Skip to content
Singahi

Compliance · guide

ISO 27001 A.6.2: Terms and Conditions of Employment

52 min read

Share
On this page

Quick Reference (60 Seconds)

AttributeDetail
Control IDA.6.2
TitleTerms and Conditions of Employment
ObjectiveEnsure employees understand their information security responsibilities and that these are enforced through contractual terms
DomainPeople
ISO 27001:2022 ClauseAnnex A.6.2
What You Must DoInclude information security responsibilities in employment contracts, ensure employees acknowledge them, and enforce compliance through HR processes
OwnerHR / Legal / CISO
Maturity Level 1Generic security mention in contracts
Maturity Level 2Security responsibilities clause in all contracts; onboarding briefing
Maturity Level 3Role-specific security responsibilities; annual acknowledgment; violation tracking
Maturity Level 4Automated acknowledgment tracking; security KPIs in performance reviews; dynamic clause updates
Maturity Level 5AI-driven responsibility personalization; behavioral analytics; predictive compliance; integrated security culture metrics
ISO 27002 attributesControl type: Preventive · Properties: Confidentiality, Integrity, Availability · Concepts: Protect · Capabilities: Human resource security · Domains: Governance and ecosystem

What the Control Asks For

Do you need this control?

A.6.2 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Include it if you employ people, because employment terms are where security responsibilities become binding. Most organisations meet it by adding security clauses to offer letters and contracts.

The Control in Brief

Annex A 6.2 asks that employment contractual agreements state both the personnel's and the organization's responsibilities for information security.

Implementation Guidance (ISO 27002:2022)

  • Information security responsibilities should be addressed in the terms and conditions of employment
  • Employees should be made aware of their security responsibilities at the time of hire
  • The organization should require employees to commit to these responsibilities in writing
  • Sanctions for non-compliance should be defined and communicated
  • Responsibilities should be reviewed and updated as roles change, and when laws, regulations or policies change
  • 27002 lists what the terms should cover (paraphrased): (a) a confidentiality or non-disclosure agreement for people given access to confidential information (A.6.6); (b) legal responsibilities and rights, for example under copyright and data protection law (A.5.32, A.5.34); (c) responsibilities for classifying information and managing assets (A.5.9–A.5.13); (d) responsibilities for handling information received from interested parties such as customers and partners; (e) what happens if security requirements are disregarded (A.6.4)
  • Security roles and responsibilities should be communicated to candidates during the pre-employment process
  • Some responsibilities, such as confidentiality, continue for a defined period after employment ends (A.6.5)
  • The organization should ensure that employees understand the consequences of security violations
  • This applies to permanent employees, contractors, and temporary staff

"Shall" vs "Should" Analysis

  • Shall (once you have selected this control): employment contracts state the employee's and the organisation's information security responsibilities
  • Should: Specific methods of communication and agreement are flexible

Common Misinterpretations

MisinterpretationReality
"A generic IT policy signature is enough"Role-specific responsibilities must be communicated and acknowledged
"Only full-time employees need this"Contractors, temps, interns, and vendors all need security terms
"Security responsibilities are obvious"Employees need explicit, documented, and acknowledged responsibilities
"Once signed at hire, done forever"Responsibilities must be reviewed and re-acknowledged annually and on role changes
"Sanctions are HR's problem, not security's"Security must define sanctions for security violations; HR enforces

Why Terms and Conditions of Employment Matters

The Business Risk Narrative

Employment contracts are the legal foundation of information security accountability. For Indian organizations, weak security clauses create significant exposure:

  • 68% of breaches worldwide involved a non-malicious human element such as an error or falling for social engineering (Verizon DBIR 2024)
  • Clear, acknowledged responsibilities make it possible to train, hold people accountable and enforce sanctions fairly
  • Without documented security responsibilities, organizations struggle to enforce disciplinary action or pursue legal remedies
  • DPDP Act 2023 requires "reasonable security safeguards" which includes personnel accountability
  • In negligence lawsuits, courts look at whether the organization clearly communicated responsibilities

Regulatory Landscape in India

RegulationEmployment Terms RequirementPenalty for Non-Compliance
DPDP Act 2023Employee data processed for employment purposes (s.7(i)); staff handling personal data must follow the safeguards the fiduciary is accountable for (s.8(1), s.8(5))Up to ₹250 crore (failure to take reasonable security safeguards)
IT Act 2000 (Section 43A)Reasonable security practices including personnelCompensation claims
Companies Act 2013Director duties including care and diligence (Section 166)Director liability, disqualification
RBI Cyber Security FrameworkEmployee security responsibilities in contractsLicense restrictions
SEBI CSCRF (2024)Personnel security terms for trading system accessTrading restrictions
IRDAI GuidelinesEmployee data protection responsibilitiesLicense suspension
POSH Act 2013Employee obligations under POSH policyEmployer liability
OSH Code 2020 (replaced the Factories Act 1948)Worker safety obligationsfine; imprisonment
Industrial Employment (SO) Act 1946Standing orders including disciplineLabour court disputes
State Shops and Establishments ActsConditions of employment for shops and offices (still state laws)Penalties under the state Act

Industry-Specific Consequences

IndustryEmployment Terms Failure Scenario
BFSIEmployee without clear security responsibilities shares password; customer account drained; RBI action
HealthtechEmployee without PHI obligations posts patient data on social media; CDSCO action; malpractice
SaaS / B2BDeveloper without IP obligations takes code to competitor; no contractual recourse; loss of product
E-commerceWarehouse employee without data handling terms steals customer addresses; fraud; DPDP penalty
GovernmentEmployee without confidentiality obligations leaks classified data; Official Secrets Act prosecution
ManufacturingEmployee without safety obligations causes industrial accident; criminal liability

