification
☐ Data minimization
☐ Approved transfer method
☐ Encryption where required
☐ Contractual requirements
☐ Privacy requirements
☐ Transfer records where appropriate

Refer to the organization’s Information Transfer Procedure where applicable.


27. Third-Party Disclosure

When confidential information is shared with a third party:

  1. Confirm business need.
  2. Confirm authorization.
  3. Confirm confidentiality obligations.
  4. Identify the information being shared.
  5. Confirm classification.
  6. Use approved transfer mechanisms.
  7. Limit the information to what is necessary.
  8. Record the disclosure where required.

28. Subprocessors and Subcontractors

Where a supplier uses subprocessors or subcontractors that may access confidential information:

☐ Subprocessor identified
☐ Business purpose identified
☐ Information accessed identified
☐ Confidentiality obligations assessed
☐ Contractual requirements addressed
☐ Security requirements addressed
☐ Approval obtained where required


29. Information Retention

Confidential information shall not be retained longer than necessary unless retention is required by:

  • Law
  • Regulation
  • Contract
  • Legal hold
  • Business requirement
  • Security requirement
  • Approved records-retention schedule

When information is no longer required, it should be securely deleted, destroyed, or returned according to applicable requirements.


30. Information Return

When requested or when a relationship ends, individuals and third parties shall return organizational information where required.

Examples include:

  • Documents
  • Source code
  • Customer records
  • Reports
  • Security information
  • Business records
  • Portable media
  • Physical documents

Return requirements should be documented where appropriate.


31. Secure Deletion

Where deletion is required:

☐ Data identified
☐ Deletion authorized
☐ Appropriate deletion method selected
☐ Backups considered
☐ Copies considered
☐ Third-party copies considered
☐ Deletion evidence obtained where appropriate

Information shall not be destroyed where it is subject to a legitimate legal, regulatory, contractual, or investigation-related preservation requirement.


32. Employee and Contractor Exit

Confidentiality obligations shall be addressed during offboarding.

The organization should:

☐ Revoke access
☐ Recover assets
☐ Address organizational information
☐ Address customer information
☐ Address source code
☐ Address credentials
☐ Confirm confidentiality obligations
☐ Address return/deletion requirements
☐ Obtain exit acknowledgement where appropriate

Individuals shall not retain confidential organizational information after their authorization ends unless specifically permitted.


33. Privileged Users

Additional confidentiality controls may apply to privileged users who have access to:

  • Production systems
  • Security systems
  • Cloud administration
  • Databases
  • Source code
  • Encryption keys
  • Security monitoring
  • Customer environments

Privileged-user offboarding shall follow the organization’s Privileged User Offboarding Checklist.


34. Security Incident and Confidentiality Breach

A suspected unauthorized disclosure shall be treated as a security event and assessed according to the organization’s incident-management process.

Examples include:

  • Email sent to the wrong recipient
  • Lost confidential document
  • Accidental public disclosure
  • Source code uploaded to a public repository
  • Customer data sent to an unauthorized party
  • Confidential information shared with an unapproved AI service
  • Lost laptop containing confidential information
  • Unauthorized copying
  • Deliberate disclosure

Individuals shall report suspected confidentiality breaches immediately through the designated security reporting process.


35. Confidentiality Breach Response

Where a confidentiality incident occurs, the organization may:

  1. Identify the information involved.
  2. Determine the affected individuals or systems.
  3. Assess the classification and sensitivity.
  4. Contain the disclosure.
  5. Revoke access where required.
  6. Recover or delete information where possible.
  7. Assess privacy and contractual impact.
  8. Preserve evidence.
  9. Notify affected parties where required.
  10. Perform root-cause analysis.
  11. Implement corrective actions.
  12. Record lessons learned.

36. Monitoring

The organization may monitor appropriate systems and activities to protect confidential information, subject to applicable law and organizational requirements.

Monitoring may include:

  • Access logs
  • File-sharing activity
  • Data-transfer activity
  • Repository activity
  • Administrative activity
  • Security alerts
  • DLP controls where implemented
  • Cloud activity
  • Email-security controls
  • Endpoint-security controls

Monitoring shall be performed according to applicable policies and legal requirements.


37. Confidentiality Exceptions

Exceptions to this policy require appropriate authorization.

Examples may include:

  • Legal disclosure
  • Regulatory disclosure
  • Law-enforcement request
  • Customer-approved disclosure
  • Contractually required disclosure
  • Approved public disclosure
  • Security testing
  • Approved research

Exception Record

ExceptionInformationReasonApproverExpiryStatus

38. Roles and Responsibilities

Management

Management shall:

  • Support confidentiality requirements.
  • Define appropriate information-classification requirements.
  • Ensure contractual protections are used where appropriate.
  • Support enforcement of confidentiality requirements.

Information Security

Information Security shall:

  • Define security requirements.
  • Support confidentiality risk assessment.
  • Monitor relevant security controls.
  • Investigate suspected confidentiality breaches.
  • Maintain related security procedures.

HR/People Team

HR/People shall:

  • Include confidentiality requirements in applicable employment processes.
  • Coordinate confidentiality acknowledgements.
  • Support employee offboarding.
  • Maintain applicable personnel records.

Procurement/Supplier Management

Procurement/Supplier Management shall:

  • Identify supplier confidentiality requirements.
  • Ensure appropriate contractual protections.
  • Coordinate supplier confidentiality obligations.

