1. Purpose
The Employee Security Responsibilities document defines the information-security responsibilities expected from employees and other personnel who access organizational systems, information, facilities, or services.
The objective is to ensure that every person understands their responsibility to:
- Protect organizational information
- Protect customer and personal information
- Use systems securely
- Protect credentials
- Follow approved security policies and procedures
- Report security incidents
- Complete required security training
- Use only authorized access
- Protect organizational assets
- Support investigations and audits
- Return information and assets when required
Core Principle
Understand → Protect → Use Securely → Report → Cooperate → Maintain Responsibility
2. Scope
These responsibilities apply to:
- Employees
- Contractors
- Consultants
- Interns
- Temporary workers
- Remote workers
- Third-party personnel
- Personnel with privileged access
- Personnel with access to customer or restricted information
Additional responsibilities may apply to specific roles based on their access and risk.
3. Employee Security Responsibility Statement
Every employee and applicable personnel member is responsible for protecting information and systems that they access as part of their role.
Personnel shall:
☐ Follow applicable information-security policies
☐ Use organizational systems only for authorized purposes
☐ Protect passwords and authentication methods
☐ Use MFA where required
☐ Protect confidential information
☐ Report suspected security incidents promptly
☐ Use only authorized software and services
☐ Protect company devices
☐ Follow access-control requirements
☐ Complete required security training
☐ Follow remote-working requirements
☐ Return organizational assets when required
4. Information Protection
Employees shall protect information according to its classification and business sensitivity.
Employees shall:
☐ Understand applicable information classifications
☐ Access information only when required
☐ Share information only with authorized recipients
☐ Use approved storage locations
☐ Use approved transfer methods
☐ Avoid unnecessary copying of sensitive information
☐ Protect confidential documents
☐ Prevent unauthorized disclosure
☐ Report accidental disclosure
Employees shall not disclose organizational information to unauthorized individuals or organizations.
5. Customer Information
Where employees handle customer information:
☐ Access only information required for their role
☐ Follow customer-specific security requirements
☐ Follow contractual restrictions
☐ Protect customer credentials
☐ Use approved communication channels
☐ Avoid unnecessary downloading or copying
☐ Report suspected customer-data exposure
☐ Follow retention and deletion requirements
6. Personal Data
Employees handling personal data shall:
☐ Access only required information
☐ Use personal data only for authorized purposes
☐ Follow applicable privacy requirements
☐ Avoid unnecessary collection
☐ Avoid unnecessary copying
☐ Protect personal data during transmission
☐ Report suspected personal-data exposure
☐ Follow retention and deletion requirements
7. Password Responsibilities
Employees shall:
☐ Use strong authentication credentials
☐ Keep passwords confidential
☐ Never share passwords with colleagues
☐ Avoid reusing passwords where prohibited
☐ Use an approved password manager where provided
☐ Never store passwords insecurely
☐ Report suspected credential compromise
☐ Change/reset credentials through approved processes
Employees shall not request another person’s password.
8. Multi-Factor Authentication
Where MFA is required:
☐ MFA shall be enabled
☐ MFA prompts shall not be approved without verification
☐ Authentication devices shall be protected
☐ MFA codes shall not be shared
☐ Unexpected MFA requests shall be reported
☐ Lost authentication devices shall be reported promptly
Repeated unexpected MFA prompts may indicate attempted account compromise.
9. User Accounts
Employees shall:
☐ Use their assigned accounts
☐ Maintain individual accountability
☐ Never use another person’s account without authorization
☐ Never allow another person to use their account
☐ Lock or secure their workstation when unattended
☐ Report unauthorized account activity
Shared accounts should be avoided unless technically or operationally necessary and appropriately controlled.
10. Access Responsibilities
Employees shall:
☐ Use only authorized systems
☐ Access only information required for their role
☐ Follow least-privilege requirements
☐ Not attempt to bypass access controls
☐ Not attempt to access unauthorized information
☐ Report inappropriate access
☐ Notify management of role changes affecting access
Employees must not use access rights for purposes unrelated to their authorized responsibilities.
11. Privileged Access Responsibilities
Personnel with privileged access have additional responsibilities.
They shall:
☐ Use privileged access only when required
☐ Use named accounts where provided
☐ Use MFA
☐ Protect administrative credentials
☐ Avoid unnecessary administrative activity
☐ Follow approved change procedures
☐ Avoid disabling security controls without authorization
☐ Protect logs and security information
☐ Report suspected privileged-account compromise
☐ Participate in periodic access reviews
Privileged access shall not be used for convenience.