Scope and Applicability

What the Control Covers

  • Employment contracts: Permanent, temporary, fixed-term, probationary
  • Contractor agreements: Independent contractors, consultants, freelancers
  • Internship agreements: Students, trainees, apprentices
  • Vendor personnel agreements: Staff augmentation, ODC workers, outsourced staff
  • Director agreements: Board members, advisors, non-executive directors
  • Remote work agreements: Work-from-home, hybrid work arrangements
  • BYOD agreements: Bring Your Own Device policies and terms
  • Side letters: Specific security terms for sensitive roles
  • Non-disclosure agreements: Standalone or embedded in employment contracts
  • Intellectual property assignment: IP ownership clauses
  • Return of assets clauses: Equipment, data, access return upon exit
  • Non-compete clauses: restrictions during employment (exclusivity) are enforceable; post-employment non-competes are void in India under s.27 of the Indian Contract Act, so rely on confidentiality, IP assignment and reasonable non-solicitation
  • Sanctions clauses: Defined consequences for security violations
  • Acknowledgment: Signed acceptance of security policies and responsibilities

Who It Applies To

RoleResponsibility
HRContract drafting, onboarding communication, acknowledgment tracking, enforcement
LegalContract review, enforceability, labor law compliance, sanctions legality
CISODefining security responsibilities, sanctions, policy content, violation assessment
Hiring ManagersCommunicating role-specific security responsibilities, performance review
EmployeesReading, understanding, and complying with security responsibilities
Line ManagersEnforcing security responsibilities within their teams, reporting violations
Compliance ManagerEnsuring contractual terms meet regulatory requirements
IT SecurityTechnical enforcement of access controls aligned with contractual terms

What It Does NOT Cover

  • General HR policies (leave, attendance, benefits), covered by HR policies
  • Compensation and benefits, covered by compensation policies
  • Performance management (general), covered by HR processes
  • Physical safety (OSHA-equivalent), covered by safety policies
  • Termination procedures, covered by A.6.5 and labor law

Size-Based Applicability

Organization SizeApproach
Startups (< 50)Security clause in all contracts; simple acknowledgment; basic sanctions
SMB (50-500)Role-specific security addendums; annual re-acknowledgment; defined sanctions
Mid-market (500-5000)Complete security terms; automated acknowledgment tracking; performance integration; contractor terms
Enterprise (5000+)Dynamic security terms; AI-driven personalization; integrated with GRC; global contract variations

Key Definitions and Terminology

TermDefinitionSource
Terms and Conditions of EmploymentThe contractual agreement between employer and employee defining rights, obligations, and responsibilitiesContract Law
Security ResponsibilitiesSpecific obligations of an employee to protect information and systemsISO 27001
SanctionsPenalties or consequences for violating security responsibilitiesISO 27002
AcknowledgmentFormal confirmation that the employee has read, understood, and agrees to complyHR Practice
Non-Disclosure Agreement (NDA)Contract prohibiting disclosure of confidential informationContract Law
Non-Compete ClauseContractual restriction preventing employment with competitors post-employmentContract Law
Garden LeavePeriod where employee remains employed but does not work, typically during noticeHR Practice
Acceptable Use Policy (AUP)Policy defining permitted use of organization systems and dataISO 27001
Bring Your Own Device (BYOD)Policy allowing personal devices for work with security requirementsIndustry
Remote Work AgreementContract defining security requirements for remote workHR Practice
IP AssignmentContractual transfer of intellectual property rights to employerContract Law
Confidentiality ObligationLegal duty to protect confidential informationContract Law
Standing OrdersRules of conduct for industrial establishments under Indian lawIndustrial Relations Code 2020
Service RulesConduct rules for government and public sector employeesGovernment
Disciplinary ActionFormal procedure for addressing violations of employment termsLabor Law
Employment BondContract requiring employee to stay for a minimum period or pay penaltyContract Law (enforceability varies)

Relationship to Other Controls

Figure · Matrix

Comparison: A.5.1 to A.5.32

RelationshipWhy It Matters
A.5.1Policies for InformationSecurity policy must exist
A.5.2Information Security RolesRole definitions inform
A.6.1ScreeningScreened employees must
A.5.32Intellectual PropertyIP assignment must
Condensed from the table below, which carries the full detail for each cell.

Upstream Controls (Prerequisites)

Control IDRelationshipWhy It Matters
A.5.1Policies for Information SecuritySecurity policy must exist before it can be referenced in contracts
A.5.2Information Security RolesRole definitions inform security responsibilities in contracts
A.6.1ScreeningScreened employees must be bound by security terms
A.5.32Intellectual Property RightsIP assignment must be in employment contracts

Downstream Controls (Enabled By)

Control IDRelationshipWhy It Matters
A.6.3Information Security AwarenessContractual responsibilities must be reinforced through training
A.6.4Disciplinary ProcessContractual sanctions enable disciplinary action
A.6.5Responsibilities after TerminationContractual return-of-assets and confidentiality clauses enable exit procedures
A.6.6Confidentiality AgreementsNDA is part of employment terms
A.6.7Remote WorkingRemote work terms must be in contracts
A.6.8Information Security Event ReportingContractual reporting obligation enables incident reporting

Parallel Controls (Work Alongside)

