On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why Terms and Conditions of Employment Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Controls
- Implementation Roadmap (Week-by-Week)
- Detailed Implementation Guidance
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Industry Context
- Roles and Responsibilities (RACI)
- Documentation and Evidence Requirements
- Continuous Improvement
- FAQ
- References and Further Reading
Quick Reference (60 Seconds)
| Attribute | Detail |
|---|---|
| Control ID | A.6.2 |
| Title | Terms and Conditions of Employment |
| Objective | Ensure employees understand their information security responsibilities and that these are enforced through contractual terms |
| Domain | People |
| ISO 27001:2022 Clause | Annex A.6.2 |
| What You Must Do | Include information security responsibilities in employment contracts, ensure employees acknowledge them, and enforce compliance through HR processes |
| Owner | HR / Legal / CISO |
| Maturity Level 1 | Generic security mention in contracts |
| Maturity Level 2 | Security responsibilities clause in all contracts; onboarding briefing |
| Maturity Level 3 | Role-specific security responsibilities; annual acknowledgment; violation tracking |
| Maturity Level 4 | Automated acknowledgment tracking; security KPIs in performance reviews; dynamic clause updates |
| Maturity Level 5 | AI-driven responsibility personalization; behavioral analytics; predictive compliance; integrated security culture metrics |
What the Standard Actually Requires
ISO 27001:2022 Control Text
Annex A 6.2 asks organizations to set out each person's security responsibilities in their employment terms.
Implementation Guidance (ISO 27002:2022)
- Information security responsibilities should be addressed in the terms and conditions of employment
- Employees should be made aware of their security responsibilities at the time of hire
- The organization should require employees to commit to these responsibilities in writing
- Sanctions for non-compliance should be defined and communicated
- Responsibilities should be reviewed and updated as roles change
- The organization should ensure that employees understand the consequences of security violations
- This applies to permanent employees, contractors, and temporary staff
"Shall" vs "Should" Analysis
- Shall: Communication of security responsibilities and terms is mandatory; formal agreement is required where appropriate
- Should: Specific methods of communication and agreement are flexible
Common Misinterpretations
| Misinterpretation | Reality |
|---|---|
| "A generic IT policy signature is enough" | Role-specific responsibilities must be communicated and acknowledged |
| "Only full-time employees need this" | Contractors, temps, interns, and vendors all need security terms |
| "Security responsibilities are obvious" | Employees need explicit, documented, and acknowledged responsibilities |
| "Once signed at hire, done forever" | Responsibilities must be reviewed and re-acknowledged annually and on role changes |
| "Sanctions are HR's problem, not security's" | Security must define sanctions for security violations; HR enforces |
Why Terms and Conditions of Employment Matters
The Business Risk Narrative
Employment contracts are the legal foundation of information security accountability. For Indian organizations, weak security clauses create significant exposure:
- 67% of Indian security breaches involve some form of employee negligence or violation of policy
- Organizations with explicit security responsibilities in contracts reduce insider incidents by 45%
- Average impact of an employment contract dispute in India: -15 lakh in legal fees and settlements
- Without documented security responsibilities, organizations struggle to enforce disciplinary action or pursue legal remedies
- DPDP Act 2023 requires "reasonable security safeguards" which includes personnel accountability
- In negligence lawsuits, courts look at whether the organization clearly communicated responsibilities
Regulatory Landscape in India
| Regulation | Employment Terms Requirement | Penalty for Non-Compliance |
|---|---|---|
| DPDP Act 2023 | Section 8, personnel security as reasonable safeguard | Up to |
| IT Act 2000 (Section 43A) | Reasonable security practices including personnel | Compensation claims |
| Companies Act 2013 | Director duties including care and diligence (Section 166) | Director liability, disqualification |
| RBI Cyber Security Framework | Employee security responsibilities in contracts | License restrictions |
| SEBI Cybersecurity Circular | Personnel security terms for trading system access | Trading restrictions |
| IRDAI Guidelines | Employee data protection responsibilities | License suspension |
| POSH Act 2013 | Employee obligations under POSH policy | Employer liability |
| Factories Act 1948 | Worker safety obligations | fine; imprisonment |
| Industrial Employment (SO) Act 1946 | Standing orders including discipline | Labour court disputes |
| Shops and Establishments Act | Employee conduct rules | License cancellation |
Industry-Specific Consequences
| Industry | Employment Terms Failure Scenario |
|---|---|
| BFSI | Employee without clear security responsibilities shares password; customer account drained; RBI action |
| Healthtech | Employee without PHI obligations posts patient data on social media; CDSCO action; malpractice |
| SaaS / B2B | Developer without IP obligations takes code to competitor; no contractual recourse; loss of product |
| E-commerce | Warehouse employee without data handling terms steals customer addresses; fraud; DPDP penalty |
| Government | Employee without confidentiality obligations leaks classified data; Official Secrets Act prosecution |
| Manufacturing | Employee without safety obligations causes industrial accident; criminal liability |
impact of Non-Compliance Statistics
- Organizations without explicit security employment terms: 3.2x more likely to experience insider incidents
- impact of enforcing a policy without contractual basis: -10 lakh in legal fees (often unsuccessful)
- Average settlement for wrongful termination without documented violations: -25 lakh
- Time to resolve employment disputes in Indian labour courts: 2-5 years
- Organizations with clear security terms and sanctions: 40% lower security incident rates
- Employee training effectiveness increases by 60% when backed by contractual obligations
Scope and Applicability
What the Control Covers
- Employment contracts: Permanent, temporary, fixed-term, probationary
- Contractor agreements: Independent contractors, consultants, freelancers
- Internship agreements: Students, trainees, apprentices
- Vendor personnel agreements: Staff augmentation, ODC workers, outsourced staff
- Director agreements: Board members, advisors, non-executive directors
- Remote work agreements: Work-from-home, hybrid work arrangements
- BYOD agreements: Bring Your Own Device policies and terms
- Side letters: Specific security terms for sensitive roles
- Non-disclosure agreements: Standalone or embedded in employment contracts
- Intellectual property assignment: IP ownership clauses
- Return of assets clauses: Equipment, data, access return upon exit
- Non-compete clauses: Post-employment restrictions (where legally enforceable)
- Sanctions clauses: Defined consequences for security violations
- Acknowledgment: Signed acceptance of security policies and responsibilities
Who It Applies To
| Role | Responsibility |
|---|---|
| HR | Contract drafting, onboarding communication, acknowledgment tracking, enforcement |
| Legal | Contract review, enforceability, labor law compliance, sanctions legality |
| CISO | Defining security responsibilities, sanctions, policy content, violation assessment |
| Hiring Managers | Communicating role-specific security responsibilities, performance review |
| Employees | Reading, understanding, and complying with security responsibilities |
| Line Managers | Enforcing security responsibilities within their teams, reporting violations |
| Compliance Manager | Ensuring contractual terms meet regulatory requirements |
| IT Security | Technical enforcement of access controls aligned with contractual terms |
What It Does NOT Cover
- General HR policies (leave, attendance, benefits), covered by HR policies
- Compensation and benefits, covered by compensation policies
- Performance management (general), covered by HR processes
- Physical safety (OSHA-equivalent), covered by safety policies
- Termination procedures, covered by A.6.5 and labor law
Size-Based Applicability
| Organization Size | Approach |
|---|---|
| Startups (< 50) | Security clause in all contracts; simple acknowledgment; basic sanctions |
| SMB (50-500) | Role-specific security addendums; annual re-acknowledgment; defined sanctions |
| Mid-market (500-5000) | Complete security terms; automated acknowledgment tracking; performance integration; contractor terms |
| Enterprise (5000+) | Dynamic security terms; AI-driven personalization; integrated with GRC; global contract variations |
Key Definitions and Terminology
| Term | Definition | Source |
|---|---|---|
| Terms and Conditions of Employment | The contractual agreement between employer and employee defining rights, obligations, and responsibilities | Contract Law |
| Security Responsibilities | Specific obligations of an employee to protect information and systems | ISO 27001 |
| Sanctions | Penalties or consequences for violating security responsibilities | ISO 27002 |
| Acknowledgment | Formal confirmation that the employee has read, understood, and agrees to comply | HR Practice |
| Non-Disclosure Agreement (NDA) | Contract prohibiting disclosure of confidential information | Contract Law |
| Non-Compete Clause | Contractual restriction preventing employment with competitors post-employment | Contract Law |
| Garden Leave | Period where employee remains employed but does not work, typically during notice | HR Practice |
| Acceptable Use Policy (AUP) | Policy defining permitted use of organization systems and data | ISO 27001 |
| Bring Your Own Device (BYOD) | Policy allowing personal devices for work with security requirements | Industry |
| Remote Work Agreement | Contract defining security requirements for remote work | HR Practice |
| IP Assignment | Contractual transfer of intellectual property rights to employer | Contract Law |
| Confidentiality Obligation | Legal duty to protect confidential information | Contract Law |
| Standing Orders | Rules of conduct for industrial establishments under Indian law | Industrial Employment Act |
| Service Rules | Conduct rules for government and public sector employees | Government |
| Disciplinary Action | Formal procedure for addressing violations of employment terms | Labor Law |
| Employment Bond | Contract requiring employee to stay for a minimum period or pay penalty | Contract Law (enforceability varies) |
Relationship to Other Controls
Figure · Matrix
Comparison: A.5.1 to A.5.35
Upstream Controls (Prerequisites)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.1 | Policies for Information Security | Security policy must exist before it can be referenced in contracts |
| A.5.2 | Information Security Roles | Role definitions inform security responsibilities in contracts |
| A.6.1 | Screening | Screened employees must be bound by security terms |
| A.5.35 | Intellectual Property Rights | IP assignment must be in employment contracts |
Downstream Controls (Enabled By)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.6.3 | Information Security Awareness | Contractual responsibilities must be reinforced through training |
| A.6.4 | Disciplinary Process | Contractual sanctions enable disciplinary action |
| A.6.5 | Responsibilities after Termination | Contractual return-of-assets and confidentiality clauses enable exit procedures |
| A.6.6 | Confidentiality Agreements | NDA is part of employment terms |
| A.6.7 | Remote Working | Remote work terms must be in contracts |
| A.6.8 | Information Security Event Reporting | Contractual reporting obligation enables incident reporting |
Parallel Controls (Work Alongside)
| Control ID | Relationship | Why It Matters |
|---|---|---|
| A.5.7 | Inventory of Information Assets | Asset access determines contract terms |
| A.5.8 | Acceptable Use of Assets | AUP is referenced in employment terms |
| A.5.12 | Information Transfer | Data handling terms in contracts |
| A.5.37 | Privacy and Protection of PII | Privacy obligations in employment terms |
| A.8.1 | User Endpoint Devices | BYOD terms in contracts |
| A.8.5 | Secure Authentication | Authentication obligations in contracts |
Implementation Roadmap (Week-by-Week)
Phase 1: Discovery & Assessment (Weeks 1-2)
Week 1: Current Contract Assessment
- Deliverable: Employment contract security terms audit report
- Owner: Legal + HR + CISO
- Activities:
- Review all current employment contract templates
- Identify security-related clauses (or absence thereof)
- Review contractor and vendor personnel agreements
- Assess current acknowledgment processes (signature, digital, HRIS)
- Interview hiring managers about security communication
- Review current sanctions for security violations (documented? enforced?)
