ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employee Security Responsibilities

Employee Security Responsibilities

1. Purpose

The Employee Security Responsibilities document defines the information-security responsibilities expected from employees and other personnel who access organizational systems, information, facilities, or services.

The objective is to ensure that every person understands their responsibility to:

  • Protect organizational information
  • Protect customer and personal information
  • Use systems securely
  • Protect credentials
  • Follow approved security policies and procedures
  • Report security incidents
  • Complete required security training
  • Use only authorized access
  • Protect organizational assets
  • Support investigations and audits
  • Return information and assets when required

Core Principle

Understand → Protect → Use Securely → Report → Cooperate → Maintain Responsibility


2. Scope

These responsibilities apply to:

  • Employees
  • Contractors
  • Consultants
  • Interns
  • Temporary workers
  • Remote workers
  • Third-party personnel
  • Personnel with privileged access
  • Personnel with access to customer or restricted information

Additional responsibilities may apply to specific roles based on their access and risk.


3. Employee Security Responsibility Statement

Every employee and applicable personnel member is responsible for protecting information and systems that they access as part of their role.

Personnel shall:

☐ Follow applicable information-security policies
☐ Use organizational systems only for authorized purposes
☐ Protect passwords and authentication methods
☐ Use MFA where required
☐ Protect confidential information
☐ Report suspected security incidents promptly
☐ Use only authorized software and services
☐ Protect company devices
☐ Follow access-control requirements
☐ Complete required security training
☐ Follow remote-working requirements
☐ Return organizational assets when required


4. Information Protection

Employees shall protect information according to its classification and business sensitivity.

Employees shall:

☐ Understand applicable information classifications
☐ Access information only when required
☐ Share information only with authorized recipients
☐ Use approved storage locations
☐ Use approved transfer methods
☐ Avoid unnecessary copying of sensitive information
☐ Protect confidential documents
☐ Prevent unauthorized disclosure
☐ Report accidental disclosure

Employees shall not disclose organizational information to unauthorized individuals or organizations.


5. Customer Information

Where employees handle customer information:

☐ Access only information required for their role
☐ Follow customer-specific security requirements
☐ Follow contractual restrictions
☐ Protect customer credentials
☐ Use approved communication channels
☐ Avoid unnecessary downloading or copying
☐ Report suspected customer-data exposure
☐ Follow retention and deletion requirements


6. Personal Data

Employees handling personal data shall:

☐ Access only required information
☐ Use personal data only for authorized purposes
☐ Follow applicable privacy requirements
☐ Avoid unnecessary collection
☐ Avoid unnecessary copying
☐ Protect personal data during transmission
☐ Report suspected personal-data exposure
☐ Follow retention and deletion requirements


7. Password Responsibilities

Employees shall:

☐ Use strong authentication credentials
☐ Keep passwords confidential
☐ Never share passwords with colleagues
☐ Avoid reusing passwords where prohibited
☐ Use an approved password manager where provided
☐ Never store passwords insecurely
☐ Report suspected credential compromise
☐ Change/reset credentials through approved processes

Employees shall not request another person’s password.


8. Multi-Factor Authentication

Where MFA is required:

☐ MFA shall be enabled
☐ MFA prompts shall not be approved without verification
☐ Authentication devices shall be protected
☐ MFA codes shall not be shared
☐ Unexpected MFA requests shall be reported
☐ Lost authentication devices shall be reported promptly

Repeated unexpected MFA prompts may indicate attempted account compromise.


9. User Accounts

Employees shall:

☐ Use their assigned accounts
☐ Maintain individual accountability
☐ Never use another person’s account without authorization
☐ Never allow another person to use their account
☐ Lock or secure their workstation when unattended
☐ Report unauthorized account activity

Shared accounts should be avoided unless technically or operationally necessary and appropriately controlled.


