Security Questionnaire Mapper
People and HR security ยท question family

Confidentiality terms and leavers: the clause the question tests

Whether staff are bound to confidentiality and what happens when they leave.

How the customer usually asks it

example

"Do employees and contractors sign confidentiality or non-disclosure agreements before they start?"

Read this question

Anchor clauses

2 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20226.6 Confidentiality or non-disclosure agreements
SIG (Shared Assessments)domain E Human Resources Security

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The confidentiality clause or agreement template, signed copies for the relevant staff, and the leaver checklist.

The clauses, with what an assessor asks for

ISO 27001 6.6 Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

Evidence an assessor expects: NDA policy; NDA templates; Signed NDA registry; NDA review process; Third party NDA records
Where answers usually fall short: NDAs not refreshed when data classification changes; Contractor agreements missing required signatures
Source: ISO/IEC 27001:2022
SIG domain E Human Resources Security

What it asks for, in one line (the standard's own text is not quoted here):

Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.

Evidence an assessor expects: Background check policy and records; Annual security awareness training completion logs; Sanctions policy; Termination checklists and access removal records
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)

Other families in people and hr security