ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Employment Security Clause Template

Employment Security Clause Template

Important: This is a security-control template, not legal advice. Employment terms should be reviewed and adapted by the organization’s HR/legal function for applicable employment, privacy, labor, intellectual-property, and data-protection requirements.


1. Purpose

This Employment Security Clause Template provides standard security-related provisions that may be incorporated into employment agreements, appointment letters, employment terms, contractor agreements, or related personnel documentation.

The clauses are intended to establish clear security responsibilities throughout the employment lifecycle.

Core Principle

Define → Communicate → Accept → Comply → Protect → Report → Return → Continue


2. Applicability

The applicable clauses should be selected based on:

  • Employee role
  • Information accessed
  • System access
  • Privileged access
  • Production access
  • Customer requirements
  • Personal-data access
  • Regulatory requirements
  • Contractual requirements
  • Intellectual-property exposure
  • Remote-working arrangements
  • Applicable law

Not every employee necessarily requires every clause.


3. Information Security Responsibilities

The Employee shall comply with the Company’s applicable information-security policies, procedures, standards, and instructions.

The Employee shall take reasonable and appropriate measures to protect Company information, systems, devices, credentials, and other organizational assets against unauthorized access, use, disclosure, alteration, loss, or destruction.

The Employee shall use Company information and systems only for authorized business purposes.


4. Confidentiality

The Employee shall maintain the confidentiality of non-public information obtained, accessed, or created during employment.

Confidential information may include:

  • Customer information
  • Personal data
  • Source code
  • Credentials
  • Security information
  • Business plans
  • Financial information
  • Product information
  • Technical information
  • Intellectual property
  • Internal documentation
  • Trade secrets
  • Other information designated as confidential or reasonably understood to be confidential

The Employee shall not disclose confidential information to unauthorized persons or organizations.


5. Protection of Customer Information

Where the Employee has access to customer information, the Employee shall:

  • Access such information only for authorized purposes.
  • Follow applicable customer and contractual requirements.
  • Use approved systems and communication channels.
  • Avoid unnecessary copying or downloading.
  • Prevent unauthorized disclosure.
  • Report suspected exposure or misuse promptly.

6. Personal Data Protection

Where the Employee processes personal data, the Employee shall:

  • Use personal data only for authorized purposes.
  • Access only the information necessary for assigned responsibilities.
  • Follow applicable privacy and data-protection requirements.
  • Protect personal data from unauthorized access or disclosure.
  • Follow retention and disposal requirements.
  • Report suspected personal-data incidents promptly.

7. Access and Authentication

The Employee shall:

  • Use only assigned or authorized accounts.
  • Keep authentication credentials confidential.
  • Not share passwords or authentication factors.
  • Use MFA where required.
  • Not attempt to bypass security controls.
  • Access only systems and information authorized for the Employee’s role.
  • Report suspected credential compromise promptly.

The Employee’s access may be monitored and reviewed in accordance with applicable law and Company policy.


8. Privileged Access

Where the Employee is granted privileged or administrative access, the Employee shall:

  • Use privileged access only when required.
  • Follow least-privilege requirements.
  • Use named accounts where provided.
  • Use MFA where required.
  • Follow approved administrative procedures.
  • Protect privileged credentials.
  • Maintain appropriate records of significant administrative activity.
  • Comply with change-management requirements.

Privileged access may be subject to enhanced monitoring and periodic review.


9. Production Access

Where the Employee has access to production systems, the Employee shall:

  • Use production access only for authorized business purposes.
  • Follow approved change and deployment procedures.
  • Avoid unnecessary access to production data.
  • Protect production credentials.
  • Follow emergency-access procedures where applicable.
  • Report unauthorized or suspicious production activity.

10. Security Policies and Procedures

The Employee agrees to comply with applicable Company policies and procedures, including where relevant:

  • Information Security Policy
  • Acceptable Use Policy
  • Access Management Policy
  • Password and MFA requirements
  • Data Protection Policy
  • Remote Working Policy
  • Asset Management requirements
  • Incident Response Procedure
  • AI Usage Policy
  • Change Management Procedure
  • Information Classification requirements

The Company may update applicable policies and procedures from time to time in accordance with its established governance process.