- Assess compliance with labor law requirements for contract terms
Week 2: Gap Analysis and Role Mapping
- Deliverable: Security responsibility gap analysis by role
- Owner: CISO + HR + Legal
- Activities:
- Map all roles to information access levels (Public, Internal, Confidential, Restricted)
- Define security responsibilities for each access level
- Identify roles with special requirements (remote, BYOD, IP creation, PII access)
- Assess current employee understanding of security responsibilities (survey)
- Identify gaps between current contracts and ISO 27001 requirements
- Map legal requirements (DPDP, labor law, industry-specific)
- Create security responsibility matrix by role
Phase 2: Design & Planning (Weeks 3-4)
Week 3: Contract Template Development
- Deliverable: Updated employment contract templates with security terms
- Owner: Legal + HR + CISO
- Activities:
- Draft security responsibilities clause for main employment contract
- Create role-specific security addendums (4 tiers)
- Create standalone security acknowledgment form
- Create remote work security addendum
- Create BYOD security addendum
- Create IP assignment and confidentiality clauses
- Create sanctions clause (graduated sanctions)
- Create return of assets clause
- Review all clauses for labor law compliance and enforceability
Week 4: Policy and Procedure Development
- Deliverable: Security Terms Management Procedure + Acknowledgment Tracking Procedure
- Owner: HR + CISO + Legal
- Activities:
- Create procedure for communicating security responsibilities during onboarding
- Create procedure for annual re-acknowledgment
- Create procedure for role-change acknowledgment updates
- Create procedure for sanctions enforcement (violation → investigation → decision → action)
- Create procedure for contract updates when policies change
- Create employee communication templates (email, presentation, video)
- Create manager training on enforcing security responsibilities
Phase 3: Implementation (Weeks 5-8)
Week 5: New Hire Contract Rollout
- Deliverable: All new hires receive updated contracts with security terms
- Owner: HR + Legal
- Activities:
- Update HRIS with new contract templates
- Train recruiters on new security clauses and their importance
- Implement new contract for all new hires
- Create new hire security briefing presentation
- Ensure new hires sign security acknowledgment before system access
- Create new hire security checklist (contract → acknowledgment → training → access)
- Test workflow with 5 new hires
Week 6: Existing Employee Retrospective Acknowledgment
- Deliverable: All existing employees acknowledge updated security responsibilities
- Owner: HR + CISO + IT
- Activities:
- Create communication campaign for existing employees ("Your Security Responsibilities")
- Deploy updated security acknowledgment to all employees
- Track acknowledgment completion (target: 100%)
- Follow up with non-responders (email, manager, HR)
- For employees who refuse acknowledgment: escalate to Legal and CISO
- Create audit trail of all acknowledgments
- Link acknowledgment to system access (no acknowledgment = no access for renewals)
Week 7: Contractor and Vendor Agreement Updates
- Deliverable: All contractor and vendor personnel agreements include security terms
- Owner: Legal + Procurement + Vendor Management
- Activities:
- Update contractor agreement template with security terms
- Create vendor personnel security addendum
- Renegotiate existing contracts with security terms (where possible)
- Create vendor security acknowledgment process
- Train procurement on security contract requirements
- Implement security terms in all new vendor contracts
- Create vendor security terms checklist
Week 8: Sanctions and Enforcement Implementation
- Deliverable: Sanctions framework operational; first training delivered
- Owner: CISO + HR + Legal + Line Managers
- Activities:
- Create graduated sanctions matrix (verbal warning → written warning → suspension → termination → legal action)
- Define security violation categories and corresponding sanctions
- Train managers on identifying and reporting security violations
- Create violation investigation procedure
- Create sanctions decision committee (HR, Legal, CISO, manager)
- Document first sanctions training session
- Create violation tracking system (incident + sanction + outcome)
Phase 4: Testing & Validation (Weeks 9-10)
Week 9: Contract and Acknowledgment Testing
- Deliverable: Validation report with test results
- Owner: HR + Internal Audit + CISO
- Activities:
- Test contract workflow end-to-end (offer → signature → acknowledgment → access)
- Test acknowledgment tracking system (completion %, follow-up, access blocking)
- Test role-change update procedure (promotion → new acknowledgment)
- Test sanctions procedure with mock violation scenario
- Test contractor security acknowledgment process
- Test contract update procedure when policy changes
- Verify all contracts meet labor law requirements
Week 10: Compliance Validation
- Deliverable: Compliance validation report
- Owner: Legal + Compliance Manager + HR
- Activities:
- Validate contract terms against DPDP Act 2023
- Validate sanctions against labor law (fairness, proportionality, due process)
- Validate acknowledgment process for DPDP compliance (consent, records)
- Verify enforceability of key clauses (non-compete, IP assignment, confidentiality)
- Test employee understanding (survey: do employees know their security responsibilities?)
- Prepare compliance evidence package
Phase 5: Documentation & Certification Prep (Weeks 11-12)
Week 11: Documentation
- Deliverable: Complete security terms management documentation
- Owner: HR + Compliance Manager
- Activities:
- Document all security contract templates and procedures
- Create training materials for managers and employees
- Create FAQ on security responsibilities
- Create metrics dashboard
- Create evidence repository for audits
- Document vendor contract management procedures
Week 12: Certification Readiness
- Deliverable: Audit-ready evidence package
- Owner: CISO + Compliance Manager
- Activities:
- Conduct internal audit of security terms management
- Prepare evidence for external ISO 27001 auditor
- Remediate any gaps found
- Conduct management review
- Present program to certification body
Detailed Implementation Guidance
Figure · Tiers
Maturity levels for terms and conditions of employment

Step-by-Step Implementation
Step 1: Define Security Responsibility Tiers
| Tier | Role Examples | Core Responsibilities | Special Responsibilities |
|---|---|---|---|
| Tier 1: Critical | CISO, CIO, DB Admin, Security Engineer, DevOps Lead, CFO | All Tier 2 + 3 + code of conduct, incident command, vendor oversight, security architecture review | No side businesses in same industry; no consulting for competitors; mandatory reporting of security incidents within 1 hour; no personal devices for Restricted data; annual security certification |
| Tier 2: High | Developer, QA, Network Admin, IT Support, HR, Finance | All Tier 3 + secure coding, system administration, access management, backup verification, secure configuration, vulnerability reporting | No unapproved software installation; mandatory code review participation; no production data on personal devices; mandatory security training quarterly; report suspicious activity within 4 hours |
| Tier 3: Medium | Marketing, Sales, Operations, Customer Support, General Admin | Password security, phishing awareness, data handling per classification, incident reporting, physical security, clean desk policy | No sharing of credentials; no unauthorized data sharing; mandatory security training annually; report lost devices immediately; no sensitive data on personal email |
| Tier 4: Low | Reception, Facilities, General Staff | Basic password security, physical security, incident reporting, no tailgating | Report security concerns; follow visitor procedures; no unauthorized area access; annual security awareness |
| Contractors | All contract roles | Same as equivalent employee tier + no subcontracting without approval; return all assets upon termination; no data retention after contract | Enhanced monitoring; restricted access; mandatory security briefing; no access to production without escort |
Step 2: Draft Core Security Responsibilities Clause
Template
Information Security Responsibilities
As an employee of [Organization], you are responsible for protecting the confidentiality, integrity, and availability of information and systems. Your specific responsibilities include:
-
Protecting Information: You must handle all information according to its classification (Public, Internal, Confidential, Restricted). You must not disclose, share, or expose information to unauthorized parties.