12. Production Access
Personnel with production access shall:
☐ Access production only when required
☐ Follow approved deployment/change procedures
☐ Use authorized accounts
☐ Avoid unnecessary production-data access
☐ Protect production credentials
☐ Follow emergency-access procedures
☐ Report unauthorized production activity
☐ Maintain appropriate evidence for significant activities
13. AWS and Cloud Security Responsibilities
Where employees access AWS or other cloud environments:
☐ Use assigned accounts
☐ Use MFA
☐ Follow least privilege
☐ Protect cloud credentials
☐ Do not share access keys
☐ Do not create unauthorized cloud resources
☐ Do not disable logging/security controls without authorization
☐ Follow approved change procedures
☐ Protect cloud data
☐ Report suspicious cloud activity
AWS root-account credentials shall not be used for routine administration.
14. Source-Code Security
Personnel with source-code access shall:
☐ Use authorized repositories
☐ Protect repository credentials
☐ Follow code-review requirements
☐ Avoid committing passwords or secrets
☐ Avoid committing customer data
☐ Follow branch and deployment controls
☐ Protect proprietary source code
☐ Report exposed credentials or secrets immediately
15. Secrets and Credentials
Employees shall protect:
- Passwords
- API keys
- Access tokens
- SSH keys
- Certificates
- Database credentials
- Cloud credentials
- Encryption keys
- Application secrets
Employees shall:
☐ Use approved secret-management systems
☐ Never intentionally expose secrets
☐ Never store secrets in public repositories
☐ Avoid sending secrets through normal email/chat
☐ Report exposed credentials immediately
☐ Follow credential-rotation procedures
16. Email Security
Employees shall:
☐ Verify unexpected requests
☐ Be cautious with links and attachments
☐ Verify payment or sensitive-data requests
☐ Report phishing
☐ Avoid forwarding confidential information unnecessarily
☐ Protect customer information
☐ Use approved business email accounts
Employees should verify unusual requests for passwords, payments, credentials, or sensitive information through an independent trusted channel.
17. Phishing and Social Engineering
Employees shall remain alert to:
- Phishing
- Spear phishing
- Business-email compromise
- Fake support requests
- Impersonation
- Credential theft
- MFA fatigue
- Malicious attachments
- Fraudulent payment requests
Employees shall report suspected social-engineering attempts promptly.
18. Device Security
Employees shall:
☐ Use approved devices
☐ Keep operating systems updated
☐ Apply security patches
☐ Use device encryption where required
☐ Use screen locks
☐ Protect devices from unauthorized access
☐ Avoid installing unauthorized software
☐ Report lost or stolen devices
☐ Follow endpoint-security requirements
19. Removable Media
Where removable media is permitted:
☐ Use approved devices
☐ Protect sensitive information
☐ Encrypt information where required
☐ Scan media where appropriate
☐ Avoid unknown USB devices
☐ Report lost media
☐ Dispose of media securely
20. Remote Working
Remote personnel shall:
☐ Use approved devices
☐ Use secure authentication
☐ Use MFA
☐ Protect confidential information
☐ Secure their physical workspace
☐ Avoid unauthorized public sharing
☐ Use approved remote-access methods
☐ Protect devices from family/third-party access
☐ Report security incidents promptly
21. Public and Shared Environments
Employees shall take care when working in:
- Cafés
- Airports
- Hotels
- Coworking spaces
- Public transport
- Customer locations
- Shared offices
Personnel should prevent unauthorized persons from viewing or accessing confidential information.
22. Clean Desk and Clear Screen
Employees shall:
☐ Lock screens when leaving workstations
☐ Avoid leaving confidential documents unattended
☐ Store sensitive documents securely
☐ Dispose of sensitive documents appropriately
☐ Avoid displaying confidential information unnecessarily
☐ Protect whiteboards containing sensitive information
23. Software and Applications
Employees shall:
☐ Use approved software
☐ Follow software licensing requirements
☐ Avoid unauthorized applications
☐ Avoid downloading software from untrusted sources
☐ Request approval where required
☐ Report suspicious software
Employees shall not install software merely to bypass organizational security controls.
24. Cloud and SaaS Applications
Employees shall use only approved cloud/SaaS services for organizational information where required.
Employees shall:
☐ Follow approved application requirements
☐ Protect cloud credentials
☐ Avoid uploading confidential information to unauthorized services
☐ Avoid creating unauthorized company accounts
☐ Report suspected shadow IT
☐ Follow data-transfer requirements
25. AI and Generative AI
Employees shall follow organizational requirements when using AI tools.