Managers

Managers shall:

  • Approve appropriate access.
  • Ensure employees understand confidentiality requirements.
  • Limit information access to business need.
  • Support offboarding and information return.

Employees and Contractors

Individuals shall:

  • Protect confidential information.
  • Follow classification requirements.
  • Use approved systems.
  • Report suspected disclosure.
  • Follow return and deletion instructions.
  • Maintain confidentiality after exit where applicable.

39. Training and Awareness

Personnel with access to confidential information shall receive appropriate security awareness and confidentiality training.

Training may cover:

  • Information classification
  • Secure information handling
  • Phishing
  • Email security
  • Data protection
  • Secure file sharing
  • AI and external service usage
  • Clean desk
  • Remote working
  • Incident reporting
  • Confidentiality obligations

Training shall be appropriate to the individual’s role and risk.


40. Enforcement

Failure to comply with this policy may result in:

  • Access restriction
  • Corrective action
  • Additional training
  • Investigation
  • Disciplinary action
  • Contractual action
  • Supplier corrective action
  • Termination of access
  • Termination of employment or contract where appropriate
  • Legal action where applicable

Actions shall be consistent with applicable law, contracts, and organizational procedures.


41. Policy Exceptions

Any exception to this policy shall:

  1. Have a documented business justification.
  2. Identify the information and risk involved.
  3. Identify compensating controls where appropriate.
  4. Have an accountable owner.
  5. Have an approved expiration date.
  6. Be reviewed periodically.

Exceptions should be recorded in the organization’s Information Security Exception Register.


42. Records and Evidence

The organization may retain evidence such as:

☐ Signed NDAs
☐ Employment confidentiality clauses
☐ Contractor agreements
☐ Supplier agreements
☐ Security acknowledgements
☐ Training records
☐ Information-transfer records
☐ Confidentiality exceptions
☐ Incident records
☐ Information-return records
☐ Secure-deletion evidence
☐ Offboarding records
☐ Access-revocation evidence

Records shall be protected according to their classification.


43. Policy Review

This policy shall be reviewed periodically and when significant changes occur, including:

  • Major organizational changes
  • New regulatory requirements
  • New customer requirements
  • Significant security incidents
  • Major technology changes
  • Changes to information-classification requirements
  • Changes to contractual obligations
  • Changes to business operations

Review Frequency

At least: Annually, unless a shorter period is required by the organization’s risk or compliance requirements.


44. Policy Approval

Policy Owner: ______________________________

Information Security Owner: __________________

Approved By: _______________________________

Version: ___________________________________

Effective Date: _____________________________

Review Date: _______________________________

Approval Date: ______________________________


45. Quick Audit Checklist

☐ Confidentiality policy approved
☐ Information classification defined
☐ Need-to-know principle implemented
☐ Employee confidentiality obligations defined
☐ Contractor confidentiality obligations defined
☐ Supplier confidentiality requirements defined
☐ NDA process defined
☐ Customer information protected
☐ Personal data requirements addressed
☐ Source-code confidentiality addressed
☐ Security information protected
☐ Credentials/secrets protected
☐ External disclosure controlled
☐ AI/external service use addressed
☐ Information transfer controlled
☐ Information retention defined
☐ Return/deletion requirements defined
☐ Offboarding confidentiality addressed
☐ Confidentiality incident reporting defined
☐ Exceptions controlled
☐ Training provided
☐ Records retained
☐ Policy reviewed periodically


46. Relationship With Other ISMS Documents

DocumentRelationship
Information Classification PolicyDefines information classification
Information Handling ProcedureDefines secure information handling
Information Transfer ProcedureControls information transfers
Acceptable Use PolicyDefines acceptable use of organizational resources
Data Protection/Privacy PolicyAddresses personal-data protection
Employee Security ResponsibilitiesDefines personnel responsibilities
Employee Offboarding PolicyAddresses employee exit
Contractor Offboarding ProcedureAddresses contractor exit
Exit Security AcknowledgementRecords continuing security obligations
Supplier Security RequirementsDefines third-party security requirements
Supplier Security AgreementEstablishes contractual security obligations
Access Management ProcedureControls access to information
Incident Response ProcedureHandles confidentiality incidents
Information Security Exception RegisterRecords approved exceptions
Security Awareness PolicySupports confidentiality awareness

47. ISO 27001 / SOC 2 Connection

This policy supports the organization’s protection of information through confidentiality requirements, access control, information handling, personnel security, supplier relationships, information transfer, incident management, and contractual controls.

For ISO 27001, the specific controls and evidence applicable to the organization should be determined through the organization’s risk assessment and Statement of Applicability.

For SOC 2, the policy can provide supporting evidence that confidentiality responsibilities are formally defined and communicated to personnel and relevant third parties.

The policy should operate together with the organization’s information-classification, access-control, supplier-management, privacy, incident-management, and offboarding processes.


48. Final Audit Trail

For confidential information, the organization should be able to demonstrate:

What information requires confidentiality protection?
How is the information classified?
Who is authorized to access it?
Why does the person need access?
What contractual confidentiality obligations apply?
How is information protected during storage and transfer?
How are external disclosures controlled?
How are customer and personal information protected?
How are source code, security information, and credentials protected?
What happens when an employee or contractor leaves?
How are confidentiality breaches reported and investigated?
How are exceptions approved?
What evidence demonstrates that confidentiality requirements are operating?

Final Principle

Confidentiality is not only an NDA. It is a lifecycle control covering classification, access, handling, sharing, storage, transfer, monitoring, incident response, and exit.