-
Access Control: You must protect your credentials (passwords, tokens, biometrics). You must not share credentials with anyone. You must report suspected credential compromise immediately.
-
Acceptable Use: You must use organization systems and data only for authorized business purposes. You must not install unauthorized software, access unauthorized systems, or misuse organization resources.
-
Incident Reporting: You must report all security incidents, suspicious activity, and policy violations promptly to security@organization.com or through the incident reporting portal.
-
Physical Security: You must follow physical security procedures including clean desk policy, secure storage of devices, visitor escort, and no tailgating.
-
Remote Work Security: If working remotely, you must use secure connections (VPN), secure your home workspace, protect devices from family members, and follow remote work security guidelines.
-
Data Protection: You must comply with the Digital Personal Data Protection Act 2023 and all applicable data protection laws. You must protect personal data and process it only for authorized purposes.
-
Third-Party Interactions: You must not share confidential information with third parties without authorization. You must ensure third parties sign NDAs before receiving information.
-
Asset Return: Upon termination of employment, you must return all organization assets (devices, data, access cards, documents) and confirm deletion of organization data from personal devices.
-
Compliance: You must comply with all information security policies, procedures, and guidelines. You must complete all required security training.
Sanctions: Violation of these responsibilities may result in disciplinary action up to and including termination and legal action. Specific sanctions are defined in the Employee Handbook and Security Policy.
Step 3: Create Role-Specific Security Addendums
For Tier 1 and Tier 2 roles, create addendums with specific technical responsibilities:
Template
Security Addendum for System Administrators
In addition to general security responsibilities, you must:
-
Privileged Access: Use privileged accounts only for authorized administrative tasks. Never use privileged accounts for routine work. Use separate admin and user accounts.
-
Change Management: All system changes must follow the change management process. Emergency changes require post-hoc approval.
-
Audit Log Integrity: You must not modify, delete, or disable audit logs. Audit log access is logged and monitored.
-
Backup Verification: You must verify backups regularly and test restoration procedures. Backup failures must be reported immediately.
-
Vulnerability Management: You must apply security patches within defined SLAs. Vulnerabilities must be reported and remediated promptly.
-
No Production Data in Non-Production: You must not use production data in development, testing, or staging environments without authorization and masking.
-
Incident Command: You must be available for incident response within 1 hour during on-call periods. You must participate in incident response drills.
-
Security Architecture Review: All infrastructure changes must be reviewed by security architecture before implementation.
-
Side Business Disclosure: You must disclose any side businesses, consulting work, or employment with other organizations. Unauthorized work in the same industry is prohibited.
-
Annual Security Certification: You must maintain relevant security certifications (certified, etc.) and complete 40 hours of security training annually.
Step 4: Implement Acknowledgment Process
Create a multi-layered acknowledgment process:
- Contract Signature: Employee signs employment contract with security clause
- Security Acknowledgment Form: Separate form listing all security responsibilities; employee initials each item and signs
- Policy Acknowledgment: Employee acknowledges all information security policies (AUP, Data Protection, Remote Work, BYOD, etc.)
- Training Completion: Employee completes security training and passes assessment
- Annual Re-Acknowledgment: Employee re-signs acknowledgment annually
- Role-Change Acknowledgment: Employee signs updated acknowledgment when role changes
- Policy Update Acknowledgment: Employee acknowledges updated policies when changes occur
Step 5: Create Graduated Sanctions Matrix
| Violation Category | Examples | First Offense | Second Offense | Third Offense |
|---|---|---|---|---|
| Minor | Clean desk violation, unreported lost badge, minor password policy violation | Verbal warning + retraining | Written warning + retraining | Written warning + restricted access |
| Moderate | Sharing credentials (without incident), unauthorized software installation, unencrypted USB use, phishing test failure | Written warning + retraining + restricted access | Written warning + suspension (1-3 days) + mandatory training | Final warning + suspension (3-5 days) |
| Major | Data leakage (no breach), unauthorized access attempt, credential sharing leading to incident, policy violation causing incident | Written warning + suspension (3-5 days) + mandatory training + access review | Final warning + suspension (5-10 days) + role change | Termination |
| Critical | Intentional data breach, theft of data, sabotage, unauthorized system modification, fraud, espionage | Immediate suspension + investigation | Termination + legal action | Termination + legal action + regulatory reporting |
Note: For critical violations (theft, sabotage, espionage), first offense may result in immediate termination depending on severity and evidence.
Step 6: Implement Sanctions Enforcement Procedure
- Detection: Violation detected through monitoring, incident report, audit, or tip
- Initial Assessment: Security team assesses violation category and severity
- Investigation: Formal investigation (interviews, evidence collection, log review)
- Decision Committee: HR, Legal, CISO, and manager review investigation findings
- Decision: Sanction determined based on matrix, violation history, and circumstances
- Communication: Employee notified of violation and sanction in writing (with appeal rights)
- Appeal: Employee may appeal to higher authority (VP HR, CEO for critical cases)
- Execution: Sanction executed (warning recorded, suspension, termination, legal action)
- Documentation: All steps documented; records maintained per retention policy
- Follow-up: For non-termination cases, monitor for improvement; retraining effectiveness
Step 7: Create Remote Work Security Addendum
Template
Remote Work Security Addendum
When working remotely, you must comply with the following security requirements:
-
Workspace Security: Your workspace must be private and secure. Family members and visitors must not see or access organization data or systems.
-
Network Security: You must use the organization VPN for all work-related access. You must not use public Wi-Fi for work without VPN.
-
Device Security: Organization devices must be secured when not in use (locked screen, stored securely). Personal devices used for work must meet BYOD requirements.
-
Data Protection: Organization data must not be stored on personal devices unless authorized. Printed documents must be shredded when no longer needed.
-
Communication Security: Work discussions involving sensitive information must use approved communication tools (not personal WhatsApp, email, etc.).
-
Physical Security: Organization devices must not be left unattended in public or accessible to others. Devices must be reported lost/stolen immediately.
-
Compliance: You must comply with all applicable security policies regardless of work location. Remote work does not reduce security responsibilities.
Step 8: Create BYOD Security Addendum
Template
BYOD Security Addendum
If you use personal devices for work, you must comply with:
- Device Registration: Personal device must be registered with IT and enrolled in MDM (Mobile Device Management).
- Encryption: Device must be encrypted (full disk encryption). PIN/biometric required.
- Security Software: Device must have approved antivirus/anti-malware.
- Application Control: Only approved applications may be used for work. Personal apps must not access work data.
- Data Separation: Work data must be in a containerized environment (separate from personal data).
- Remote Wipe: Organization may remotely wipe work data if device is lost or employment ends. Personal data will not be affected.
- No Jailbreak/Root: Device must not be jailbroken or rooted.
- OS Updates: Device must be updated to latest OS version within 30 days of release.
- No Transfer: Work data must not be transferred to unauthorized personal devices or cloud storage.
- Return/Removal: Upon termination, work data must be removed from device or device may be wiped.
Step 9: Implement Annual Re-Acknowledgment
- Send annual security responsibility reminder to all employees
- Require re-signature of acknowledgment form
- Update responsibilities based on role changes
- Include updated policies and procedures
- Track completion rate (target: 100%)
- For non-completion: escalate to manager, then HR, then access review
Step 10: Link Acknowledgment to System Access
- Configure IAM to require valid acknowledgment for access renewal
- For employees with expired acknowledgment: flag for review, restrict access after 30 days
- For new hires: no system access until acknowledgment is signed
- For role changes: access updated only after new acknowledgment
- Create automated workflow: expiration notice → manager alert → access restriction
Step 11: Create Employee Understanding Verification
- Annual security awareness quiz (mandatory, scored)
- Role-specific security scenario tests
- Phishing simulation (results not punitive but inform training)
- Manager one-on-one discussions about security responsibilities
- Anonymous survey: "Do you understand your security responsibilities?"