11. Security Awareness and Training

The Employee shall complete security awareness and role-specific security training required by the Company.

Training may include:

  • Information security
  • Privacy
  • Phishing
  • Social engineering
  • Password security
  • MFA
  • Secure development
  • Cloud security
  • Incident reporting
  • AI security
  • Customer-specific security requirements

12. Security Incident Reporting

The Employee shall promptly report suspected or actual security incidents through the Company’s approved reporting channels.

Examples include:

  • Phishing
  • Malware
  • Lost or stolen devices
  • Credential compromise
  • Unauthorized access
  • Accidental data disclosure
  • Exposed credentials
  • Suspicious system activity
  • Unauthorized software
  • Customer-data exposure

The Employee should report a suspected incident even when the full impact is not yet known.


13. Security Weakness Reporting

The Employee shall report identified or suspected security weaknesses through approved channels.

Examples include:

  • Misconfigurations
  • Exposed credentials
  • Unpatched systems
  • Insecure applications
  • Unauthorized access
  • Data exposure
  • Security-control failures

The Employee shall not intentionally exploit a security weakness unless expressly authorized to perform security testing.


14. Company Devices and Assets

The Employee shall protect Company-issued or Company-controlled assets.

These may include:

  • Laptops
  • Mobile devices
  • Storage media
  • Security tokens
  • Access cards
  • Hardware
  • Software
  • Documentation
  • Other Company property

The Employee shall promptly report loss, theft, or suspected compromise of Company assets.


15. Remote Working

Where remote working is permitted, the Employee shall comply with applicable remote-working security requirements.

The Employee shall:

  • Protect Company devices.
  • Use approved authentication methods.
  • Use secure connections where required.
  • Prevent unauthorized persons from accessing Company information.
  • Protect confidential information from unauthorized viewing.
  • Report lost devices or suspected compromise promptly.

16. Software and Cloud Services

The Employee shall use approved software, applications, and cloud services for Company business where required.

The Employee shall not:

  • Install unauthorized software to bypass security controls.
  • Create unauthorized Company accounts.
  • Upload restricted information to unauthorized cloud services.
  • Store Company information in personal accounts without authorization.

17. Artificial Intelligence and Generative AI

Where AI or generative AI tools are used for Company activities, the Employee shall comply with applicable Company requirements.

Unless expressly authorized, the Employee shall not submit:

  • Confidential information
  • Restricted information
  • Customer information
  • Sensitive personal data
  • Passwords
  • API keys
  • Private keys
  • Security credentials
  • Proprietary source code
  • Unpublished security findings

The Employee shall review AI-generated output appropriately before relying on it for business or security-sensitive purposes.


18. Intellectual Property

All intellectual property created by the Employee in the course of employment shall be handled in accordance with applicable employment terms, Company policy, and applicable law.

The Employee shall protect Company intellectual property, including:

  • Source code
  • Designs
  • Documentation
  • Product information
  • Technical methods
  • Business information
  • Trade secrets
  • Security-related information

The specific ownership provisions should be defined separately by the Company’s legal/HR function where required.


19. Information Classification

The Employee shall handle information according to its applicable classification.

Where classifications are used, the Employee shall follow requirements concerning:

  • Access
  • Storage
  • Transmission
  • Sharing
  • Printing
  • Retention
  • Disposal

The Employee shall not downgrade, remove, or alter an information classification without authorization.


20. Information Sharing

Before sharing sensitive information, the Employee shall verify:

  • The recipient
  • The recipient’s authorization
  • The purpose of sharing
  • The approved transfer mechanism
  • Applicable contractual restrictions
  • Applicable privacy requirements

Sensitive information shall not be shared through unauthorized channels.


21. Password and Credential Protection

The Employee shall not:

  • Share passwords
  • Share MFA codes
  • Share API keys
  • Store credentials insecurely
  • Publish credentials
  • Commit secrets to source-code repositories
  • Send credentials through unauthorized communication channels

The Employee shall immediately report suspected credential exposure.


22. Security Testing

The Employee shall not perform unauthorized:

  • Vulnerability scanning
  • Penetration testing
  • Network scanning
  • Password testing
  • Exploitation
  • Social-engineering exercises
  • Security-tool deployment

Security testing shall require appropriate authorization and scope.


