1. Purpose
The Employee Termination Security Checklist provides a structured process for securely managing the termination of an employee, contractor, intern, consultant, or other personnel.
The objective is to ensure that when employment or engagement ends:
- Access is revoked at the appropriate time
- Organizational information remains protected
- Company assets are recovered
- Privileged and production access is removed
- Cloud, SaaS, source-code, and remote access are addressed
- Credentials, tokens, and secrets are managed
- Business responsibilities are transferred
- Confidentiality obligations remain protected
- Security incidents or investigations are not accidentally disrupted
- Evidence of completion is retained
Core Principle
Identify → Notify → Assess → Revoke → Recover → Protect → Transfer → Verify → Record → Close
2. When to Use
Use this checklist when:
☐ Employee resignation
☐ Involuntary termination
☐ Contract completion
☐ Internship completion
☐ Consultant/contractor termination
☐ Immediate/high-risk termination
☐ Long-term leave requiring access suspension
☐ Organizational restructuring
☐ Role elimination
☐ Supplier/third-party personnel departure
The checklist should be adapted based on the person’s role, access, information handled, and security risk.
3. Employee Termination Information
| Field | Details |
|---|---|
| Employee Name | |
| Employee ID | |
| Department | |
| Job Title | |
| Manager | |
| Employment Type | |
| Termination Type | |
| Notice Date | |
| Effective Termination Date | |
| Effective Termination Time | |
| Risk Level | |
| HR Owner | |
| IT Owner | |
| Security Reviewer | |
| Checklist ID | |
| Completion Date |
4. Termination Type
☐ Voluntary resignation
☐ Involuntary termination
☐ Immediate termination
☐ Contract completion
☐ Internship completion
☐ Retirement
☐ Redundancy
☐ Role elimination
☐ Other: __________________________
Termination Risk
☐ Low
☐ Medium
☐ High
☐ Critical
Risk Factors
☐ Privileged access
☐ Production access
☐ AWS/cloud access
☐ Source-code access
☐ Database access
☐ Customer information
☐ Personal data
☐ Financial information
☐ Security administration
☐ Access to secrets/credentials
☐ Active security investigation
☐ Access to critical business systems
☐ Other: __________________________
5. Termination Notification
Confirm that the appropriate personnel have been notified.
☐ HR notified
☐ Manager notified
☐ IT notified
☐ Information Security notified where required
☐ System owners notified where required
☐ Facilities/security notified where required
☐ Relevant business owners notified
☐ Termination timing confirmed
☐ Immediate termination requirements identified
Notification Record
| Person/Team | Notification Date | Method | Confirmed By |
|---|---|---|---|
| HR | |||
| Manager | |||
| IT | |||
| Information Security | |||
| Facilities | |||
| System Owners |
6. Termination Timing
Define when access must be removed.
Termination Date: __________________
Termination Time: __________________
Access Revocation Deadline: __________________
☐ Access removal scheduled
☐ Immediate access removal required
☐ Access removal coordinated with termination meeting
☐ After-hours termination process considered where required
☐ Time zone considered for remote employees
For high-risk termination, access removal should be coordinated so that unnecessary access does not remain available after termination.
7. Access Inventory
Identify all access held by the employee.
☐ Corporate identity
☐ Email
☐ VPN
☐ MFA
☐ SSO
☐ AWS/cloud
☐ Azure/GCP where applicable
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ Production systems
☐ Databases
☐ SaaS applications
☐ CRM
☐ HR systems
☐ Finance systems
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ Collaboration tools
☐ Password manager
☐ VPN/firewall
☐ Remote-access tools
☐ Physical access
☐ Other systems
8. Corporate Identity
☐ Corporate identity disabled
☐ Login access removed
☐ SSO access disabled
☐ MFA access revoked
☐ Recovery methods removed
☐ Authentication devices addressed
☐ Active sessions terminated where appropriate
☐ Authentication tokens revoked
☐ Account status verified
Evidence
9. Email and Collaboration
☐ Corporate email disabled
☐ Active email sessions terminated
☐ Email forwarding reviewed
☐ Automatic forwarding removed
☐ Mailbox ownership transferred where required
☐ Business-critical correspondence identified
☐ Shared mailbox access reviewed
☐ Slack/Teams access removed
☐ Collaboration groups reviewed
☐ Calendar ownership transferred
☐ Shared files reviewed
Email termination alone should not be treated as proof that all organizational access has been removed.