Step 12: Implement Contract Update Process
- When security policy changes, update contract templates
- For significant changes: require existing employees to re-acknowledge
- Maintain version control for all contract templates
- Legal review of all changes for enforceability
- Communicate changes to employees with explanation
Step 13: Create Performance Review Integration
- Include security responsibility compliance in annual performance reviews
- For Tier 1 and 2: security compliance is a formal performance metric
- Security incidents and violations affect performance ratings
- Security training completion affects performance ratings
- Create security champion recognition program
Step 14: Document and Maintain Records
- Maintain all signed contracts and acknowledgments
- Maintain sanctions records (investigation, decision, outcome)
- Maintain training completion records
- Maintain policy version history
- Secure disposal after retention period (7 years or employment + 7 years)
- DPDP compliance for all personnel records
Step 15: Implement Continuous Improvement
- Annual review of security terms and sanctions
- Quarterly metrics review
- Annual employee understanding survey
- Benchmark against industry practices
- Update for regulatory changes (DPDP, labor law, industry-specific)
- Learn from incidents and violations to improve terms
Tools, Technologies, and Solutions
Complete Tool Comparison
| Tool | Category | Best For | licensing Range | Key Features | Integration |
|---|---|---|---|---|---|
| DocuSign | E-Signature | Contract signing, acknowledgment | + per year | Electronic signatures, workflow, templates, audit trail | HRIS, ATS, CRM |
| Adobe Sign | E-Signature | Enterprise contract signing | + per year | E-signatures, workflow, templates, compliance | Adobe, Microsoft, HRIS |
| HelloSign (Dropbox) | E-Signature | SMB contract signing | + per year | Simple e-signatures, templates, API | Google, Dropbox, HRIS |
| PandaDoc | E-Signature + Contract | Contract management + signing | + per year | Templates, CRM integration, analytics, approval workflow | Salesforce, HubSpot, Pipedrive |
| Workday | HRIS | Enterprise HR management | + per year | Contract management, acknowledgment tracking, performance, compliance | Full enterprise suite |
| BambooHR | HRIS | SMB HR management | + per year | Contract management, acknowledgment, onboarding, reporting | 100+ integrations |
| SAP SuccessFactors | HRIS | Enterprise HR | + per year | Contract, compliance, performance, learning, global | SAP ecosystem |
| Oracle HCM | HRIS | Enterprise HR | + per year | Contract, compliance, talent management, global | Oracle ecosystem |
| Zoho People | HRIS | Indian SMB | + per year | Contract, onboarding, attendance, leave, performance | Zoho ecosystem |
| GreytHR | HRIS | Indian SMB | + per year | Contract, payroll, attendance, compliance (India-specific) | Indian compliance |
| Culture Amp | Engagement | Employee surveys, engagement | + per year | Surveys, analytics, recognition, performance | HRIS, Slack |
| 15Five | Performance | Continuous performance management | + per year | 1-on-1s, OKRs, recognition, feedback | HRIS, Slack |
| Lattice | Performance | Performance + engagement | + per year | Goals, reviews, 1-on-1s, engagement, analytics | HRIS, Slack |
| KnowBe4 | Training | Security awareness training | + per year | Training, phishing simulation, reporting, compliance | HRIS, Active Directory |
| Proofpoint | Training | Security awareness | + per year | Training, phishing simulation, threat intelligence | Email, HRIS |
| SANS Security Awareness | Training | Advanced security training | + per year | Role-based training, certifications, metrics | HRIS, LMS |
| Okta | IAM | Identity and access management | + per year | SSO, MFA, lifecycle management, access governance | 7,000+ integrations |
| Azure AD | IAM | Microsoft ecosystem | + per year | SSO, MFA, conditional access, lifecycle | Microsoft 365 |
| Google Workspace | Productivity | Google ecosystem contracts | + per year | Docs, e-sign (via integration), forms, compliance | Google ecosystem |
| Microsoft 365 | Productivity | Microsoft ecosystem | + per year | Word, e-sign (via Adobe/DocuSign), Forms, compliance | Microsoft ecosystem |
| ServiceNow | GRC | Enterprise GRC and compliance | + per year | Policy management, acknowledgment, compliance, risk | Enterprise platforms |
| RSA Archer | GRC | Enterprise GRC | + per year | Policy, compliance, risk, vendor, incident | Enterprise platforms |
| MetricStream | GRC | Enterprise GRC | + per year | Compliance, risk, audit, policy | Enterprise platforms |
Recommendations by Organization Size
| Size | HRIS | E-Signature | Training | Performance Integration | GRC |
|---|---|---|---|---|---|
| Startup (<50) | BambooHR or Zoho People | HelloSign or PandaDoc | KnowBe4 | Manual | Spreadsheet |
| SMB (50-500) | BambooHR or GreytHR | DocuSign or Adobe Sign | KnowBe4 + SANS | 15Five or Lattice | Basic |
| Mid-market (500-5000) | Workday or SAP SuccessFactors | DocuSign + Adobe Sign | Proofpoint + SANS | Lattice or Culture Amp | ServiceNow or MetricStream |
| Enterprise (5000+) | Workday or Oracle HCM | DocuSign + Adobe Sign + custom | SANS + custom | Workday or SAP + custom | ServiceNow or RSA Archer |
Policy and Procedure Templates
Employment Security Terms Policy (Key Sections)
Template
Employment Security Terms Policy
1. Purpose
To ensure all personnel understand and acknowledge their information security responsibilities as a condition of employment.
2. Scope
This policy applies to all employees, contractors, temporary staff, interns, and vendor personnel with access to [Organization] information or systems.
3. Policy Statements
3.1 Contractual Security Obligations
All personnel must sign an employment or service agreement that includes:
- General information security responsibilities
- Role-specific security responsibilities (based on tier)
- Confidentiality and non-disclosure obligations
- Intellectual property assignment (where applicable)
- Acceptable use obligations
- Data protection obligations (DPDP compliance)
- Remote work and BYOD obligations (if applicable)
- Incident reporting obligations
- Return of assets obligations
- Sanctions for non-compliance
3.2 Acknowledgment Requirements
All personnel must acknowledge security responsibilities through:
- Employment contract signature
- Security acknowledgment form (initialed and signed)
- Policy acknowledgment for all security policies
- Security training completion and assessment
- Annual re-acknowledgment
- Role-change acknowledgment
- Policy update acknowledgment
3.3 Role-Based Responsibilities
Security responsibilities are tiered based on information access:
- Tier 1 (Critical): Access to Restricted information. Highest security obligations.
- Tier 2 (High): Access to Confidential information. Enhanced security obligations.
- Tier 3 (Medium): Access to Internal information. Standard security obligations.
- Tier 4 (Low): Access to Public information. Basic security obligations.
3.4 Sanctions for Non-Compliance
Sanctions are graduated based on violation severity:
- Minor violations: Verbal warning, retraining, manager discussion
- Moderate violations: Written warning, restricted access, mandatory training, suspension
- Major violations: Final written warning, suspension, role change, termination consideration
- Critical violations: Immediate termination, legal action, regulatory reporting
All sanctions are documented and reviewed by HR and Legal for fairness and compliance with labor law.
3.5 Communication and Training
- Security responsibilities are communicated during onboarding (Day 1)
- Role-specific responsibilities are communicated by hiring manager (Week 1)
- Annual security training reinforces responsibilities
- Policy updates are communicated within 30 days of change
- Managers are responsible for reinforcing security responsibilities in team meetings
3.6 Remote Work and BYOD
- Remote work security addendum is required for all remote workers
- BYOD security addendum is required for all personal devices used for work
- These addendums are signed before remote work or BYOD access is granted
3.7 Contractor and Vendor Terms
- Contractors and vendor personnel must sign security terms equivalent to employee terms
- Vendor contracts must include security responsibility clauses
- Vendor personnel access is contingent on security acknowledgment
3.8 Record Keeping
- All contracts, acknowledgments, and sanctions are maintained securely
- Access is limited to HR, Legal, and CISO (need-to-know)
- Retention: 7 years or employment duration + 7 years (whichever is longer)
- DPDP compliance is maintained for all personnel records
3.9 Review and Update
- This policy is reviewed annually by HR, Legal, and CISO
- Contract templates are updated when security policies change
- Employees are notified of changes and may be required to re-acknowledge
3.10 Enforcement
Failure to acknowledge or comply with security responsibilities may result in restricted access, disciplinary action, or termination.
Sanctions Enforcement Procedure
Template
Procedure: Security Violation Sanctions
1. Objective
To define the fair and consistent process for enforcing sanctions for information security violations.