Control IDRelationshipWhy It Matters
A.5.9Inventory of Information AssetsAsset access determines contract terms
A.5.10Acceptable Use of AssetsAUP is referenced in employment terms
A.5.14Information TransferData handling terms in contracts
A.5.34Privacy and Protection of PIIPrivacy obligations in employment terms
A.8.1User Endpoint DevicesBYOD terms in contracts
A.8.5Secure AuthenticationAuthentication obligations in contracts

Implementation Roadmap (Week-by-Week)

Phase 1: Discovery & Assessment (Weeks 1-2)

Week 1: Current Contract Assessment

  • Deliverable: Employment contract security terms audit report
  • Owner: Legal + HR + CISO
  • Activities:
    1. Review all current employment contract templates
    2. Identify security-related clauses (or absence thereof)
    3. Review contractor and vendor personnel agreements
    4. Assess current acknowledgment processes (signature, digital, HRIS)
    5. Interview hiring managers about security communication
    6. Review current sanctions for security violations (documented? enforced?)
    7. Assess compliance with labor law requirements for contract terms

Week 2: Gap Analysis and Role Mapping

  • Deliverable: Security responsibility gap analysis by role
  • Owner: CISO + HR + Legal
  • Activities:
    1. Map all roles to information access levels (Public, Internal, Confidential, Restricted)
    2. Define security responsibilities for each access level
    3. Identify roles with special requirements (remote, BYOD, IP creation, PII access)
    4. Assess current employee understanding of security responsibilities (survey)
    5. Identify gaps between current contracts and ISO 27001 requirements
    6. Map legal requirements (DPDP, labor law, industry-specific)
    7. Create security responsibility matrix by role

Phase 2: Design & Planning (Weeks 3-4)

Week 3: Contract Template Development

  • Deliverable: Updated employment contract templates with security terms
  • Owner: Legal + HR + CISO
  • Activities:
    1. Draft security responsibilities clause for main employment contract
    2. Create role-specific security addendums (4 tiers)
    3. Create standalone security acknowledgment form
    4. Create remote work security addendum
    5. Create BYOD security addendum
    6. Create IP assignment and confidentiality clauses
    7. Create sanctions clause (graduated sanctions)
    8. Create return of assets clause
    9. Review all clauses for labor law compliance and enforceability

Week 4: Policy and Procedure Development

  • Deliverable: Security Terms Management Procedure + Acknowledgment Tracking Procedure
  • Owner: HR + CISO + Legal
  • Activities:
    1. Create procedure for communicating security responsibilities during onboarding
    2. Create procedure for annual re-acknowledgment
    3. Create procedure for role-change acknowledgment updates
    4. Create procedure for sanctions enforcement (violation → investigation → decision → action)
    5. Create procedure for contract updates when policies change
    6. Create employee communication templates (email, presentation, video)
    7. Create manager training on enforcing security responsibilities

Phase 3: Implementation (Weeks 5-8)

Week 5: New Hire Contract Rollout

  • Deliverable: All new hires receive updated contracts with security terms
  • Owner: HR + Legal
  • Activities:
    1. Update HRIS with new contract templates
    2. Train recruiters on new security clauses and their importance
    3. Implement new contract for all new hires
    4. Create new hire security briefing presentation
    5. Ensure new hires sign security acknowledgment before system access
    6. Create new hire security checklist (contract → acknowledgment → training → access)
    7. Test workflow with 5 new hires

Week 6: Existing Employee Retrospective Acknowledgment

  • Deliverable: All existing employees acknowledge updated security responsibilities
  • Owner: HR + CISO + IT
  • Activities:
    1. Create communication campaign for existing employees ("Your Security Responsibilities")
    2. Deploy updated security acknowledgment to all employees
    3. Track acknowledgment completion (target: 100%)
    4. Follow up with non-responders (email, manager, HR)
    5. For employees who refuse acknowledgment: escalate to Legal and CISO
    6. Create audit trail of all acknowledgments
    7. Link acknowledgment to system access (no acknowledgment = no access for renewals)

Week 7: Contractor and Vendor Agreement Updates

  • Deliverable: All contractor and vendor personnel agreements include security terms
  • Owner: Legal + Procurement + Vendor Management
  • Activities:
    1. Update contractor agreement template with security terms
    2. Create vendor personnel security addendum
    3. Renegotiate existing contracts with security terms (where possible)
    4. Create vendor security acknowledgment process
    5. Train procurement on security contract requirements
    6. Implement security terms in all new vendor contracts
    7. Create vendor security terms checklist

Week 8: Sanctions and Enforcement Implementation

  • Deliverable: Sanctions framework operational; first training delivered
  • Owner: CISO + HR + Legal + Line Managers
  • Activities:
    1. Create graduated sanctions matrix (verbal warning → written warning → suspension → termination → legal action)
    2. Define security violation categories and corresponding sanctions
    3. Train managers on identifying and reporting security violations
    4. Create violation investigation procedure
    5. Create sanctions decision committee (HR, Legal, CISO, manager)
    6. Document first sanctions training session
    7. Create violation tracking system (incident + sanction + outcome)

Phase 4: Testing & Validation (Weeks 9-10)

Week 9: Contract and Acknowledgment Testing

  • Deliverable: Validation report with test results
  • Owner: HR + Internal Audit + CISO
  • Activities:
    1. Test contract workflow end-to-end (offer → signature → acknowledgment → access)
    2. Test acknowledgment tracking system (completion %, follow-up, access blocking)
    3. Test role-change update procedure (promotion → new acknowledgment)
    4. Test sanctions procedure with mock violation scenario
    5. Test contractor security acknowledgment process
    6. Test contract update procedure when policy changes
    7. Verify all contracts meet labor law requirements