Unless specifically authorized, employees should not submit:
- Passwords
- API keys
- Private keys
- Customer confidential information
- Restricted information
- Sensitive personal data
- Proprietary source code
- Security credentials
- Unpublished security findings
Employees shall:
☐ Use approved AI services where required
☐ Understand applicable data-use restrictions
☐ Verify AI-generated outputs where appropriate
☐ Protect confidential information
☐ Report accidental disclosure
26. Information Transfer
Before sending sensitive information, employees shall:
☐ Confirm the recipient
☐ Confirm the recipient is authorized
☐ Use approved transfer channels
☐ Use encryption where required
☐ Minimize the information transferred
☐ Verify unusual requests
☐ Avoid unnecessary external sharing
27. Physical Security
Employees shall:
☐ Protect access cards
☐ Prevent unauthorized entry
☐ Challenge or report suspicious access where appropriate
☐ Secure company equipment
☐ Follow visitor requirements
☐ Report lost access cards
☐ Protect restricted areas
Employees shall not allow unauthorized individuals to use their access credentials or badges.
28. Security Incident Reporting
Employees shall promptly report suspected or actual security incidents.
Examples include:
☐ Phishing
☐ Malware
☐ Lost device
☐ Stolen device
☐ Unauthorized access
☐ Credential compromise
☐ Accidental data disclosure
☐ Mis-sent email
☐ Exposed API key
☐ Suspicious cloud activity
☐ Unauthorized software
☐ Security-policy violation
Reporting Contact
Security Contact: ______________________
Email: _________________________________
Phone/Channel: _________________________
29. Security Event Reporting
Not every security event is necessarily a confirmed incident.
Employees should report suspicious events such as:
- Unexpected MFA prompts
- Suspicious login notifications
- Unusual system behavior
- Suspicious emails
- Unexpected password resets
- Unknown software
- Unusual cloud activity
The security team can then assess whether the event requires incident response.
30. Vulnerability Reporting
Employees shall report:
☐ Security weaknesses
☐ Exposed credentials
☐ Misconfigured systems
☐ Unpatched systems
☐ Suspicious applications
☐ Insecure processes
☐ Accidental data exposure
Employees should not attempt unauthorized security testing or exploitation.
31. Security Testing
Only authorized personnel may perform security testing.
Employees shall not conduct unauthorized:
- Vulnerability scanning
- Penetration testing
- Exploitation
- Password testing
- Network scanning
- Social engineering
- Security-tool deployment
Security testing shall follow approved authorization and scope.
32. Change Management
Employees making changes to organizational systems shall:
☐ Follow approved change procedures
☐ Obtain required authorization
☐ Test changes where required
☐ Document significant changes
☐ Follow rollback requirements
☐ Protect production systems
☐ Report failed or unauthorized changes
33. Data Retention and Disposal
Employees shall:
☐ Retain information according to applicable requirements
☐ Avoid unnecessary copies
☐ Delete information when authorized and no longer required
☐ Use approved disposal methods
☐ Avoid placing sensitive information in personal storage
Employees shall not independently delete records subject to legal, contractual, investigation, or retention requirements.
34. Intellectual Property
Employees shall protect:
- Source code
- Designs
- Product information
- Business plans
- Documentation
- Trade secrets
- Customer information
- Proprietary methods
Employees shall not disclose organizational intellectual property without authorization.
35. Third-Party Information
Employees handling supplier or partner information shall:
☐ Protect confidential information
☐ Follow contractual restrictions
☐ Use information only for authorized purposes
☐ Avoid unauthorized disclosure
☐ Follow approved transfer methods
36. Customer-Specific Requirements
Where customer contracts impose additional security requirements:
☐ Employees shall be informed where applicable
☐ Applicable requirements shall be followed
☐ Customer information shall be handled according to agreed requirements
☐ Exceptions shall be escalated
☐ Customer security incidents shall be reported through approved channels
37. Security Awareness
Employees shall complete required security awareness activities.
Requirements may include:
- New-joiner training
- Annual security awareness
- Phishing awareness
- Role-specific security training
- Privacy training
- Secure development training
- Cloud security training
- AI security awareness
Training completion may be monitored.
38. Policy Compliance
Employees shall comply with applicable:
- Information Security Policy
- Acceptable Use Policy
- Access Management Policy
- Password/MFA requirements
- Data Protection Policy
- Remote Working Policy
- Incident Response Procedure
- AI Usage Policy
- Asset Management requirements
- Other applicable security procedures
39. Reporting Policy Violations
Employees shall report known or suspected violations through approved channels.