10. Cloud Access
If the employee has cloud access:
☐ AWS access reviewed
☐ IAM users disabled/deleted where appropriate
☐ IAM roles reviewed
☐ Role assignments removed
☐ Access keys revoked
☐ MFA devices addressed
☐ Temporary credentials invalidated where applicable
☐ Console access removed
☐ CLI/API access addressed
☐ Cloud security groups/permissions reviewed where applicable
☐ Cloud ownership transferred
☐ Cloud logs preserved where required
11. Source-Code Access
If the employee has development access:
☐ GitHub access removed
☐ GitLab access removed
☐ Bitbucket access removed
☐ Repository permissions reviewed
☐ Organization membership removed
☐ Production repository access removed
☐ CI/CD access removed
☐ Deployment permissions removed
☐ Code-signing access reviewed
☐ Repository ownership transferred
☐ Pull-request responsibilities transferred
☐ Personal access tokens revoked
12. Production Access
For production access:
☐ Production access identified
☐ Production accounts disabled
☐ Privileged roles removed
☐ SSH access removed
☐ Bastion access removed
☐ Database access removed
☐ Kubernetes access removed
☐ Cloud production permissions removed
☐ Monitoring access removed
☐ Emergency access credentials reviewed
☐ Shared credentials rotated where necessary
Production Access Verification
| System | Access Type | Revoked | Verified By | Date |
|---|---|---|---|---|
| ☐ | ||||
| ☐ | ||||
| ☐ |
13. Privileged Access
If the employee had privileged access:
☐ Administrator access identified
☐ Privileged accounts disabled
☐ Privileged roles removed
☐ Root-equivalent access reviewed
☐ Break-glass access reviewed
☐ Shared administrator credentials changed where necessary
☐ Privileged sessions terminated
☐ Privileged access logs preserved where appropriate
☐ New administrator assigned where required
Privileged Access Verification
14. SaaS Applications
Review all relevant SaaS platforms.
| Application | Access Type | Revoked | Verified By |
|---|---|---|---|
| ☐ | |||
| ☐ | |||
| ☐ | |||
| ☐ |
Examples may include:
- CRM
- HR platform
- Accounting
- Project management
- Cloud security tools
- Password manager
- Customer support
- Analytics
- Marketing platforms
- Communication platforms
15. Credentials, Tokens and Secrets
Identify credentials that may have been accessible to the employee.
☐ Passwords reviewed
☐ API keys reviewed
☐ Personal access tokens reviewed
☐ SSH keys reviewed
☐ Cloud credentials reviewed
☐ Database credentials reviewed
☐ Service-account access reviewed
☐ Certificates reviewed
☐ Encryption-key access reviewed
☐ Secrets stored in password manager reviewed
☐ Shared secrets rotated where necessary
☐ Credentials embedded in scripts/configuration reviewed
Secret Rotation Required?
☐ Yes
☐ No
Details
16. Customer and Supplier Access
If the employee had access to external organizations:
☐ Customer portals reviewed
☐ Customer accounts removed
☐ Supplier portals reviewed
☐ Third-party systems reviewed
☐ External collaboration accounts removed
☐ Customer contact responsibilities transferred
☐ Supplier responsibilities transferred
☐ External administrator access reviewed
17. Information Protection
Identify information handled by the employee.
☐ Customer information
☐ Personal data
☐ Confidential information
☐ Restricted information
☐ Source code
☐ Security information
☐ Financial information
☐ Contracts
☐ Credentials/secrets
☐ Intellectual property
Information Handling
☐ Information ownership transferred
☐ Business files transferred where required
☐ Unauthorized copies addressed where appropriate
☐ Local storage reviewed where permitted
☐ Cloud storage reviewed
☐ Shared folders reviewed
☐ Personal repositories reviewed where applicable and lawful
☐ Confidentiality requirements reiterated
18. Data Return and Deletion
Where applicable:
☐ Company information returned
☐ Company information transferred to authorized owner
☐ Unauthorized copies addressed
☐ Information deleted where authorized and required
☐ Cloud storage reviewed
☐ Local storage addressed
☐ Removable media addressed
☐ Data retention requirements considered
Do not delete information that must be retained for legal, regulatory, contractual, audit, or investigation purposes.