10. Access Responsibilities

Employees shall:

☐ Use only authorized systems
☐ Access only information required for their role
☐ Follow least-privilege requirements
☐ Not attempt to bypass access controls
☐ Not attempt to access unauthorized information
☐ Report inappropriate access
☐ Notify management of role changes affecting access

Employees must not use access rights for purposes unrelated to their authorized responsibilities.


11. Privileged Access Responsibilities

Personnel with privileged access have additional responsibilities.

They shall:

☐ Use privileged access only when required
☐ Use named accounts where provided
☐ Use MFA
☐ Protect administrative credentials
☐ Avoid unnecessary administrative activity
☐ Follow approved change procedures
☐ Avoid disabling security controls without authorization
☐ Protect logs and security information
☐ Report suspected privileged-account compromise
☐ Participate in periodic access reviews

Privileged access shall not be used for convenience.


12. Production Access

Personnel with production access shall:

☐ Access production only when required
☐ Follow approved deployment/change procedures
☐ Use authorized accounts
☐ Avoid unnecessary production-data access
☐ Protect production credentials
☐ Follow emergency-access procedures
☐ Report unauthorized production activity
☐ Maintain appropriate evidence for significant activities


13. AWS and Cloud Security Responsibilities

Where employees access AWS or other cloud environments:

☐ Use assigned accounts
☐ Use MFA
☐ Follow least privilege
☐ Protect cloud credentials
☐ Do not share access keys
☐ Do not create unauthorized cloud resources
☐ Do not disable logging/security controls without authorization
☐ Follow approved change procedures
☐ Protect cloud data
☐ Report suspicious cloud activity

AWS root-account credentials shall not be used for routine administration.


14. Source-Code Security

Personnel with source-code access shall:

☐ Use authorized repositories
☐ Protect repository credentials
☐ Follow code-review requirements
☐ Avoid committing passwords or secrets
☐ Avoid committing customer data
☐ Follow branch and deployment controls
☐ Protect proprietary source code
☐ Report exposed credentials or secrets immediately


15. Secrets and Credentials

Employees shall protect:

  • Passwords
  • API keys
  • Access tokens
  • SSH keys
  • Certificates
  • Database credentials
  • Cloud credentials
  • Encryption keys
  • Application secrets

Employees shall:

☐ Use approved secret-management systems
☐ Never intentionally expose secrets
☐ Never store secrets in public repositories
☐ Avoid sending secrets through normal email/chat
☐ Report exposed credentials immediately
☐ Follow credential-rotation procedures


16. Email Security

Employees shall:

☐ Verify unexpected requests
☐ Be cautious with links and attachments
☐ Verify payment or sensitive-data requests
☐ Report phishing
☐ Avoid forwarding confidential information unnecessarily
☐ Protect customer information
☐ Use approved business email accounts

Employees should verify unusual requests for passwords, payments, credentials, or sensitive information through an independent trusted channel.


17. Phishing and Social Engineering

Employees shall remain alert to:

  • Phishing
  • Spear phishing
  • Business-email compromise
  • Fake support requests
  • Impersonation
  • Credential theft
  • MFA fatigue
  • Malicious attachments
  • Fraudulent payment requests

Employees shall report suspected social-engineering attempts promptly.


18. Device Security

Employees shall:

☐ Use approved devices
☐ Keep operating systems updated
☐ Apply security patches
☐ Use device encryption where required
☐ Use screen locks
☐ Protect devices from unauthorized access
☐ Avoid installing unauthorized software
☐ Report lost or stolen devices
☐ Follow endpoint-security requirements


19. Removable Media

Where removable media is permitted:

☐ Use approved devices
☐ Protect sensitive information
☐ Encrypt information where required
☐ Scan media where appropriate
☐ Avoid unknown USB devices
☐ Report lost media
☐ Dispose of media securely


20. Remote Working

Remote personnel shall:

☐ Use approved devices
☐ Use secure authentication
☐ Use MFA
☐ Protect confidential information
☐ Secure their physical workspace
☐ Avoid unauthorized public sharing
☐ Use approved remote-access methods
☐ Protect devices from family/third-party access
☐ Report security incidents promptly


21. Public and Shared Environments

Employees shall take care when working in:

  • Cafés
  • Airports
  • Hotels
  • Coworking spaces
  • Public transport
  • Customer locations
  • Shared offices

Personnel should prevent unauthorized persons from viewing or accessing confidential information.