Examples:
☐ Unauthorized access
☐ Credential sharing
☐ Data leakage
☐ Unauthorized software
☐ Bypassing security controls
☐ Misuse of company systems
☐ Improper handling of customer data
☐ Intentional security-policy violations
40. Cooperation With Investigations
Personnel shall cooperate with authorized security investigations.
Where appropriate, employees may be required to:
- Provide relevant information
- Preserve evidence
- Follow investigation instructions
- Participate in interviews
- Avoid altering relevant records
- Protect investigation confidentiality
Employees shall not independently delete or modify potentially relevant evidence.
41. Audit and Compliance Cooperation
Employees may be required to support:
- Internal audits
- Security assessments
- Customer audits
- Certification audits
- Compliance reviews
- Security investigations
Employees shall provide accurate information and appropriate evidence within their authority.
42. Business Continuity Responsibilities
Employees assigned business-continuity responsibilities shall:
☐ Understand their recovery role
☐ Maintain required contact information
☐ Participate in exercises where required
☐ Follow emergency procedures
☐ Protect critical information during disruptions
☐ Support recovery activities
43. Emergency Access
Where emergency access is required:
☐ Use approved emergency procedures
☐ Obtain authorization where practical
☐ Use only the minimum required access
☐ Record emergency activity
☐ Report activity afterward where required
☐ Return to normal access arrangements after the emergency
44. Contractor and Third-Party Responsibilities
Contractors and third-party personnel shall comply with applicable security requirements established through:
- Contracts
- Security agreements
- Supplier requirements
- Access conditions
- Organizational policies
Their access shall be limited to authorized business requirements.
45. Role-Specific Responsibilities
Additional responsibilities may apply to:
Developers
☐ Secure coding
☐ Code review
☐ Secret protection
☐ Dependency security
☐ Approved deployment processes
DevOps/Cloud Administrators
☐ Privileged-access protection
☐ Cloud configuration
☐ Logging
☐ Infrastructure security
☐ Production access controls
Security Personnel
☐ Security monitoring
☐ Incident response
☐ Security-tool protection
☐ Vulnerability management
☐ Evidence protection
Finance Personnel
☐ Financial information protection
☐ Payment authorization controls
☐ Segregation of duties
☐ Fraud/security reporting
HR Personnel
☐ Personnel-data protection
☐ Restricted HR-system access
☐ Background-verification confidentiality
☐ Secure personnel-record handling
46. Prohibited Activities
Unless explicitly authorized, employees shall not:
- Share credentials
- Circumvent security controls
- Access unauthorized information
- Install unauthorized security tools
- Perform unauthorized penetration testing
- Upload restricted information to unauthorized services
- Publish confidential information
- Disable security controls
- Copy sensitive information unnecessarily
- Use company systems for unauthorized activities
47. Employee Security Acknowledgement
Where required, employees shall acknowledge that they:
☐ Have received applicable security requirements
☐ Understand their responsibilities
☐ Know how to report security incidents
☐ Understand credential requirements
☐ Understand information-protection requirements
☐ Understand acceptable-use requirements
☐ Understand applicable confidentiality obligations
☐ Understand that access is provided only for authorized purposes
Employee
Name: _________________________________
Employee ID: __________________________
Role: __________________________________
Date: __________________________________
Signature/Acknowledgement: _____________
48. Security Responsibility During Role Changes
When an employee changes role:
☐ Responsibilities are updated
☐ Security responsibilities are reassessed
☐ Access is reviewed
☐ Additional training is provided where required
☐ Sensitive-role classification is reassessed
☐ Privileged access is reviewed
☐ Confidentiality requirements are updated where necessary
49. Responsibilities During Offboarding
Before leaving the organization, personnel shall:
☐ Return company equipment
☐ Return access cards/tokens
☐ Return organizational information where required
☐ Stop using organizational accounts
☐ Transfer required business information
☐ Protect continuing confidentiality obligations
☐ Follow information-return/deletion requirements
Access revocation shall be managed through the organization’s offboarding process.
50. Management Responsibilities
Managers shall:
☐ Ensure personnel understand relevant responsibilities
☐ Approve access based on business need
☐ Notify HR/IT of role changes
☐ Notify relevant teams of termination
☐ Support security training
☐ Address security violations
☐ Ensure sensitive responsibilities are appropriately assigned
51. Security Responsibility Monitoring
The organization may monitor:
- Security training completion
- Policy acknowledgement
- Access compliance
- Security incidents
- Policy violations
- Phishing results
- Privileged access
- Sensitive-role compliance
- Offboarding completion
Monitoring should be proportionate and comply with applicable requirements.