19. Company Assets
Identify assets assigned to the employee.
☐ Laptop
☐ Desktop
☐ Mobile phone
☐ Tablet
☐ Security token
☐ Smart card
☐ USB/removable media
☐ Hardware security key
☐ Monitor
☐ Other equipment
Asset Return Record
| Asset | Asset ID | Returned | Condition | Verified By |
|---|---|---|---|---|
| ☐ | ||||
| ☐ | ||||
| ☐ |
20. Device Security
After asset recovery:
☐ Device received
☐ Device ownership verified
☐ Device condition recorded
☐ Device security status reviewed
☐ Corporate account removed
☐ Device management status reviewed
☐ Encryption status verified where applicable
☐ Device retained for investigation if required
☐ Secure wipe performed when authorized
☐ Device reassigned only after appropriate security processing
21. Mobile Devices
For company-managed mobile devices:
☐ Corporate account removed
☐ MDM access reviewed
☐ Device lock enforced where required
☐ Corporate applications removed
☐ Corporate certificates removed
☐ Corporate credentials removed
☐ Remote wipe performed where authorized
☐ SIM/eSIM addressed
☐ Device recovered
22. Physical Access
☐ Office access card returned
☐ Building access disabled
☐ Restricted-area access removed
☐ Data-center access removed
☐ Visitor privileges removed
☐ Parking access addressed
☐ Physical keys returned
☐ Security tokens returned
Physical Access Verification
23. Business Ownership Transfer
Identify business responsibilities that must continue.
☐ Projects reassigned
☐ Customer responsibilities transferred
☐ Supplier responsibilities transferred
☐ System ownership transferred
☐ Repository ownership transferred
☐ Documentation ownership transferred
☐ Security responsibilities transferred
☐ Incident-response responsibilities transferred
☐ Business continuity responsibilities transferred
24. Knowledge Transfer
Where required:
☐ Operational knowledge transferred
☐ Critical procedures documented
☐ System documentation updated
☐ Architecture knowledge transferred
☐ Customer knowledge transferred
☐ Supplier knowledge transferred
☐ Security knowledge transferred
☐ Emergency procedures transferred
25. Confidentiality
Confirm continuing confidentiality obligations.
☐ NDA/confidentiality agreement reviewed
☐ Continuing confidentiality obligations communicated
☐ Intellectual property obligations reviewed
☐ Customer confidentiality obligations reviewed
☐ Security responsibilities communicated
☐ Post-termination restrictions reviewed where applicable
Legal obligations should be reviewed by appropriate legal personnel.
26. Security Incident or Investigation Check
Before closing the termination:
☐ Employee involved in active security investigation?
☐ Employee involved in unresolved security incident?
☐ Relevant logs preserved?
☐ Evidence preserved?
☐ Investigation owner notified?
☐ Legal/HR notified where required?
☐ Account deletion coordinated with investigation requirements?
Investigation Reference
Do not destroy potentially relevant evidence solely because the employee has left the organization.
27. High-Risk Termination
For high-risk or immediate termination:
☐ Risk assessment completed
☐ Security/HR coordination completed
☐ Access revocation synchronized
☐ Privileged access removed first where appropriate
☐ Cloud access removed
☐ Production access removed
☐ Source-code access removed
☐ VPN access removed
☐ Email/session access addressed
☐ Credentials/secrets reviewed
☐ Relevant logs preserved
☐ Assets secured
☐ Investigation requirements assessed
☐ Independent verification completed
28. Remote Employee
For remote employees:
☐ Remote access disabled
☐ VPN access removed
☐ Cloud access removed
☐ SaaS access removed
☐ Device recovery arranged
☐ Shipping/collection documented
☐ Company information addressed
☐ BYOD access removed where applicable
☐ Authentication devices recovered or revoked
29. BYOD
If Bring Your Own Device was permitted:
☐ Corporate accounts removed
☐ MDM controls removed or updated
☐ Corporate applications removed
☐ Corporate certificates removed
☐ Corporate data removed where authorized
☐ Tokens/session access revoked
☐ Corporate storage access removed
☐ Personal data protected during corporate-data removal
BYOD actions should follow applicable law and the organization’s approved BYOD policy.