Week 10: Compliance Validation

  • Deliverable: Compliance validation report
  • Owner: Legal + Compliance Manager + HR
  • Activities:
    1. Validate contract terms against DPDP Act 2023
    2. Validate sanctions against labor law (fairness, proportionality, due process)
    3. Validate acknowledgment process for DPDP compliance (consent, records)
    4. Verify enforceability of key clauses (non-compete, IP assignment, confidentiality)
    5. Test employee understanding (survey: do employees know their security responsibilities?)
    6. Prepare compliance evidence package

Phase 5: Documentation & Certification Prep (Weeks 11-12)

Week 11: Documentation

  • Deliverable: Complete security terms management documentation
  • Owner: HR + Compliance Manager
  • Activities:
    1. Document all security contract templates and procedures
    2. Create training materials for managers and employees
    3. Create FAQ on security responsibilities
    4. Create metrics dashboard
    5. Create evidence repository for audits
    6. Document vendor contract management procedures

Week 12: Certification Readiness

  • Deliverable: Audit-ready evidence package
  • Owner: CISO + Compliance Manager
  • Activities:
    1. Conduct internal audit of security terms management
    2. Prepare evidence for external ISO 27001 auditor
    3. Remediate any gaps found
    4. Conduct management review
    5. Present program to certification body

Detailed Implementation Guidance

Figure · Tiers

Maturity levels for terms and conditions of employment

Maturity levels for ISO 27001 A.6.2, terms and conditions of employment, from most to least mature: Contractors, all contract roles; Tier 4: Low, reception, facilities, general staff; Tier 3: Medium, marketing, sales, operations; Tier 2: High, developer, qa, network admin, it support; Tier 1: Critical, ciso, cio, db admin, security engineer.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Step-by-Step Implementation

Step 1: Define Security Responsibility Tiers

TierRole ExamplesCore ResponsibilitiesSpecial Responsibilities
Tier 1: CriticalCISO, CIO, DB Admin, Security Engineer, DevOps Lead, CFOAll Tier 2 + 3 + code of conduct, incident command, vendor oversight, security architecture reviewNo side businesses in same industry; no consulting for competitors; mandatory reporting of security incidents within 1 hour; no personal devices for Restricted data; annual security certification
Tier 2: HighDeveloper, QA, Network Admin, IT Support, HR, FinanceAll Tier 3 + secure coding, system administration, access management, backup verification, secure configuration, vulnerability reportingNo unapproved software installation; mandatory code review participation; no production data on personal devices; mandatory security training quarterly; report suspicious activity within 4 hours
Tier 3: MediumMarketing, Sales, Operations, Customer Support, General AdminPassword security, phishing awareness, data handling per classification, incident reporting, physical security, clean desk policyNo sharing of credentials; no unauthorized data sharing; mandatory security training annually; report lost devices immediately; no sensitive data on personal email
Tier 4: LowReception, Facilities, General StaffBasic password security, physical security, incident reporting, no tailgatingReport security concerns; follow visitor procedures; no unauthorized area access; annual security awareness
ContractorsAll contract rolesSame as equivalent employee tier + no subcontracting without approval; return all assets upon termination; no data retention after contractEnhanced monitoring; restricted access; mandatory security briefing; no access to production without escort

Step 2: Draft Core Security Responsibilities Clause

Template

Step 3: Create Role-Specific Security Addendums

For Tier 1 and Tier 2 roles, create addendums with specific technical responsibilities:

Template

Step 4: Implement Acknowledgment Process

Create a multi-layered acknowledgment process:

  1. Contract Signature: Employee signs employment contract with security clause
  2. Security Acknowledgment Form: Separate form listing all security responsibilities; employee initials each item and signs
  3. Policy Acknowledgment: Employee acknowledges all information security policies (AUP, Data Protection, Remote Work, BYOD, etc.)
  4. Training Completion: Employee completes security training and passes assessment
  5. Annual Re-Acknowledgment: Employee re-signs acknowledgment annually
  6. Role-Change Acknowledgment: Employee signs updated acknowledgment when role changes
  7. Policy Update Acknowledgment: Employee acknowledges updated policies when changes occur

Step 5: Create Graduated Sanctions Matrix

Violation CategoryExamplesFirst OffenseSecond OffenseThird Offense
MinorClean desk violation, unreported lost badge, minor password policy violationVerbal warning + retrainingWritten warning + retrainingWritten warning + restricted access
ModerateSharing credentials (without incident), unauthorized software installation, unencrypted USB useWritten warning + retraining + restricted accessWritten warning + suspension (1-3 days) + mandatory trainingFinal warning + suspension (3-5 days)
MajorData leakage (no breach), unauthorized access attempt, credential sharing leading to incident, policy violation causing incidentWritten warning + suspension (3-5 days) + mandatory training + access reviewFinal warning + suspension (5-10 days) + role changeTermination
CriticalIntentional data breach, theft of data, sabotage, unauthorized system modification, fraud, espionageImmediate suspension + investigationTermination + legal actionTermination + legal action + regulatory reporting

Simulated phishing: a click in a phishing simulation is a learning event, not a violation. It triggers coaching, never sanctions (see A.6.3). Discipline applies to wilful or concealed breaches and to failing to report. ISO 27002 also expects the disciplinary process to consider whether the person was properly trained.

Note: For critical violations (theft, sabotage, espionage), first offense may result in immediate termination depending on severity and evidence.