22. Clean Desk and Clear Screen

Employees shall:

☐ Lock screens when leaving workstations
☐ Avoid leaving confidential documents unattended
☐ Store sensitive documents securely
☐ Dispose of sensitive documents appropriately
☐ Avoid displaying confidential information unnecessarily
☐ Protect whiteboards containing sensitive information


23. Software and Applications

Employees shall:

☐ Use approved software
☐ Follow software licensing requirements
☐ Avoid unauthorized applications
☐ Avoid downloading software from untrusted sources
☐ Request approval where required
☐ Report suspicious software

Employees shall not install software merely to bypass organizational security controls.


24. Cloud and SaaS Applications

Employees shall use only approved cloud/SaaS services for organizational information where required.

Employees shall:

☐ Follow approved application requirements
☐ Protect cloud credentials
☐ Avoid uploading confidential information to unauthorized services
☐ Avoid creating unauthorized company accounts
☐ Report suspected shadow IT
☐ Follow data-transfer requirements


25. AI and Generative AI

Employees shall follow organizational requirements when using AI tools.

Unless specifically authorized, employees should not submit:

  • Passwords
  • API keys
  • Private keys
  • Customer confidential information
  • Restricted information
  • Sensitive personal data
  • Proprietary source code
  • Security credentials
  • Unpublished security findings

Employees shall:

☐ Use approved AI services where required
☐ Understand applicable data-use restrictions
☐ Verify AI-generated outputs where appropriate
☐ Protect confidential information
☐ Report accidental disclosure


26. Information Transfer

Before sending sensitive information, employees shall:

☐ Confirm the recipient
☐ Confirm the recipient is authorized
☐ Use approved transfer channels
☐ Use encryption where required
☐ Minimize the information transferred
☐ Verify unusual requests
☐ Avoid unnecessary external sharing


27. Physical Security

Employees shall:

☐ Protect access cards
☐ Prevent unauthorized entry
☐ Challenge or report suspicious access where appropriate
☐ Secure company equipment
☐ Follow visitor requirements
☐ Report lost access cards
☐ Protect restricted areas

Employees shall not allow unauthorized individuals to use their access credentials or badges.


28. Security Incident Reporting

Employees shall promptly report suspected or actual security incidents.

Examples include:

☐ Phishing
☐ Malware
☐ Lost device
☐ Stolen device
☐ Unauthorized access
☐ Credential compromise
☐ Accidental data disclosure
☐ Mis-sent email
☐ Exposed API key
☐ Suspicious cloud activity
☐ Unauthorized software
☐ Security-policy violation

Reporting Contact

Security Contact: ______________________

Email: _________________________________

Phone/Channel: _________________________


29. Security Event Reporting

Not every security event is necessarily a confirmed incident.

Employees should report suspicious events such as:

  • Unexpected MFA prompts
  • Suspicious login notifications
  • Unusual system behavior
  • Suspicious emails
  • Unexpected password resets
  • Unknown software
  • Unusual cloud activity

The security team can then assess whether the event requires incident response.


30. Vulnerability Reporting

Employees shall report:

☐ Security weaknesses
☐ Exposed credentials
☐ Misconfigured systems
☐ Unpatched systems
☐ Suspicious applications
☐ Insecure processes
☐ Accidental data exposure

Employees should not attempt unauthorized security testing or exploitation.


31. Security Testing

Only authorized personnel may perform security testing.