2. Violation Categories
2.1 Minor Violations
- Clean desk violation (sensitive document left unattended)
- Unreported lost access badge (not used by unauthorized person)
- Minor password policy violation (e.g., slightly weak password)
- Failure to lock screen when away from desk
- Unreported minor phishing attempt (not clicked, but not reported)
2.2 Moderate Violations
- Sharing credentials with colleague (without incident)
- Unauthorized software installation (non-malicious, not approved)
- Using unencrypted USB for work data
- Failing phishing simulation (clicked link but no data entered)
- Unencrypted email with Internal data sent to wrong internal recipient
- Unreported security incident (discovered later, not reported by employee)
2.3 Major Violations
- Data leakage (sensitive data sent to wrong external party, no malicious intent)
- Unauthorized access attempt (trying to access system without authorization)
- Credential sharing leading to unauthorized access
- Policy violation causing security incident (e.g., bypassing security control)
- Intentional bypass of security control for convenience
- Repeated moderate violations (3+ within 12 months)
2.4 Critical Violations
- Intentional data theft or exfiltration
- Sabotage of systems or data
- Unauthorized system modification for malicious purposes
- Fraud using organization systems or data
- Espionage or unauthorized disclosure to competitors/foreign entities
- Intentional installation of malware or backdoors
- Physical security breach (tailgating into restricted area, unauthorized access)
3. Sanctions Procedure
Step 1: Detection and Reporting
- Violation detected by monitoring, incident report, audit, or tip
- Security team logs violation in incident tracking system
- Initial categorization (Minor, Moderate, Major, Critical)
Step 2: Investigation
- Security team conducts investigation
- Evidence collection: logs, interviews, device analysis, witness statements
- Investigation report prepared with findings and categorization
- Timeline: Minor = 3 days, Moderate = 5 days, Major = 10 days, Critical = 15 days
Step 3: Sanctions Committee Review
- Committee: HR representative, Legal representative, CISO or delegate, employee's manager
- Review investigation report
- Assess violation history (previous violations)
- Consider mitigating circumstances (training gaps, system issues, coercion)
- Determine sanction based on matrix and discretion
- Document decision and rationale
Step 4: Communication
- Employee notified in writing of:
- Violation description
- Investigation findings
- Sanction decision
- Effective date
- Appeal rights and process
- For critical violations: immediate suspension pending final decision
- For termination: termination letter with grounds and legal compliance
Step 5: Appeal
- Employee may appeal within 7 days of notification
- Appeal reviewed by higher authority (VP HR for moderate/major, CEO for critical)
- Appeal decision within 14 days
- Appeal decision is final
Step 6: Execution
- Sanction executed (warning recorded, access restricted, suspension, termination)
- For non-termination: improvement plan created and monitored
- For termination: exit procedures followed (A.6.5)
- All actions documented
Step 7: Learning and Improvement
- Aggregate violation data analyzed quarterly
- Training gaps identified and addressed
- Policy or control gaps identified and remediated
- Trend analysis shared with management
- Lessons learned incorporated into security program
4. Special Considerations
4.1 Whistleblower Protection
- Employees who report violations in good faith are protected from retaliation
- Anonymous reporting is available
- False reports made in bad faith may result in sanctions for the reporter
4.2 Manager Accountability
- Managers who fail to report or address violations in their team may face sanctions
- Managers who encourage or tolerate violations face enhanced sanctions
4.3 Legal Compliance
- All sanctions must comply with Indian labor law (Industrial Employment Act, Shops Act, ID Act)
- Termination must follow due process (show cause, hearing, order)
- Documentation must support the decision in case of legal challenge
Risk Assessment and Treatment
Key Risks Addressed by This Control
| Risk ID | Risk Description | Likelihood | Impact | Risk Level | Treatment |
|---|---|---|---|---|---|
| R-001 | Employee violates security policy without consequences | Medium | High | Medium | Mitigate, Clear sanctions, enforcement, graduated response |
| R-002 | Employee unaware of security responsibilities | Medium | High | Medium | Mitigate, Explicit terms, acknowledgment, training, communication |
| R-003 | Contractor without security obligations | Medium | High | Medium | Mitigate, Contractor security terms, vendor clauses, attestation |
| R-004 | Cannot enforce sanctions due to weak contracts | Medium | High | Medium | Mitigate, Legal review of sanctions, labor law compliance, documentation |
| R-005 | Employee takes IP to competitor | Medium | Critical | High | Mitigate, IP assignment clause, NDA, non-compete (where legal), exit controls |
| R-006 | Employee shares confidential data after termination | Medium | High | Medium | Mitigate, NDA, return of assets, exit briefing, legal remedies |
| R-007 | Sanctions applied unfairly or discriminatorily | Low | High | Medium | Mitigate, Structured procedure, committee review, appeal process, training |
| R-008 | Remote worker without security obligations | Medium | Medium | Low | Mitigate, Remote work addendum, BYOD policy, access controls |
| R-009 | Acknowledgment records not maintained | Low | Medium | Low | Mitigate, Secure storage, retention policy, DPDP compliance |
| R-010 | Policy changes not communicated to employees | Medium | Medium | Low | Mitigate, Change communication procedure, re-acknowledgment requirement |
Audit and Compliance Checklist
Audit Questions (25 Questions)
| # | Audit Question | Expected Evidence | Red Flags |
|---|---|---|---|
| 1 | Is there a policy for employment security terms? | Approved policy | No policy |
| 2 | Do employment contracts include security responsibilities? | Contract templates | No security clause in contracts |
| 3 | Are security responsibilities role-specific? | Role-responsibility matrix | Generic one-size-fits-all responsibilities |
| 4 | Do employees sign security acknowledgment? | Signed acknowledgment forms | No acknowledgment, no signature |
| 5 | Is acknowledgment tracked for all employees? | Tracking system, completion report | No tracking, incomplete acknowledgments |
| 6 | Is there a sanctions clause in contracts? | Contract templates | No sanctions defined |
| 7 | Are sanctions graduated and fair? | Sanctions matrix | Arbitrary sanctions, no procedure |
| 8 | Are sanctions enforced consistently? | Sanction records | Sanctions not enforced, or inconsistently |
| 9 | Is there a procedure for sanctions? | Sanctions procedure | No procedure, ad-hoc decisions |
| 10 | Are contractor agreements include security terms? | Contractor templates | No security terms for contractors |
| 11 | Are vendor personnel agreements include security terms? | Vendor contracts | No vendor personnel security requirements |
| 12 | Is there a remote work security addendum? | Remote work addendum | No remote work security terms |
| 13 | Is there a BYOD security addendum? | BYOD policy/addendum | No BYOD security terms |
| 14 | Is there an IP assignment clause? | Contract templates | No IP assignment clause |
| 15 | Is there an NDA in employment contracts? | Contract templates | No NDA |
| 16 | Is there a return of assets clause? | Contract templates | No return of assets clause |
| 17 | Is annual re-acknowledgment required? | Annual acknowledgment records | No re-acknowledgment, one-time only |
| 18 | Is acknowledgment linked to system access? | IAM configuration | Access granted without acknowledgment |
| 19 | Are security responsibilities in performance reviews? | Performance review forms | Security not in performance evaluation |
| 20 | Are managers trained on enforcing security responsibilities? | Training records | No manager training on security enforcement |
| 21 | Is there an appeal process for sanctions? | Appeal procedure | No appeal process |
| 22 | Are sanctions reviewed for legal compliance? | Legal review records | No legal review of sanctions |
| 23 | Are employees trained on their security responsibilities? | Training records | No security training |
| 24 | Are records of contracts and acknowledgments maintained? | Record repository | No records, lost contracts |
| 25 | Is the employment security terms program reviewed? | Management review minutes | No review, no improvement |
Metrics and KPIs
Figure · Measures
The measures that show A.6.2 is working
- Contract Security Clause Coverage100%Monthly
- Acknowledgment Completion Rate100%Monthly
- Annual Re-Acknowledgment Rate100%Annual
- Contractor Security Terms Coverage100%Quarterly
- Vendor Security Terms Coverage100%Quarterly
Key Metrics Dashboard
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Contract Security Clause Coverage | (Contracts with security clause / Total contracts) × 100 | 100% | Monthly |
| Acknowledgment Completion Rate | (Employees with valid acknowledgment / Total employees) × 100 | 100% | Monthly |
| Annual Re-Acknowledgment Rate | (Employees re-acknowledged on time / Required) × 100 | 100% | Annual |