Step 6: Implement Sanctions Enforcement Procedure

  1. Detection: Violation detected through monitoring, incident report, audit, or tip
  2. Initial Assessment: Security team assesses violation category and severity
  3. Investigation: Formal investigation (interviews, evidence collection, log review)
  4. Decision Committee: HR, Legal, CISO, and manager review investigation findings
  5. Decision: Sanction determined based on matrix, violation history, and circumstances
  6. Communication: Employee notified of violation and sanction in writing (with appeal rights)
  7. Appeal: Employee may appeal to higher authority (VP HR, CEO for critical cases)
  8. Execution: Sanction executed (warning recorded, suspension, termination, legal action)
  9. Documentation: All steps documented; records maintained per retention policy
  10. Follow-up: For non-termination cases, monitor for improvement; retraining effectiveness

Step 7: Create Remote Work Security Addendum

Template

Step 8: Create BYOD Security Addendum

Template

Step 9: Implement Annual Re-Acknowledgment

  • Send annual security responsibility reminder to all employees
  • Require re-signature of acknowledgment form
  • Update responsibilities based on role changes
  • Include updated policies and procedures
  • Track completion rate (target: 100%)
  • For non-completion: escalate to manager, then HR, then access review

Step 10: Link Acknowledgment to System Access

  • Configure IAM to require valid acknowledgment for access renewal
  • For employees with expired acknowledgment: flag for review, restrict access after 30 days
  • For new hires: no system access until acknowledgment is signed
  • For role changes: access updated only after new acknowledgment
  • Create automated workflow: expiration notice → manager alert → access restriction

Step 11: Create Employee Understanding Verification

  • Annual security awareness quiz (mandatory, scored)
  • Role-specific security scenario tests
  • Phishing simulation (results not punitive but inform training)
  • Manager one-on-one discussions about security responsibilities
  • Anonymous survey: "Do you understand your security responsibilities?"

Step 12: Implement Contract Update Process

  • When security policy changes, update contract templates
  • For significant changes: require existing employees to re-acknowledge
  • Maintain version control for all contract templates
  • Legal review of all changes for enforceability
  • Communicate changes to employees with explanation

Step 13: Create Performance Review Integration

  • Include security responsibility compliance in annual performance reviews
  • For Tier 1 and 2: security compliance is a formal performance metric
  • Security incidents and violations affect performance ratings
  • Security training completion affects performance ratings
  • Create security champion recognition program

Step 14: Document and Maintain Records

  • Maintain all signed contracts and acknowledgments
  • Maintain sanctions records (investigation, decision, outcome)
  • Maintain training completion records
  • Maintain policy version history
  • Secure disposal after retention period (7 years or employment + 7 years)
  • DPDP compliance for all personnel records

Step 15: Implement Continuous Improvement

  • Annual review of security terms and sanctions
  • Quarterly metrics review
  • Annual employee understanding survey
  • Benchmark against industry practices
  • Update for regulatory changes (DPDP, labor law, industry-specific)
  • Learn from incidents and violations to improve terms

Tools, Technologies, and Solutions

Complete Tool Comparison

ToolCategoryBest ForPricing modelKey FeaturesIntegration
DocuSignE-SignatureContract signing, acknowledgmentCommercialElectronic signatures, workflow, templates, audit trailHRIS, ATS, CRM
Adobe SignE-SignatureEnterprise contract signingCommercialE-signatures, workflow, templates, complianceAdobe, Microsoft, HRIS
HelloSign (Dropbox)E-SignatureSMB contract signingCommercialSimple e-signatures, templates, APIGoogle, Dropbox, HRIS
PandaDocE-Signature + ContractContract management + signingCommercialTemplates, CRM integration, analytics, approval workflowSalesforce, HubSpot, Pipedrive
WorkdayHRISEnterprise HR managementCommercialContract management, acknowledgment tracking, performance, complianceFull enterprise suite
BambooHRHRISSMB HR managementCommercialContract management, acknowledgment, onboarding, reporting100+ integrations
SAP SuccessFactorsHRISEnterprise HRCommercialContract, compliance, performance, learning, globalSAP ecosystem
Oracle HCMHRISEnterprise HRCommercialContract, compliance, talent management, globalOracle ecosystem
Zoho PeopleHRISIndian SMBCommercialContract, onboarding, attendance, leave, performanceZoho ecosystem
GreytHRHRISIndian SMBCommercialContract, payroll, attendance, compliance (India-specific)Indian compliance
Culture AmpEngagementEmployee surveys, engagementCommercialSurveys, analytics, recognition, performanceHRIS, Slack
15FivePerformanceContinuous performance managementCommercial1-on-1s, OKRs, recognition, feedbackHRIS, Slack
LatticePerformancePerformance + engagementCommercialGoals, reviews, 1-on-1s, engagement, analyticsHRIS, Slack
KnowBe4TrainingSecurity awareness trainingCommercialTraining, phishing simulation, reporting, complianceHRIS, Active Directory
ProofpointTrainingSecurity awarenessCommercialTraining, phishing simulation, threat intelligenceEmail, HRIS
SANS Security AwarenessTrainingAdvanced security trainingCommercialRole-based training, certifications, metricsHRIS, LMS
OktaIAMIdentity and access managementCommercialSSO, MFA, lifecycle management, access governance7,000+ integrations
Azure ADIAMMicrosoft ecosystemCommercialSSO, MFA, conditional access, lifecycleMicrosoft 365
Google WorkspaceProductivityGoogle ecosystem contractsCommercialDocs, e-sign (via integration), forms, complianceGoogle ecosystem
Microsoft 365ProductivityMicrosoft ecosystemCommercialWord, e-sign (via Adobe/DocuSign), Forms, complianceMicrosoft ecosystem
ServiceNowGRCEnterprise GRC and complianceCommercialPolicy management, acknowledgment, compliance, riskEnterprise platforms
RSA ArcherGRCEnterprise GRCCommercialPolicy, compliance, risk, vendor, incidentEnterprise platforms
MetricStreamGRCEnterprise GRCCommercialCompliance, risk, audit, policyEnterprise platforms