Employees shall not conduct unauthorized:

  • Vulnerability scanning
  • Penetration testing
  • Exploitation
  • Password testing
  • Network scanning
  • Social engineering
  • Security-tool deployment

Security testing shall follow approved authorization and scope.


32. Change Management

Employees making changes to organizational systems shall:

☐ Follow approved change procedures
☐ Obtain required authorization
☐ Test changes where required
☐ Document significant changes
☐ Follow rollback requirements
☐ Protect production systems
☐ Report failed or unauthorized changes


33. Data Retention and Disposal

Employees shall:

☐ Retain information according to applicable requirements
☐ Avoid unnecessary copies
☐ Delete information when authorized and no longer required
☐ Use approved disposal methods
☐ Avoid placing sensitive information in personal storage

Employees shall not independently delete records subject to legal, contractual, investigation, or retention requirements.


34. Intellectual Property

Employees shall protect:

  • Source code
  • Designs
  • Product information
  • Business plans
  • Documentation
  • Trade secrets
  • Customer information
  • Proprietary methods

Employees shall not disclose organizational intellectual property without authorization.


35. Third-Party Information

Employees handling supplier or partner information shall:

☐ Protect confidential information
☐ Follow contractual restrictions
☐ Use information only for authorized purposes
☐ Avoid unauthorized disclosure
☐ Follow approved transfer methods


36. Customer-Specific Requirements

Where customer contracts impose additional security requirements:

☐ Employees shall be informed where applicable
☐ Applicable requirements shall be followed
☐ Customer information shall be handled according to agreed requirements
☐ Exceptions shall be escalated
☐ Customer security incidents shall be reported through approved channels


37. Security Awareness

Employees shall complete required security awareness activities.

Requirements may include:

  • New-joiner training
  • Annual security awareness
  • Phishing awareness
  • Role-specific security training
  • Privacy training
  • Secure development training
  • Cloud security training
  • AI security awareness

Training completion may be monitored.


38. Policy Compliance

Employees shall comply with applicable:

  • Information Security Policy
  • Acceptable Use Policy
  • Access Management Policy
  • Password/MFA requirements
  • Data Protection Policy
  • Remote Working Policy
  • Incident Response Procedure
  • AI Usage Policy
  • Asset Management requirements
  • Other applicable security procedures

39. Reporting Policy Violations

Employees shall report known or suspected violations through approved channels.

Examples:

☐ Unauthorized access
☐ Credential sharing
☐ Data leakage
☐ Unauthorized software
☐ Bypassing security controls
☐ Misuse of company systems
☐ Improper handling of customer data
☐ Intentional security-policy violations


40. Cooperation With Investigations

Personnel shall cooperate with authorized security investigations.

Where appropriate, employees may be required to:

  • Provide relevant information
  • Preserve evidence
  • Follow investigation instructions
  • Participate in interviews
  • Avoid altering relevant records
  • Protect investigation confidentiality

Employees shall not independently delete or modify potentially relevant evidence.


41. Audit and Compliance Cooperation

Employees may be required to support:

  • Internal audits
  • Security assessments
  • Customer audits
  • Certification audits
  • Compliance reviews
  • Security investigations

Employees shall provide accurate information and appropriate evidence within their authority.


42. Business Continuity Responsibilities

Employees assigned business-continuity responsibilities shall:

☐ Understand their recovery role
☐ Maintain required contact information
☐ Participate in exercises where required
☐ Follow emergency procedures
☐ Protect critical information during disruptions
☐ Support recovery activities


43. Emergency Access

Where emergency access is required:

☐ Use approved emergency procedures
☐ Obtain authorization where practical
☐ Use only the minimum required access
☐ Record emergency activity
☐ Report activity afterward where required
☐ Return to normal access arrangements after the emergency


44. Contractor and Third-Party Responsibilities

Contractors and third-party personnel shall comply with applicable security requirements established through:

  • Contracts
  • Security agreements
  • Supplier requirements
  • Access conditions
  • Organizational policies

Their access shall be limited to authorized business requirements.