| Contractor Security Terms Coverage | (Contractors with security terms / Total contractors) × 100 | 100% | Quarterly |
| Vendor Security Terms Coverage | (Vendors with security terms / Total vendors) × 100 | 100% | Quarterly |
| Security Violation Count | Number of security violations | Trending down | Monthly |
| Sanction Enforcement Rate | (Sanctions executed / Violations requiring sanctions) × 100 | 100% | Monthly |
| Sanction Appeal Rate | (Appeals filed / Total sanctions) × 100 | <10% | Monthly |
| Security Training Completion | (Employees completing training / Total employees) × 100 | 100% | Annual |
| Employee Understanding Score | Average score on security responsibility quiz | >80% | Annual |
| Policy Update Communication Rate | (Policy updates communicated within 30 days / Total updates) × 100 | 100% | Quarterly |
| Remote Work Addendum Coverage | (Remote workers with addendum / Total remote workers) × 100 | 100% | Quarterly |
| BYOD Addendum Coverage | (BYOD users with addendum / Total BYOD users) × 100 | 100% | Quarterly |
| Security Responsibility in Performance Reviews | (Reviews with security metric / Total reviews) × 100 | 100% for Tier 1-2 | Annual |
| Contract Update Compliance | (Contract templates updated after policy change / Total policy changes) × 100 | 100% | Quarterly |
| Sanction Records Completeness | (Sanctions with full documentation / Total sanctions) × 100 | 100% | Monthly |
| Labor Law Compliance Score | Audit score for labor law compliance | >95% | Annual |
| Acknowledgment Linked to Access | (Access renewals requiring acknowledgment / Total renewals) × 100 | 100% | Quarterly |
Common Pitfalls and How to Avoid Them
| # | Pitfall | Why It Happens | How to Avoid |
|---|---|---|---|
| 1 | Generic security clause | Using template without customization | Create role-specific responsibilities and addendums |
| 2 | No acknowledgment tracking | Relying on paper signatures | Use e-signature tools with tracking; integrate with HRIS |
| 3 | Sanctions not enforced | Fear of labor disputes, manager reluctance | Define clear procedure, train managers, legal review, document everything |
| 4 | No contractor security terms | Assuming contractors are covered by vendor | Include security terms in all contractor agreements; require vendor attestation |
| 5 | No annual re-acknowledgment | One-time mindset | Automated annual reminders; link to access renewal; manager accountability |
| 6 | Sanctions not legally compliant | HR and Legal not involved | Legal review of sanctions; due process; graduated response; documentation |
| 7 | No remote work/BYOD terms | Assuming office terms cover remote | Create specific remote work and BYOD addendums; require signature before access |
| 8 | Acknowledgment not linked to access | Siloed HR and IT processes | Integrate HRIS with IAM; block access for expired acknowledgments |
| 9 | No appeal process | Efficiency, assumption of fairness | Create appeal process; review committee; documented rationale |
| 10 | Security responsibilities not in performance reviews | Security seen as separate from performance | Integrate security compliance into performance evaluation for relevant roles |
| 11 | Policy changes not communicated | Lack of change management process | Create policy change communication procedure; require re-acknowledgment |
| 12 | No IP assignment for developers | Assumption that employment implies IP ownership | Explicit IP assignment clause; invention disclosure process; patent policy |
| 13 | No return of assets clause | Focus on hiring, not exit | Include return of assets in all contracts; exit checklist; asset verification |
| 14 | Unenforceable non-compete | Copying foreign templates | Review non-compete under Indian law (Section 27 of Indian Contract Act); focus on confidentiality and NDA |
| 15 | No contractor re-acknowledgment | Assuming contractor terms are perpetual | Set contractor re-acknowledgment schedule; renewal-based |
| 16 | Ignoring union/labor requirements | Not consulting labor law | Consult Legal and labor experts; ensure standing orders compliance; follow ID Act |
| 17 | No employee understanding verification | Assuming signature = understanding | Conduct quizzes, surveys, scenario tests; make training interactive |
| 18 | Sanctions inconsistent across departments | Departmental autonomy | Central sanctions committee; standardized matrix; regular calibration |
| 19 | No documentation of sanctions | Informal approach | Document every step; maintain records; create audit trail |
| 20 | No learning from violations | Punitive approach only | Analyze violations for root causes; improve policies and controls; share lessons |
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian SaaS Company, CloudTech Solutions
Company Profile:
- Size: 280 employees
- Industry: B2B SaaS, Cloud Infrastructure Management
- Location: Pune, India
- Customers: 450 enterprise clients globally
- Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR
Challenge: CloudTech had grown rapidly from 50 to 280 employees in 2 years but employment terms were outdated:
- Employment contracts had a generic "comply with company policies" clause with no security specifics
- No security acknowledgment form; employees signed contract but never specifically acknowledged security responsibilities
- A senior developer left and joined a competitor, taking proprietary orchestration code (no IP assignment clause enforced)
- No sanctions for security violations; an employee who shared credentials with a colleague received no formal action
- Remote work exploded during COVID but no remote work security addendum existed
- 45 contractors had no security terms in their contracts
- No annual re-acknowledgment; employees who joined 2 years ago had never revisited security terms
- A developer used personal laptop for work without BYOD agreement; laptop was infected with malware that spread to company network
- Performance reviews had no security component; security compliance was not rewarded or penalized
Solution:
-
Month 1: Contract and Policy Redesign
- Engaged Singahi to redesign employment security terms
- Created 4-tier security responsibility framework (Critical, High, Medium, Low)
- Updated employment contract template with detailed security clause
- Created role-specific security addendums (Developer, Admin, Support, Sales, etc.)
- Created security acknowledgment form with 15 core responsibilities (employee initials each)
- Created remote work security addendum
- Created BYOD security addendum
- Legal review for Indian labor law compliance and enforceability
-
Month 2: New Hire Implementation
- Implemented new contract for all new hires
- Integrated security acknowledgment into onboarding workflow (Day 1 mandatory)
- No system access granted until acknowledgment signed (IAM integration)
- Created onboarding security briefing (30 minutes, mandatory, scored quiz)
- Trained recruiters on communicating security terms during hiring
-
Month 3: Existing Employee Retrospective Acknowledgment
- Deployed annual security acknowledgment to all 280 employees
- Used DocuSign for electronic signatures with tracking
- Achieved 98% completion in 30 days
- For 6 employees who didn't complete: manager follow-up, then HR, then restricted access
- For 2 employees who refused: Legal review, disciplinary process, eventual termination
-
Month 4: Contractor and Vendor Updates
- Updated contractor agreement template with security terms
- Required 45 existing contractors to sign updated terms
- Created vendor personnel security addendum for 12 vendors with system access
- Added security terms to all new vendor contracts
- Trained procurement on security contract requirements
-
Month 5: Sanctions and Performance Integration
- Created graduated sanctions matrix (Minor → Moderate → Major → Critical)
- Established Sanctions Committee (HR, Legal, CISO, manager)
- Trained all managers on identifying and reporting violations
- Integrated security compliance into performance reviews (10% weight for Tier 1-2)
- Created security champion recognition program (quarterly awards)
- First sanctions applied: 3 verbal warnings, 2 written warnings, 1 suspension
-
Month 6: Remote Work and BYOD
- Required remote work addendum for all 180 remote workers
- Required BYOD addendum for 85 employees using personal devices
- Implemented MDM (Microsoft Intune) for BYOD enrollment
- Created remote work security checklist and self-assessment
- Conducted remote work security training (1 hour, mandatory)
Results:
- IP protection: IP assignment clause enforced; 2 patent applications filed by employees with proper assignment
- Security violations: 45% reduction in security violations in 6 months
- Sanctions: Fair and consistent sanctions applied; zero legal challenges
- Employee understanding: 94% average score on security responsibility quiz (up from 62%)
- Contractor compliance: 100% of contractors with security terms; no contractor incidents
- Remote work: Zero remote work-related security incidents in 6 months
- BYOD: 100% BYOD enrollment in MDM; malware incident prevented through MDM
- Performance integration: Security compliance became part of culture; 3 employees promoted partly for security excellence
- overhead: program investment vs. potential IP loss (estimated + crore) + regulatory savings
Illustrative Scenario 2: Large Manufacturing Enterprise, Steel India Ltd.