Recommendations by Organization Size

SizeHRISE-SignatureTrainingPerformance IntegrationGRC
Startup (<50)BambooHR or Zoho PeopleHelloSign or PandaDocKnowBe4ManualSpreadsheet
SMB (50-500)BambooHR or GreytHRDocuSign or Adobe SignKnowBe4 + SANS15Five or LatticeBasic
Mid-market (500-5000)Workday or SAP SuccessFactorsDocuSign + Adobe SignProofpoint + SANSLattice or Culture AmpServiceNow or MetricStream
Enterprise (5000+)Workday or Oracle HCMDocuSign + Adobe Sign + customSANS + customWorkday or SAP + customServiceNow or RSA Archer

Policy and Procedure Templates

Employment Security Terms Policy (Key Sections)

Template

Sanctions Enforcement Procedure

Template


Risk Assessment and Treatment

Key Risks Addressed by This Control

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R-001Employee violates security policy without consequencesMediumHighMediumMitigate, Clear sanctions, enforcement, graduated response
R-002Employee unaware of security responsibilitiesMediumHighMediumMitigate, Explicit terms, acknowledgment, training, communication
R-003Contractor without security obligationsMediumHighMediumMitigate, Contractor security terms, vendor clauses, attestation
R-004Cannot enforce sanctions due to weak contractsMediumHighMediumMitigate, Legal review of sanctions, labor law compliance, documentation
R-005Employee takes IP to competitorMediumCriticalHighMitigate, IP assignment clause, NDA, non-solicitation, exit controls (post-employment non-competes are void under s.27)
R-006Employee shares confidential data after terminationMediumHighMediumMitigate, NDA, return of assets, exit briefing, legal remedies
R-007Sanctions applied unfairly or discriminatorilyLowHighMediumMitigate, Structured procedure, committee review, appeal process, training
R-008Remote worker without security obligationsMediumMediumLowMitigate, Remote work addendum, BYOD policy, access controls
R-009Acknowledgment records not maintainedLowMediumLowMitigate, Secure storage, retention policy, DPDP compliance
R-010Policy changes not communicated to employeesMediumMediumLowMitigate, Change communication procedure, re-acknowledgment requirement

Audit and Compliance Checklist

Audit Questions (25 Questions)

#Audit QuestionExpected EvidenceRed Flags
1Is there a policy for employment security terms?Approved policyNo policy
2Do employment contracts include security responsibilities?Contract templatesNo security clause in contracts
3Are security responsibilities role-specific?Role-responsibility matrixGeneric one-size-fits-all responsibilities
4Do employees sign security acknowledgment?Signed acknowledgment formsNo acknowledgment, no signature
5Is acknowledgment tracked for all employees?Tracking system, completion reportNo tracking, incomplete acknowledgments
6Is there a sanctions clause in contracts?Contract templatesNo sanctions defined
7Are sanctions graduated and fair?Sanctions matrixArbitrary sanctions, no procedure
8Are sanctions enforced consistently?Sanction recordsSanctions not enforced, or inconsistently
9Is there a procedure for sanctions?Sanctions procedureNo procedure, ad-hoc decisions
10Are contractor agreements include security terms?Contractor templatesNo security terms for contractors
11Are vendor personnel agreements include security terms?Vendor contractsNo vendor personnel security requirements
12Is there a remote work security addendum?Remote work addendumNo remote work security terms
13Is there a BYOD security addendum?BYOD policy/addendumNo BYOD security terms
14Is there an IP assignment clause?Contract templatesNo IP assignment clause
15Is there an NDA in employment contracts?Contract templatesNo NDA
16Is there a return of assets clause?Contract templatesNo return of assets clause
17Is annual re-acknowledgment required?Annual acknowledgment recordsNo re-acknowledgment, one-time only
18Is acknowledgment linked to system access?IAM configurationAccess granted without acknowledgment
19Are security responsibilities in performance reviews?Performance review formsSecurity not in performance evaluation
20Are managers trained on enforcing security responsibilities?Training recordsNo manager training on security enforcement
21Is there an appeal process for sanctions?Appeal procedureNo appeal process
22Are sanctions reviewed for legal compliance?Legal review recordsNo legal review of sanctions
23Are employees trained on their security responsibilities?Training recordsNo security training
24Are records of contracts and acknowledgments maintained?Record repositoryNo records, lost contracts
25Is the employment security terms program reviewed?Management review minutesNo review, no improvement

Metrics and KPIs

Figure · Measures

The measures that show A.6.2 is working

  • Contract Security Clause Coverage100%Monthly
  • Acknowledgment Completion Rate100%Monthly
  • Annual Re-Acknowledgment Rate100%Annual
  • Contractor Security Terms Coverage100%Quarterly
  • Vendor Security Terms Coverage100%Quarterly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Metrics Dashboard