30. Final Access Verification
A second person should verify termination activities for sensitive or high-risk roles where practical.
☐ Identity disabled
☐ Email disabled
☐ VPN disabled
☐ MFA addressed
☐ Cloud access removed
☐ AWS access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Physical access removed
☐ Customer access removed
☐ Supplier access removed
Verification
Verified By: __________________________
Date/Time: __________________________
Result: ☐ Complete ☐ Exceptions Identified
31. Exceptions
Document any access or activity that could not be completed immediately.
| Exception | Reason | Risk | Compensating Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
All exceptions should be risk-assessed and formally approved where required.
32. Termination Completion Record
| Activity | Completed | Evidence | Verified By |
|---|---|---|---|
| HR notification | ☐ | ||
| Access review | ☐ | ||
| Identity revocation | ☐ | ||
| Cloud access removal | ☐ | ||
| Production access removal | ☐ | ||
| Source-code access removal | ☐ | ||
| SaaS access removal | ☐ | ||
| Credential review | ☐ | ||
| Asset recovery | ☐ | ||
| Physical access removal | ☐ | ||
| Information protection | ☐ | ||
| Ownership transfer | ☐ | ||
| Final verification | ☐ |
33. Evidence Retention
Retain appropriate evidence such as:
☐ Termination notification
☐ Access-revocation records
☐ IAM evidence
☐ SaaS deactivation evidence
☐ Asset-return record
☐ Physical-access removal evidence
☐ Credential-rotation evidence
☐ Ownership-transfer record
☐ Final verification
☐ Approved exceptions
☐ Investigation records where applicable
Do not unnecessarily retain passwords, private keys, authentication secrets, or other sensitive credentials as evidence.
34. Termination Register
Maintain a record of completed terminations where appropriate.
| Employee ID | Termination Date | Risk | Access Revoked | Assets Returned | Verified | Status |
|---|---|---|---|---|---|---|
| ☐ | ☐ | ☐ | ||||
| ☐ | ☐ | ☐ |
35. Completion Criteria
The termination should not be marked Complete until:
☐ Required access has been revoked
☐ Privileged access has been addressed
☐ Cloud and SaaS access has been addressed
☐ Production/source-code access has been addressed
☐ Assets have been recovered or exception approved
☐ Information responsibilities have been transferred
☐ Credentials/secrets have been reviewed
☐ Physical access has been removed
☐ Investigation requirements have been addressed
☐ Exceptions have been documented
☐ Final verification has been completed
☐ Evidence has been retained
36. Final Approval
Employee: ______________________________
Manager: ______________________________
HR Representative: ______________________________
IT Representative: ______________________________
Security Reviewer: ______________________________
Termination Date: ______________________________
Checklist Completion Date: ______________________________
Overall Status:
☐ Complete
☐ Complete with Approved Exceptions
☐ Further Action Required
Comments
37. AWS SaaS Startup Example
A DevOps engineer leaves a SaaS startup and has access to:
- AWS production
- GitHub
- CI/CD
- Production database
- Monitoring
- VPN
- Slack
- Corporate email
- Password manager
Termination Actions
HR → confirms termination time.
Manager → identifies responsibilities and replacement owners.
IT → disables corporate identity, VPN, email, and collaboration access.
Security → verifies privileged-access removal.
Cloud Owner → revokes AWS IAM access, access keys, roles, and MFA-related access as applicable.
Engineering → removes GitHub, CI/CD, deployment, and repository permissions.
Database Owner → removes production database access.
Security → reviews whether shared credentials, tokens, or secrets require rotation.
Asset Team → recovers company laptop and security keys.
Second Reviewer → independently verifies that critical access has been removed.
Audit Trail
Termination Notice → Risk Assessment → Access Inventory → Revoke Access → Rotate Required Secrets → Recover Assets → Transfer Ownership → Verify → Record
38. Startup-Friendly Termination Model
For a small startup, the process can remain simple:
Step 1 — HR Notification
Notify the manager and IT/security.
Step 2 — Access Inventory
Check:
- Google/Microsoft account
- AWS
- GitHub
- VPN
- SaaS
- Production
- Database
- Password manager
Step 3 — Revoke
Disable accounts and remove permissions.