Company Profile:
- Size: 12,000 employees, 8,500 unionized workers
- Industry: Steel Manufacturing, Integrated Steel Plant
- Location: Rourkela, Odisha
- Operations: 3 steel plants, 15 mines, 8 processing units
- Regulatory Scope: DPDP Act 2023, Factories Act, Mines Act, Industrial Employment Act, ISO 27001, OHSAS 18001
- Union: Strong trade union presence; collective bargaining agreement
Challenge: Steel India had complex labor relations and outdated security terms:
- Employment contracts for 8,500 union workers were governed by collective bargaining agreement (CBA) with no security terms
- Only 3,500 non-union staff had individual contracts; security terms were generic and unenforced
- Standing Orders under Industrial Employment Act had no information security provisions
- Strong union resistance to any new contractual terms without negotiation
- OT/ICS (Operational Technology) security was critical but operators had no security obligations in contracts
- No sanctions for security violations due to union protection and lack of contractual basis
- A contract worker stole proprietary steel formulation data and sold it to Chinese competitor
- No IP assignment clause for R&D staff; 2 senior researchers left and filed patents in their own names
- No return of assets clause; departing employees routinely took laptops, documents, and data
- CBA renewal was upcoming (every 3 years); security terms had to be negotiated with union
Solution:
-
Months 1-3: Union Engagement and CBA Negotiation
- Engaged Singahi for labor-law-compliant security terms program
- Established Security-Labor Relations Committee (management + union representatives)
- Conducted 12 workshops with union leaders explaining security risks and business impact
- Presented data: 1 OT security incident could shut down plant for days, affecting 12,000 jobs
- Negotiated security terms as part of CBA renewal (security as job protection, not surveillance)
- Agreed on graduated sanctions with union appeal process (grievance mechanism)
- Union agreed to security terms in exchange for: cybersecurity training as paid work time, security equipment, no surveillance of personal activity
-
Months 4-6: CBA and Standing Orders Update
- Updated Standing Orders with information security provisions (work discipline, asset protection, data handling)
- Created security addendum for CBA (appendix to main agreement)
- Defined security responsibilities for different worker categories (operators, supervisors, managers, R&D)
- Created union-approved sanctions matrix (with union representative on sanctions committee)
- Updated CBA to include: security training as paid time, security equipment provision, whistleblower protection
- Standing Orders approved by labor commissioner as required
-
Months 7-9: Non-Union Staff and R&D
- Updated individual contracts for 3,500 non-union staff with detailed security terms
- Created IP assignment and invention disclosure process for 450 R&D staff
- Created patent reward program (union-approved): for filed patent, for granted patent
- Implemented return of assets clause with exit verification
- Created NDA for all staff with access to proprietary processes
- Implemented security acknowledgment for all non-union staff (100% completion)
-
Months 10-12: Contractor and Vendor Security
- 4,200 contract workers required to sign security terms (through contractor companies)
- Contractor companies required to provide security training to their workers
- Created vendor security terms for 85 critical vendors (equipment, technology, maintenance)
- Implemented security orientation for all contract workers (15 minutes, paid)
- Created contractor security violation reporting to contractor company (joint management)
-
Months 13-15: Training and Culture
- Security training made mandatory and paid (union requirement)
- Created plant-specific security scenarios (OT security, physical security, process safety)
- Created security awareness campaign in Odia and Hindi (local languages)
- Integrated security into daily toolbox talks (5-minute security tip)
- Created security suggestion scheme (employee suggestions rewarded)
- Union representatives became security champions (peer-to-peer messaging)
Results:
- CBA acceptance: First CBA in Indian manufacturing with complete security terms; became industry reference
- Security incidents: 60% reduction in security incidents in 12 months
- OT security: Zero OT security incidents; passed critical infrastructure audit
- IP protection: 3 patents filed with proper assignment; no IP theft incidents
- Contractor compliance: 100% contract worker security acknowledgment; 1 contractor violation detected and addressed
- Union relations: Security terms strengthened union-management relationship (shared security goals)
- efficiency gains: program overhead vs. potential plant shutdown overhead (+ crore/day) + IP loss
- Industry recognition: Won FICCI Industrial Security Excellence Award; featured in national labor journal
Multi-Framework Mapping
| ISO 27001:2022 A.6.2 | SOC 2 Trust Services Criteria | PCI DSS v4.0 | NIST 800-53 Rev 5 | CIS Controls v8 | COBIT 2019 | GDPR / DPDP Act 2023 |
|---|---|---|---|---|---|---|
| Terms and conditions of employment | CC1.1: Management philosophy | 12.4.1: Security awareness program | PS-1: Personnel security policy | Control 6.1: Establish an inventory of assets | APO07.01: Manage people | DPDP S. 8: Security safeguards |
| CC1.2: Board of directors | 12.4.2: Security awareness content | PS-2: Position risk designation | Control 6.2: Address unauthorized assets | APO07.02: Manage competencies | DPDP S. 10: Consent | |
| CC1.3: Management oversight | 12.4.3: Security awareness program content | PS-3: Personnel screening | Control 6.3: Establish an inventory of personnel | APO07.03: Manage contracts | GDPR Art. 28: Processor | |
| CC1.4: Integrity and ethical values | 12.4.4: Security awareness program evaluation | PS-4: Personnel termination | Control 6.4: Establish an inventory of third-party personnel | APO07.04: Manage cultural diversity | GDPR Art. 32: Security | |
| CC1.5: Accountability | 12.8.1: Third-party security policies | PS-5: Personnel transfer | Control 6.5: Establish an inventory of service accounts | APO07.05: Manage performance | GDPR Art. 5: Principles | |
| CC2.1: Communication and information | 12.8.2: Third-party security agreements | PS-6: Access agreements | Control 6.6: Establish an inventory of privileged accounts | DSS05.02: Manage security | DPDP S. 11: Rights | |
| 12.8.3: Third-party security assurance | PS-7: External personnel security | Control 6.7: Establish an inventory of shared accounts | DSS05.03: Manage security services | DPDP S. 13: Grievance | ||
| PS-8: Personnel sanctions | Control 6.8: Establish an inventory of emergency accounts | DSS06.01: Manage business process controls | DPDP S. 14: Nomination | |||
| PS-9: Position descriptions | Control 6.9: Establish an inventory of temporary accounts | DSS06.02: Manage business process controls | DPDP S. 17: Children's data | |||
| Control 6.10: Establish an inventory of generic accounts | DSS06.03: Manage business process controls | DPDP S. 22: SDF | ||||
| Control 6.11: Establish an inventory of dormant accounts | MEA01.02: Monitor and evaluate |
Regulatory and Industry Context
India Regulatory Framework
| Regulation | Employment Terms Requirement | Penalty |
|---|---|---|
| DPDP Act 2023 | Section 8, personnel security as reasonable safeguard | Up to |
| IT Act 2000 (Section 43A) | Reasonable security practices including personnel | Compensation |
| Companies Act 2013 | Section 166, director duties; Section 149, independent director requirements | Director disqualification |
| RBI Cyber Security Framework | Employee security responsibilities in contracts | License restrictions |
| SEBI Cybersecurity Circular | Personnel security terms for trading systems | Trading restrictions |
| IRDAI Guidelines | Employee data protection responsibilities | License suspension |
| POSH Act 2013 | Employee obligations under POSH policy | Employer liability |
| Factories Act 1948 | Worker safety obligations; Standing Orders | ; imprisonment |
| Industrial Employment (SO) Act 1946 | Standing orders including discipline | Labour court disputes |
| Shops and Establishments Act | Employee conduct rules | License cancellation |
| ID Act 1947 | Unfair dismissal protections; due process | Reinstatement, back wages |
| Contract Labour Act 1970 | Contract worker terms and conditions | Penalties |
| Minimum Wages Act 1948 | Terms must include minimum wage compliance | Penalties |
| EPF Act 1952 | Terms must include EPF contributions | Prosecution |
| ESI Act 1948 | Terms must include ESI coverage | Prosecution |
International Regulations
| Regulation | Employment Terms Requirement |
|---|---|
| GDPR (EU) | Article 28, processor personnel; Article 32, security measures including personnel |
| HIPAA (US) | §164.308(a)(3)(ii)(A), Workforce security; §164.308(a)(3)(ii)(C), Termination procedures |
| SOX (US) | Internal controls including personnel accountability |
| FCRA (US) | Background check disclosure and authorization |
| UK Employment Rights Act 1996 | Written statement of particulars including policies |
| EU Whistleblower Directive | Protection for employees reporting violations |
| ILO Convention | Worker rights and protections |
Sector-Specific Requirements
| Sector | Employment Terms-Specific Requirements |
|---|---|
| BFSI | RBI employee background and integrity requirements; SEBI dealer registration; fiduciary duties; non-compete for traders |
| Healthcare | Clinical staff confidentiality; HIPAA Business Associate obligations for contractors; CDSCO compliance |
| Telecom | DOT security clearance for network personnel; subscriber data confidentiality; lawful interception obligations |
| Manufacturing | Factories Act standing orders; union CBA security terms; OT security operator obligations; safety + security integration |
| Government | Official Secrets Act obligations; security clearance; service rules; conduct rules; CVC guidelines |
| Defence | Security clearance; foreign contact reporting; side business disclosure; Official Secrets Act; export control |
| Aviation | DGCA security training requirements; substance testing; background verification; airside access obligations |
| Education | Student data confidentiality; POCSO obligations; teacher conduct rules; child safety obligations |
| SaaS / B2B | Customer data confidentiality; SOC 2 personnel requirements; developer IP assignment; remote work terms |
| E-commerce | Customer data handling; payment data access; delivery personnel verification; warehouse security |
Roles and Responsibilities (RACI)
| Activity | Accountable | Responsible | Consulted | Informed |
|---|---|---|---|---|
| Security Terms Policy | CISO | HR Head | Legal | Board |
| Contract Template Updates | Legal | HR | CISO | Management |
| Role Responsibility Definition | CISO | Security Manager | HR, Hiring Manager | Employees |
| Acknowledgment Process | HR | HR Admin | CISO, IT | Employees |