KPIFormulaTargetFrequency
Contract Security Clause Coverage(Contracts with security clause / Total contracts) × 100100%Monthly
Acknowledgment Completion Rate(Employees with valid acknowledgment / Total employees) × 100100%Monthly
Annual Re-Acknowledgment Rate(Employees re-acknowledged on time / Required) × 100100%Annual
Contractor Security Terms Coverage(Contractors with security terms / Total contractors) × 100100%Quarterly
Vendor Security Terms Coverage(Vendors with security terms / Total vendors) × 100100%Quarterly
Security Violation CountNumber of security violationsTrending downMonthly
Sanction Enforcement Rate(Sanctions executed / Violations requiring sanctions) × 100100%Monthly
Sanction Appeal Rate(Appeals filed / Total sanctions) × 100<10%Monthly
Security Training Completion(Employees completing training / Total employees) × 100100%Annual
Employee Understanding ScoreAverage score on security responsibility quiz>80%Annual
Policy Update Communication Rate(Policy updates communicated within 30 days / Total updates) × 100100%Quarterly
Remote Work Addendum Coverage(Remote workers with addendum / Total remote workers) × 100100%Quarterly
BYOD Addendum Coverage(BYOD users with addendum / Total BYOD users) × 100100%Quarterly
Security Responsibility in Performance Reviews(Reviews with security metric / Total reviews) × 100100% for Tier 1-2Annual
Contract Update Compliance(Contract templates updated after policy change / Total policy changes) × 100100%Quarterly
Sanction Records Completeness(Sanctions with full documentation / Total sanctions) × 100100%Monthly
Labor Law Compliance ScoreAudit score for labor law compliance>95%Annual
Acknowledgment Linked to Access(Access renewals requiring acknowledgment / Total renewals) × 100100%Quarterly

Common Pitfalls and How to Avoid Them

#PitfallWhy It HappensHow to Avoid
1Generic security clauseUsing template without customizationCreate role-specific responsibilities and addendums
2No acknowledgment trackingRelying on paper signaturesUse e-signature tools with tracking; integrate with HRIS
3Sanctions not enforcedFear of labor disputes, manager reluctanceDefine clear procedure, train managers, legal review, document everything
4No contractor security termsAssuming contractors are covered by vendorInclude security terms in all contractor agreements; require vendor attestation
5No annual re-acknowledgmentOne-time mindsetAutomated annual reminders; link to access renewal; manager accountability
6Sanctions not legally compliantHR and Legal not involvedLegal review of sanctions; due process; graduated response; documentation
7No remote work/BYOD termsAssuming office terms cover remoteCreate specific remote work and BYOD addendums; require signature before access
8Acknowledgment not linked to accessSiloed HR and IT processesIntegrate HRIS with IAM; block access for expired acknowledgments
9No appeal processEfficiency, assumption of fairnessCreate appeal process; review committee; documented rationale
10Security responsibilities not in performance reviewsSecurity seen as separate from performanceIntegrate security compliance into performance evaluation for relevant roles
11Policy changes not communicatedLack of change management processCreate policy change communication procedure; require re-acknowledgment
12No IP assignment for developersAssumption that employment implies IP ownershipExplicit IP assignment clause; invention disclosure process; patent policy
13No return of assets clauseFocus on hiring, not exitInclude return of assets in all contracts; exit checklist; asset verification
14Unenforceable non-competeCopying foreign templatesReview non-compete under Indian law (Section 27 of Indian Contract Act); focus on confidentiality and NDA
15No contractor re-acknowledgmentAssuming contractor terms are perpetualSet contractor re-acknowledgment schedule; renewal-based
16Ignoring union/labor requirementsNot consulting labor lawConsult Legal and labor experts; ensure standing orders compliance; follow the Industrial Relations Code
17No employee understanding verificationAssuming signature = understandingConduct quizzes, surveys, scenario tests; make training interactive
18Sanctions inconsistent across departmentsDepartmental autonomyCentral sanctions committee; standardized matrix; regular calibration
19No documentation of sanctionsInformal approachDocument every step; maintain records; create audit trail
20No learning from violationsPunitive approach onlyAnalyze violations for root causes; improve policies and controls; share lessons

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SaaS Company, CloudTech Solutions

Company Profile:

  • Size: 280 employees
  • Industry: B2B SaaS, Cloud Infrastructure Management
  • Location: Pune, India
  • Customers: 450 enterprise clients globally
  • Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR

Challenge: CloudTech had grown rapidly from 50 to 280 employees in 2 years but employment terms were outdated:

  • Employment contracts had a generic "comply with company policies" clause with no security specifics
  • No security acknowledgment form; employees signed contract but never specifically acknowledged security responsibilities
  • A senior developer left and joined a competitor, taking proprietary orchestration code (no IP assignment clause enforced)
  • No sanctions for security violations; an employee who shared credentials with a colleague received no formal action
  • Remote work exploded during COVID but no remote work security addendum existed
  • 45 contractors had no security terms in their contracts
  • No annual re-acknowledgment; employees who joined 2 years ago had never revisited security terms
  • A developer used personal laptop for work without BYOD agreement; laptop was infected with malware that spread to company network
  • Performance reviews had no security component; security compliance was not rewarded or penalized

Solution:

  1. Month 1: Contract and Policy Redesign

    • Engaged an external security consultant to redesign employment security terms
    • Created 4-tier security responsibility framework (Critical, High, Medium, Low)
    • Updated employment contract template with detailed security clause
    • Created role-specific security addendums (Developer, Admin, Support, Sales, etc.)
    • Created security acknowledgment form with 15 core responsibilities (employee initials each)
    • Created remote work security addendum
    • Created BYOD security addendum
    • Legal review for Indian labor law compliance and enforceability
  2. Month 2: New Hire Implementation