23. Monitoring and Logging

The Employee acknowledges that Company systems and activities may be subject to appropriate security monitoring, logging, and review in accordance with applicable law, Company policy, and legitimate business/security requirements.

Monitoring may include, where appropriate:

  • Authentication events
  • Access activity
  • Administrative activity
  • Security events
  • System activity
  • Network activity
  • Cloud activity

Monitoring requirements should be communicated appropriately and implemented in accordance with applicable privacy and employment requirements.


24. Background Verification

Where applicable and lawful, employment may be subject to background verification appropriate to the role.

Verification requirements may depend on:

  • Role sensitivity
  • Information access
  • Privileged access
  • Customer requirements
  • Regulatory requirements
  • Applicable law

Any verification process shall be conducted in accordance with applicable requirements.


25. Sensitive and High-Risk Roles

Where the Employee performs a security-sensitive role, additional requirements may apply.

Examples include:

  • Cloud administration
  • Production administration
  • Database administration
  • Security operations
  • VAPT
  • Source-code administration
  • Identity administration
  • Financial authority
  • Restricted-information handling

Additional controls may include enhanced screening, training, authorization, monitoring, or periodic review.


26. Conflicts of Interest

The Employee shall disclose relevant conflicts of interest where required by Company policy, employment terms, law, regulation, or the nature of the role.

Security-sensitive or regulated roles may be subject to additional conflict-of-interest requirements.


27. Third-Party and Customer Requirements

Where the Employee works on behalf of a customer or third party, the Employee shall comply with applicable security requirements communicated by the Company.

Such requirements may include:

  • Customer security policies
  • Data-handling requirements
  • Access restrictions
  • Confidentiality requirements
  • Security training
  • Incident reporting
  • Approved technology requirements

28. Security During Role Changes

When the Employee changes roles or responsibilities:

  • Access may be reviewed.
  • Existing access may be modified or removed.
  • New access shall require appropriate authorization.
  • Additional security training may be required.
  • Sensitive-role requirements may be reassessed.

The Employee shall cooperate with such changes.


29. Return of Company Assets

Upon termination of employment, or earlier when requested, the Employee shall return Company assets under their control.

This may include:

  • Laptops
  • Mobile devices
  • Access cards
  • Security tokens
  • Storage media
  • Documents
  • Equipment
  • Other Company property

30. Return and Protection of Information

Upon termination or when requested, the Employee shall:

  • Return Company information where required.
  • Stop using Company information except as legally permitted or specifically authorized.
  • Follow applicable information-deletion requirements.
  • Not retain unauthorized copies.
  • Protect continuing confidentiality obligations.

31. Access Revocation

Upon termination or role change, the Company may revoke or modify access to:

  • Corporate systems
  • Email
  • SaaS applications
  • Cloud environments
  • Production systems
  • Databases
  • Source-code repositories
  • VPN
  • Physical facilities

The Employee shall not attempt to regain or bypass revoked access.


32. Continuing Confidentiality

The Employee’s confidentiality obligations may continue after termination to the extent provided by applicable employment terms, agreements, law, or other applicable obligations.

The Employee shall continue to protect confidential information that remains subject to such obligations.


33. Cooperation With Security Investigations

The Employee shall reasonably cooperate with authorized security investigations relating to Company systems, information, or security incidents, subject to applicable law and Company procedures.

The Employee shall not intentionally alter, destroy, or conceal relevant evidence.


34. Disciplinary Process

Failure to comply with applicable security responsibilities may result in appropriate action under Company procedures and applicable law.

Potential actions may include:

  • Additional training
  • Corrective action
  • Access restriction
  • Investigation
  • Disciplinary action
  • Other appropriate employment action

Any action shall be handled through established HR/legal processes.


35. Security Exceptions

Employees shall not independently create exceptions to security requirements.

Where an exception is required:

  • Business justification shall be documented.
  • Risk shall be assessed.
  • Alternative controls shall be considered.
  • Appropriate approval shall be obtained.
  • The exception shall be monitored and reviewed.

36. Compliance With Law and Regulation

The Employee shall comply with applicable laws, regulations, contractual requirements, and Company policies relevant to their responsibilities.