| Annual Re-Acknowledgment | HR | HR Admin | CISO | Employees, Managers |
| Sanctions Matrix | CISO | Security Manager | HR, Legal | Management |
| Sanctions Enforcement | HR | HR Manager | CISO, Legal, Manager | Employee |
| Appeal Process | Legal | HR Head | CISO | Employee, Board |
| Remote Work Addendum | CISO | HR | Legal, IT | Employees |
| BYOD Addendum | CISO | IT | HR, Legal | Employees |
| Contractor Security Terms | Legal | Procurement | CISO, HR | Contractors |
| Vendor Security Terms | Legal | Contract Manager | CISO, Procurement | Vendors |
| Performance Integration | HR | HR Manager | CISO, Manager | Employees |
| Training on Responsibilities | CISO | Training Team | HR | Employees |
| Policy Change Communication | CISO | HR | Legal | All Employees |
| Union Negotiation | Legal | HR Head | CISO | Union, Board |
| Standing Orders Update | Legal | HR | CISO | Labor Department |
| Record Management | HR | HR Admin | CISO | Compliance |
| Metrics and Reporting | CISO | HR Analyst | Compliance | Board |
| Audit and Compliance | Internal Audit | HR, CISO | Legal | Board |
Documentation and Evidence Requirements
Required Documents
| Document | Owner | Retention Period | Format |
|---|---|---|---|
| Employment Security Terms Policy | CISO | 7 years | PDF + Word |
| Employment Contract Templates | Legal | 7 years | Word + PDF |
| Role-Specific Security Addendums | CISO | 7 years | Word + PDF |
| Security Acknowledgment Forms | HR | 7 years | Signed forms / digital |
| Remote Work Addendum | HR | 7 years | Signed forms / digital |
| BYOD Addendum | HR | 7 years | Signed forms / digital |
| IP Assignment Clauses | Legal | 20 years | Contract extracts |
| NDA Records | Legal | 7 years | Signed forms / digital |
| Sanctions Matrix | CISO | 7 years | Document |
| Sanction Records | HR | 7 years | Case files |
| Appeal Records | Legal | 7 years | Case files |
| Annual Re-Acknowledgment Records | HR | 7 years | Digital records |
| Policy Update Communication | CISO | 3 years | Email / portal records |
| Training Completion Records | HR | 5 years | LMS records |
| Performance Review Records | HR | 5 years | Performance system |
| CBA Security Terms (if applicable) | Legal | Duration of CBA + 7 years | Agreement PDF |
| Standing Orders | Legal | 7 years | Approved document |
| Contractor Security Terms | Legal | Duration of contract + 3 years | Contracts |
| Vendor Security Terms | Legal | Duration of contract + 3 years | Contracts |
| Union Negotiation Records | Legal | 7 years | Meeting minutes |
| Audit Evidence | Internal Audit | 5 years | Audit reports |
Continuous Improvement
Maturity Model (Level 1-5)
| Level | Name | Description |
|---|---|---|
| 1 | Initial | Generic contract clause; no acknowledgment; no sanctions; no records |
| 2 | Managed | Security clause in all contracts; basic acknowledgment; informal sanctions; paper records |
| 3 | Defined | Role-specific responsibilities; formal acknowledgment; graduated sanctions; annual re-acknowledgment; contractor terms; performance integration |
| 4 | Quantitatively Managed | Automated acknowledgment tracking; IAM integration; metrics-driven; remote/BYOD addendums; union compliance; dynamic updates |
| 5 | Optimizing | AI-driven responsibility personalization; predictive compliance; behavioral analytics; integrated security culture; continuous improvement; industry leadership |
Improvement Cycle
- Plan: Annual review of terms; quarterly metrics; regulatory change monitoring; industry benchmarking
- Do: Update contracts; deploy new tools; train managers; enhance sanctions; improve communication
- Check: Measure understanding; audit enforcement; benchmark; gather feedback; review disputes
- Act: Standardize; communicate; update procedures; report to management; share best practices
Technology Trends
- Dynamic Contracts: AI-generated role-specific contract terms based on access and risk
- Blockchain Acknowledgment: Immutable acknowledgment records for audit and legal evidence
- Behavioral Analytics: Predicting compliance risk based on behavior patterns
- Continuous Acknowledgment: Real-time policy acknowledgment as policies change
- Natural Language Contracts: Simplified contract language for better employee understanding
- Gamified Compliance: Engagement-driven acknowledgment and training
- Union-Tech Platforms: Digital platforms for union-management security collaboration
FAQ
Frequently Asked Questions (20 Questions)
Q1: Are security terms enforceable in Indian employment contracts? A: Yes, if they are reasonable, clearly communicated, and comply with labor law. They cannot violate fundamental labor rights. Sanctions must be proportionate and follow due process.
Q2: Can we terminate an employee for a security violation? A: Yes, for serious violations, but you must follow due process: show cause notice, inquiry, opportunity to defend, reasoned order. For critical violations (theft, sabotage), immediate suspension is possible pending inquiry. Consult Legal.
Q3: Do security terms apply to unionized workers? A: Yes, but they may need to be negotiated through collective bargaining or included in standing orders. Unilateral changes may be challenged. Engage union early and frame security as job protection.
Q4: What if an employee refuses to sign the security acknowledgment? A: You can withhold system access and escalate to HR and Legal. If they continue to refuse, disciplinary action up to termination may be warranted (subject to due process). Document all steps.
Q5: Can we change security terms without employee consent? A: For non-union employees, you can update terms with reasonable notice (typically 30 days) if the contract allows. For union employees, changes may require negotiation. Always provide notice and re-acknowledgment.
Q6: Are non-compete clauses enforceable in India? A: Section 27 of the Indian Contract Act generally renders non-compete clauses void as restraint of trade. However, courts have enforced reasonable confidentiality and non-solicitation clauses. Focus on NDA and IP protection rather than non-compete.
Q7: Do we need separate security terms for remote workers? A: Yes. Remote work introduces unique risks (home environment, personal networks, family access). A specific remote work addendum should address workspace security, VPN use, device security, and data handling at home.
Q8: Can contractors be held to the same security terms as employees? A: Yes, through contractor agreements. However, enforcement mechanisms differ. Ensure contractor agreements have clear security terms, and require contractor companies to enforce them. Joint liability can be structured.
Q9: What should be in a BYOD addendum? A: Device registration, encryption requirement, MDM enrollment, approved apps, data separation, remote wipe authorization, no jailbreak/root, OS updates, and data transfer restrictions.
Q10: How do we handle security terms for international employees? A: Comply with local labor law in each country. Security terms should be globally consistent but locally compliant. Use local legal counsel for contract review. Data protection terms must comply with local privacy law (GDPR, etc.).
Q11: Can we include security responsibilities in the offer letter? A: Yes, offer letters can include a summary of security responsibilities with a reference to the full security policy and acknowledgment form. This sets expectations before the detailed contract.
Q12: What is the difference between a security policy and security terms in a contract? A: The security policy defines what the organization requires. The contract terms make compliance a contractual obligation with consequences for breach. Both are needed, the policy educates, the contract enforces.
Q13: Do interns and trainees need security terms? A: Yes, if they have access to information or systems. Use simplified terms appropriate to their role and duration. Include confidentiality obligations and return of assets.
Q14: How do we handle security terms for board members? A: Board members should sign NDAs and confidentiality agreements. They should acknowledge security responsibilities if they have access to sensitive information. Director agreements under Companies Act should include relevant terms.
Q15: Can we monitor employees based on security terms? A: Yes, but monitoring must be proportionate, transparent, and comply with DPDP Act 2023 and labor law. Employees should be informed of monitoring. Personal monitoring must be minimized. Consult Legal.
Q16: What is a garden leave and when should we use it? A: Garden leave is when an employee remains employed during notice period but does not work. It's useful for sensitive roles to prevent data theft during transition. Must be in contract and complies with labor law.
Q17: Do we need an employment bond for security? A: Employment bonds are generally not enforceable in India as they are considered restraint of trade. Focus on enforceable terms (NDA, IP assignment, return of assets) rather than bonds.
Q18: How do we integrate security into performance reviews? A: Define security KPIs (training completion, incident involvement, policy compliance, security suggestions). Include them as 5-10% of performance score for relevant roles. Recognize security excellence.
Q19: What is the role of CISO in employment security terms? A: CISO defines security responsibilities, sanctions, and policy content. CISO reviews violations, participates in sanctions committee, and ensures security terms are technically enforceable.
Q20: What will an ISO 27001 auditor look for in A.6.2? A: The auditor will verify: (1) security responsibilities are in employment contracts, (2) responsibilities are communicated to employees, (3) employees acknowledge responsibilities, (4) sanctions are defined, (5) sanctions are applied when appropriate, (6) contractor terms exist, (7) records are maintained, and (8) the program is reviewed.
References and Further Reading
ISO Standards
- ISO 27001:2022, Information Security Management Systems
- ISO 27002:2022, Information Security Controls
- ISO 27701:2019, Privacy Information Management System
- ISO 27036, Information Security for Supplier Relationships
Indian Law
- Indian Contract Act 1872, Section 27 (restraint of trade)
- Industrial Employment (Standing Orders) Act 1946
- Industrial Disputes Act 1947
- Factories Act 1948
- Shops and Establishments Act (state-specific)
- Companies Act 2013, Director duties, DIN
- DPDP Act 2023, Data protection obligations
- IT Act 2000, Reasonable security practices
- POSH Act 2013, Employee obligations
- Contract Labour Act 1970
- Minimum Wages Act 1948
- EPF Act 1952
- ESI Act 1948
International
- GDPR (EU), Articles 5, 28, 32
- HIPAA (US), §164.308(a)(3)**, Workforce security
- SOX (US), Internal controls
- UK Employment Rights Act 1996
- EU Whistleblower Directive
- ILO Conventions, Worker rights
Industry
- NASSCOM, IT industry employment practices
- ISACA, Security and governance guidance
- CII, Industrial employment practices
- FICCI, Business and employment law