Step 4 — Protect
Review tokens, API keys, shared passwords, secrets, and sensitive information.
Step 5 — Recover
Recover laptop, phone, security keys, cards, and other assets.
Step 6 — Transfer
Transfer projects, repositories, customer relationships, and system ownership.
Step 7 — Verify
A second person verifies critical access removal.
Step 8 — Record
Store evidence and close the termination record.
39. Common Mistakes
Avoid:
- Disabling only the email account.
- Waiting until the next business day for access removal.
- Forgetting AWS/cloud accounts.
- Forgetting GitHub/GitLab access.
- Forgetting CI/CD permissions.
- Forgetting production databases.
- Forgetting VPN access.
- Forgetting SaaS applications.
- Forgetting physical access.
- Forgetting API keys and tokens.
- Forgetting shared credentials.
- Failing to transfer system ownership.
- Deleting evidence needed for an investigation.
- Wiping a device before checking whether evidence must be preserved.
- Marking termination complete without independent verification.
- Leaving undocumented exceptions.
- Assuming HR notification automatically removes technical access.
40. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Human Resources Security Policy | Defines personnel-security requirements |
| Employee Offboarding Policy | Defines overall offboarding requirements |
| Employee Offboarding Checklist | Provides broader operational offboarding steps |
| Joiner-Mover-Leaver Procedure | Manages personnel lifecycle |
| Access Management Procedure | Controls account and access lifecycle |
| Privileged Access Procedure | Controls administrative access |
| Cloud Access Review Checklist | Verifies cloud access |
| Source Code Access Review Checklist | Verifies development access |
| Asset Return Procedure | Controls company asset recovery |
| Confidentiality Agreement | Defines confidentiality obligations |
| Information Classification Policy | Defines information protection requirements |
| Security Investigation Procedure | Protects investigation evidence |
| Security Incident Management Policy | Addresses security incidents |
| Security Violation Investigation Procedure | Handles suspected personnel violations |
| Risk Register | Records significant termination-related risks |
| Corrective Action Tracker | Tracks unresolved termination findings |
41. ISO 27001 Connection
Employee termination security supports the organization’s management of personnel security, access rights, authentication, information protection, asset handling, and organizational responsibilities throughout the employment lifecycle.
The Employee Termination Security Checklist is not itself a universally mandatory ISO 27001 form. The organization should determine the appropriate termination controls based on:
- ISMS scope
- Risk assessment
- Personnel roles
- Information handled
- System access
- Privileged access
- Legal and regulatory requirements
- Customer requirements
- Contractual obligations
- Business requirements
The organization should be able to demonstrate that termination or change of employment does not leave inappropriate access or uncontrolled information behind.
42. Final Audit Checklist
Before closing the termination, confirm:
☐ Termination formally authorized
☐ Termination date/time recorded
☐ Risk assessed
☐ Access inventory completed
☐ Corporate identity disabled
☐ Email disabled
☐ VPN removed
☐ MFA addressed
☐ Cloud access removed
☐ AWS access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Customer access removed
☐ Supplier access removed
☐ Tokens/API keys reviewed
☐ Shared credentials rotated where necessary
☐ Company assets recovered
☐ Physical access removed
☐ Information transferred/protected
☐ Business ownership transferred
☐ Confidentiality obligations confirmed
☐ Investigation requirements checked
☐ Exceptions documented
☐ Final verification completed
☐ Evidence retained
☐ Termination record closed
43. Final Audit Trail
For every significant termination, the organization should be able to demonstrate:
When was the employee terminated?
Who authorized the termination?
What was the termination risk?
What access did the employee have?
When was access revoked?
Was privileged access removed?
Was cloud/AWS access removed?
Was production access removed?
Was source-code access removed?
Were SaaS and VPN accounts removed?
Were credentials, tokens, and secrets reviewed?
Were company assets recovered?
Was organizational information protected?
Were responsibilities transferred?
Were investigation requirements considered?
Who verified completion?
Were exceptions documented and approved?
What evidence proves the termination was completed?
Final Principle
An employee termination is not complete when HR records the departure. It is complete when access, information, assets, responsibilities, credentials, physical access, and security dependencies have been appropriately addressed, verified, and recorded.