Nothing in this template is intended to reduce or remove any legal obligation applicable to the Employee or Company.


37. Employee Acknowledgement

The Employee acknowledges that they have received or been provided access to applicable security requirements and understands their responsibility to protect Company information and systems.

Employee Name: ______________________________

Employee ID: _________________________________

Position: ____________________________________

Department: __________________________________

Date: ________________________________________

Employee Signature/Acknowledgement: ____________


38. Employer Acknowledgement

Authorized Representative: ____________________

Role: ________________________________________

Date: ________________________________________

Signature: ____________________________________


39. Role-Specific Security Schedule

Additional security requirements may be attached for specific roles.

Example: AWS Production Administrator

☐ MFA required
☐ Named administrative account
☐ Least privilege
☐ Production access approval
☐ Privileged-access review
☐ Cloud activity logging
☐ Change-management compliance
☐ Security incident reporting
☐ Secrets protection
☐ Periodic access review

Example: Developer

☐ Source-code protection
☐ Secure coding requirements
☐ Code-review requirements
☐ Secret protection
☐ Approved repositories
☐ Production-access restrictions
☐ Secure deployment requirements

Example: Finance Employee

☐ Financial information protection
☐ Segregation of duties
☐ Payment authorization requirements
☐ Fraud reporting
☐ Restricted system access


40. Document Control

FieldDetails
Document NameEmployment Security Clause Template
Document OwnerHR / Information Security
Version
Effective Date
Review Date
Approved By
Classification
Status

41. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security requirements
Employee Security ResponsibilitiesDefines employee responsibilities
Employee Screening PolicyDefines screening requirements
Background Verification ProcedureDefines verification process
Sensitive Role Identification ChecklistIdentifies sensitive roles
Role-Based Screening MatrixDetermines screening requirements
Security Awareness ProcedureDefines training
Access Management ProcedureControls access
Privileged Access ProcedureControls privileged access
Acceptable Use PolicyDefines acceptable system use
Remote Working PolicyDefines remote-working security
Incident Response ProcedureDefines incident reporting and handling
Employee Offboarding ProcedureControls termination
Asset Return ProcedureControls return of Company assets
Security Policy Acknowledgement RegisterRecords policy acknowledgement

42. ISO/IEC 27001 Connection

Employment security clauses support the organization’s personnel-security arrangements by establishing relevant security responsibilities and expectations as part of employment or engagement.

Relevant areas may include:

  • Personnel screening
  • Employment terms and conditions
  • Information-security awareness
  • Confidentiality
  • Access control
  • Privileged access
  • Remote working
  • Information protection
  • Incident reporting
  • Personnel changes
  • Termination or change of employment

The Employment Security Clause Template is not itself a universally prescribed ISO/IEC 27001 document. The organization should determine the appropriate contractual clauses based on its ISMS scope, risk assessment, applicable controls, legal and regulatory requirements, customer requirements, and business needs.


43. Audit Evidence Checklist

The organization should be able to demonstrate, where applicable:

☐ Approved employment security clauses
☐ Employment/appointment agreements
☐ Employee security responsibilities
☐ Confidentiality obligations
☐ NDA records
☐ Background verification records
☐ Sensitive-role assessments
☐ Security training records
☐ Policy acknowledgements
☐ Access approvals
☐ Privileged-access approvals
☐ Role-change records
☐ Incident reports
☐ Security exceptions
☐ Offboarding records
☐ Asset-return evidence
☐ Access-revocation evidence


44. Final Employment Security Audit Trail

For applicable personnel, the organization should be able to demonstrate:

Were security responsibilities defined?
Were confidentiality requirements established?
Was appropriate screening performed?
Were role-specific requirements identified?
Was security training provided?
Was access appropriately authorized?
Were privileged responsibilities appropriately controlled?
Were security incidents required to be reported?
Were role changes managed?
Were Company assets and information returned when required?
Was access revoked at termination?
Were continuing confidentiality obligations communicated?

Final Principle

Employment security clauses turn information-security expectations into clearly communicated employment responsibilities. The objective is not to make every employee sign an excessive security agreement, but to ensure that responsibilities appropriate to the person’s role, access, information exposure, and applicable requirements are clearly established, understood, and enforceable through the organization’s normal HR and legal processes.