52. Exceptions
Where an employee cannot comply with a security requirement:
☐ Business justification documented
☐ Security risk assessed
☐ Alternative control considered
☐ Appropriate approval obtained
☐ Exception expiry/review date defined
☐ Exception monitored
Employees shall not create informal exceptions to security requirements.
53. Consequences of Non-Compliance
Failure to follow security responsibilities may result in:
- Additional training
- Access restriction
- Corrective action
- Investigation
- Disciplinary action
- Contractual action for third parties
- Other actions consistent with applicable law and organizational processes
The response shall be proportionate to the circumstances and handled through established processes.
54. AWS SaaS Startup Example
For an AWS SaaS startup, an employee with normal SaaS application access may primarily be responsible for:
MFA → Password protection → Data protection → Phishing awareness → Incident reporting
A DevOps engineer may additionally be responsible for:
Privileged access → Cloud security → Production changes → Secrets protection → Logging → Incident escalation
An AWS administrator may have additional requirements for:
Named account → MFA → Least privilege → Secure administration → Production access → Logging → Periodic access review
The security responsibilities should therefore reflect the actual risk and access of the role.
55. Startup-Friendly Employee Security Model
Every employee should remember five basic responsibilities:
1. Protect
Protect information, devices, credentials, and company assets.
2. Access
Use only the systems and information required for your role.
3. Verify
Verify unusual requests, links, attachments, payments, and credential requests.
4. Report
Report suspected security incidents quickly.
5. Follow
Follow organizational security policies and approved procedures.
Protect → Access → Verify → Report → Follow
56. Common Mistakes
Employees should avoid:
- Sharing passwords
- Approving unexpected MFA prompts
- Sending confidential data to personal email
- Uploading sensitive information to unauthorized AI tools
- Committing secrets to source-code repositories
- Using unauthorized SaaS applications
- Leaving devices unlocked
- Ignoring phishing
- Delaying incident reporting
- Accessing information without business need
- Using privileged access for convenience
- Performing unauthorized security testing
- Ignoring security requirements after changing roles
- Taking company information after leaving
57. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Human Resources Security Policy | Defines personnel-security governance |
| Employee Screening Policy | Defines screening requirements |
| Background Verification Procedure | Defines verification |
| Sensitive Role Identification Checklist | Identifies sensitive roles |
| Role-Based Screening Matrix | Determines screening level |
| Security Awareness Procedure | Defines training |
| Acceptable Use Policy | Defines acceptable system use |
| Access Management Procedure | Controls access |
| Privileged Access Procedure | Controls privileged access |
| Remote Working Policy | Defines remote-working security |
| Incident Response Procedure | Defines incident handling |
| Employee Offboarding Procedure | Controls exit |
| Security Policy Acknowledgement Register | Records acknowledgements |
| HR Security Audit Checklist | Audits HR security controls |
58. ISO/IEC 27001 Connection
Employee security responsibilities support the organization’s personnel-security and access-control arrangements.
Relevant areas may include:
- Personnel screening
- Employment terms and responsibilities
- Security awareness and training
- Confidentiality
- Access control
- Privileged access
- Information protection
- Remote working
- Incident reporting
- Personnel changes
- Termination or change of employment
The Employee Security Responsibilities document is not itself a universally prescribed ISO/IEC 27001 document title. The organization should determine the appropriate employee responsibilities based on its ISMS scope, risk assessment, applicable controls, legal requirements, contractual requirements, customer requirements, and business needs.
59. Audit Evidence Checklist
The organization should be able to demonstrate:
☐ Employee security responsibilities
☐ Human Resources Security Policy
☐ Employment/security terms
☐ NDA/confidentiality requirements
☐ Security awareness records
☐ Policy acknowledgements where applicable
☐ Access approvals
☐ Privileged-access approvals
☐ Sensitive-role assessments
☐ Background verification records
☐ Incident reporting records
☐ Role-change records
☐ Offboarding records
☐ Asset-return records
☐ Security exceptions
☐ Corrective actions
60. Final Employee Security Audit Trail
The organization should be able to demonstrate:
Did the employee understand their security responsibilities?
Were those responsibilities appropriate to their role?
Was the employee appropriately screened where required?
Were confidentiality obligations established?
Was security training completed?
Was access authorized and limited?
Was privileged access appropriately controlled?
Did the employee know how to report incidents?
Were role changes reviewed?
Were security violations addressed?
Was access removed when employment ended?
Were organizational assets and information protected?
Final Principle
Information security is not only the responsibility of the security or IT team. Every employee and applicable third party has security responsibilities based on the information they handle, systems they access, and authority they possess. Clear responsibilities, appropriate training, controlled access, timely reporting, and effective offboarding turn personnel security requirements into everyday security practices.