45. Role-Specific Responsibilities

Additional responsibilities may apply to:

Developers

☐ Secure coding
☐ Code review
☐ Secret protection
☐ Dependency security
☐ Approved deployment processes

DevOps/Cloud Administrators

☐ Privileged-access protection
☐ Cloud configuration
☐ Logging
☐ Infrastructure security
☐ Production access controls

Security Personnel

☐ Security monitoring
☐ Incident response
☐ Security-tool protection
☐ Vulnerability management
☐ Evidence protection

Finance Personnel

☐ Financial information protection
☐ Payment authorization controls
☐ Segregation of duties
☐ Fraud/security reporting

HR Personnel

☐ Personnel-data protection
☐ Restricted HR-system access
☐ Background-verification confidentiality
☐ Secure personnel-record handling


46. Prohibited Activities

Unless explicitly authorized, employees shall not:

  • Share credentials
  • Circumvent security controls
  • Access unauthorized information
  • Install unauthorized security tools
  • Perform unauthorized penetration testing
  • Upload restricted information to unauthorized services
  • Publish confidential information
  • Disable security controls
  • Copy sensitive information unnecessarily
  • Use company systems for unauthorized activities

47. Employee Security Acknowledgement

Where required, employees shall acknowledge that they:

☐ Have received applicable security requirements
☐ Understand their responsibilities
☐ Know how to report security incidents
☐ Understand credential requirements
☐ Understand information-protection requirements
☐ Understand acceptable-use requirements
☐ Understand applicable confidentiality obligations
☐ Understand that access is provided only for authorized purposes

Employee

Name: _________________________________

Employee ID: __________________________

Role: __________________________________

Date: __________________________________

Signature/Acknowledgement: _____________


48. Security Responsibility During Role Changes

When an employee changes role:

☐ Responsibilities are updated
☐ Security responsibilities are reassessed
☐ Access is reviewed
☐ Additional training is provided where required
☐ Sensitive-role classification is reassessed
☐ Privileged access is reviewed
☐ Confidentiality requirements are updated where necessary


49. Responsibilities During Offboarding

Before leaving the organization, personnel shall:

☐ Return company equipment
☐ Return access cards/tokens
☐ Return organizational information where required
☐ Stop using organizational accounts
☐ Transfer required business information
☐ Protect continuing confidentiality obligations
☐ Follow information-return/deletion requirements

Access revocation shall be managed through the organization’s offboarding process.


50. Management Responsibilities

Managers shall:

☐ Ensure personnel understand relevant responsibilities
☐ Approve access based on business need
☐ Notify HR/IT of role changes
☐ Notify relevant teams of termination
☐ Support security training
☐ Address security violations
☐ Ensure sensitive responsibilities are appropriately assigned


51. Security Responsibility Monitoring

The organization may monitor:

  • Security training completion
  • Policy acknowledgement
  • Access compliance
  • Security incidents
  • Policy violations
  • Phishing results
  • Privileged access
  • Sensitive-role compliance
  • Offboarding completion

Monitoring should be proportionate and comply with applicable requirements.


52. Exceptions

Where an employee cannot comply with a security requirement:

☐ Business justification documented
☐ Security risk assessed
☐ Alternative control considered
☐ Appropriate approval obtained
☐ Exception expiry/review date defined
☐ Exception monitored

Employees shall not create informal exceptions to security requirements.


53. Consequences of Non-Compliance

Failure to follow security responsibilities may result in:

  • Additional training
  • Access restriction
  • Corrective action
  • Investigation
  • Disciplinary action
  • Contractual action for third parties
  • Other actions consistent with applicable law and organizational processes

The response shall be proportionate to the circumstances and handled through established processes.


54. AWS SaaS Startup Example

For an AWS SaaS startup, an employee with normal SaaS application access may primarily be responsible for:

MFA → Password protection → Data protection → Phishing awareness → Incident reporting

A DevOps engineer may additionally be responsible for:

Privileged access → Cloud security → Production changes → Secrets protection → Logging → Incident escalation

An AWS administrator may have additional requirements for:

Named account → MFA → Least privilege → Secure administration → Production access → Logging → Periodic access review

The security responsibilities should therefore reflect the actual risk and access of the role.


55. Startup-Friendly Employee Security Model

Every employee should remember five basic responsibilities:

1. Protect

Protect information, devices, credentials, and company assets.

2. Access

Use only the systems and information required for your role.

3. Verify

Verify unusual requests, links, attachments, payments, and credential requests.

4. Report

Report suspected security incidents quickly.

5. Follow

Follow organizational security policies and approved procedures.

Protect → Access → Verify → Report → Follow


56. Common Mistakes

Employees should avoid:

  • Sharing passwords
  • Approving unexpected MFA prompts
  • Sending confidential data to personal email
  • Uploading sensitive information to unauthorized AI tools
  • Committing secrets to source-code repositories
  • Using unauthorized SaaS applications
  • Leaving devices unlocked
  • Ignoring phishing
  • Delaying incident reporting
  • Accessing information without business need
  • Using privileged access for convenience
  • Performing unauthorized security testing
  • Ignoring security requirements after changing roles
  • Taking company information after leaving

57. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security governance
Employee Screening PolicyDefines screening requirements
Background Verification ProcedureDefines verification
Sensitive Role Identification ChecklistIdentifies sensitive roles
Role-Based Screening MatrixDetermines screening level
Security Awareness ProcedureDefines training
Acceptable Use PolicyDefines acceptable system use
Access Management ProcedureControls access
Privileged Access ProcedureControls privileged access
Remote Working PolicyDefines remote-working security
Incident Response ProcedureDefines incident handling
Employee Offboarding ProcedureControls exit
Security Policy Acknowledgement RegisterRecords acknowledgements
HR Security Audit ChecklistAudits HR security controls

58. ISO/IEC 27001 Connection

Employee security responsibilities support the organization’s personnel-security and access-control arrangements.

Relevant areas may include:

  • Personnel screening
  • Employment terms and responsibilities
  • Security awareness and training
  • Confidentiality
  • Access control
  • Privileged access
  • Information protection
  • Remote working
  • Incident reporting
  • Personnel changes
  • Termination or change of employment

The Employee Security Responsibilities document is not itself a universally prescribed ISO/IEC 27001 document title. The organization should determine the appropriate employee responsibilities based on its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer requirements, and business needs.


59. Audit Evidence Checklist

The organization should be able to demonstrate:

☐ Employee security responsibilities
☐ Human Resources Security Policy
☐ Employment/security terms
☐ NDA/confidentiality requirements
☐ Security awareness records
☐ Policy acknowledgements where applicable
☐ Access approvals
☐ Privileged-access approvals
☐ Sensitive-role assessments
☐ Background verification records
☐ Incident reporting records
☐ Role-change records
☐ Offboarding records
☐ Asset-return records
☐ Security exceptions
☐ Corrective actions


60. Final Employee Security Audit Trail

The organization should be able to demonstrate:

Did the employee understand their security responsibilities?
Were those responsibilities appropriate to their role?
Was the employee appropriately screened where required?
Were confidentiality obligations established?
Was security training completed?
Was access authorized and limited?
Was privileged access appropriately controlled?
Did the employee know how to report incidents?
Were role changes reviewed?
Were security violations addressed?
Was access removed when employment ended?
Were organizational assets and information protected?

Final Principle

Information security is not only the responsibility of the security or IT team. Every employee and applicable third party has security responsibilities based on the information they handle, systems they access, and authority they possess. Clear responsibilities, appropriate training, controlled access, timely reporting, and effective offboarding turn personnel security requirements into everyday security practices.