    • Implemented new contract for all new hires
    • Integrated security acknowledgment into onboarding workflow (Day 1 mandatory)
    • No system access granted until acknowledgment signed (IAM integration)
    • Created onboarding security briefing (30 minutes, mandatory, scored quiz)
    • Trained recruiters on communicating security terms during hiring
  3. Month 3: Existing Employee Retrospective Acknowledgment

    • Deployed annual security acknowledgment to all 280 employees
    • Used DocuSign for electronic signatures with tracking
    • Achieved 98% completion in 30 days
    • For 6 employees who didn't complete: manager follow-up, then HR, then restricted access
    • For 2 employees who refused: Legal review, disciplinary process, eventual termination
  4. Month 4: Contractor and Vendor Updates

    • Updated contractor agreement template with security terms
    • Required 45 existing contractors to sign updated terms
    • Created vendor personnel security addendum for 12 vendors with system access
    • Added security terms to all new vendor contracts
    • Trained procurement on security contract requirements
  5. Month 5: Sanctions and Performance Integration

    • Created graduated sanctions matrix (Minor → Moderate → Major → Critical)
    • Established Sanctions Committee (HR, Legal, CISO, manager)
    • Trained all managers on identifying and reporting violations
    • Integrated security compliance into performance reviews (10% weight for Tier 1-2)
    • Created security champion recognition program (quarterly awards)
    • First sanctions applied: 3 verbal warnings, 2 written warnings, 1 suspension
  6. Month 6: Remote Work and BYOD

    • Required remote work addendum for all 180 remote workers
    • Required BYOD addendum for 85 employees using personal devices
    • Implemented MDM (Microsoft Intune) for BYOD enrollment
    • Created remote work security checklist and self-assessment
    • Conducted remote work security training (1 hour, mandatory)

Results:

  • IP protection: IP assignment clause enforced; 2 patent applications filed by employees with proper assignment
  • Security violations: fewer violations within 6 months
  • Sanctions: Fair and consistent sanctions applied; zero legal challenges
  • Employee understanding: 94% average score on security responsibility quiz (up from 62%)
  • Contractor compliance: 100% of contractors with security terms; no contractor incidents
  • Remote work: Zero remote work-related security incidents in 6 months
  • BYOD: 100% BYOD enrollment in MDM; malware incident prevented through MDM
  • Performance integration: Security compliance became part of culture; 3 employees promoted partly for security excellence

Illustrative Scenario 2: Large Manufacturing Enterprise, Steel India Ltd.

Company Profile:

  • Size: 12,000 employees, 8,500 unionized workers
  • Industry: Steel Manufacturing, Integrated Steel Plant
  • Location: Rourkela, Odisha
  • Operations: 3 steel plants, 15 mines, 8 processing units
  • Regulatory Scope: DPDP Act 2023, OSH Code 2020, Mines Act, Industrial Relations Code, ISO 27001, OHSAS 18001
  • Union: Strong trade union presence; collective bargaining agreement

Challenge: Steel India had complex labor relations and outdated security terms:

  • Employment contracts for 8,500 union workers were governed by collective bargaining agreement (CBA) with no security terms
  • Only 3,500 non-union staff had individual contracts; security terms were generic and unenforced
  • Standing orders had no information security provisions
  • Strong union resistance to any new contractual terms without negotiation
  • OT/ICS (Operational Technology) security was critical but operators had no security obligations in contracts
  • No sanctions for security violations due to union protection and lack of contractual basis
  • A contract worker stole proprietary steel formulation data and sold it to Chinese competitor
  • No IP assignment clause for R&D staff; 2 senior researchers left and filed patents in their own names
  • No return of assets clause; departing employees routinely took laptops, documents, and data
  • CBA renewal was upcoming (every 3 years); security terms had to be negotiated with union

Solution:

  1. Months 1-3: Union Engagement and CBA Negotiation

    • Engaged an external security consultant for labor-law-compliant security terms program
    • Established Security-Labor Relations Committee (management + union representatives)
    • Conducted 12 workshops with union leaders explaining security risks and business impact
    • Presented data: 1 OT security incident could shut down plant for days, affecting 12,000 jobs
    • Negotiated security terms as part of CBA renewal (security as job protection, not surveillance)
    • Agreed on graduated sanctions with union appeal process (grievance mechanism)
    • Union agreed to security terms in exchange for: cybersecurity training as paid work time, security equipment, no surveillance of personal activity
  2. Months 4-6: CBA and Standing Orders Update

    • Updated Standing Orders with information security provisions (work discipline, asset protection, data handling)
    • Created security addendum for CBA (appendix to main agreement)
    • Defined security responsibilities for different worker categories (operators, supervisors, managers, R&D)
    • Created union-approved sanctions matrix (with union representative on sanctions committee)
    • Updated CBA to include: security training as paid time, security equipment provision, whistleblower protection
    • Standing Orders approved by labor commissioner as required
  3. Months 7-9: Non-Union Staff and R&D

    • Updated individual contracts for 3,500 non-union staff with detailed security terms
    • Created IP assignment and invention disclosure process for 450 R&D staff
    • Created patent reward program (union-approved): for filed patent, for granted patent
    • Implemented return of assets clause with exit verification
    • Created NDA for all staff with access to proprietary processes
    • Implemented security acknowledgment for all non-union staff (100% completion)
  4. Months 10-12: Contractor and Vendor Security

    • 4,200 contract workers required to sign security terms (through contractor companies)
    • Contractor companies required to provide security training to their workers
    • Created vendor security terms for 85 critical vendors (equipment, technology, maintenance)
    • Implemented security orientation for all contract workers (15 minutes, paid)
    • Created contractor security violation reporting to contractor company (joint management)
  5. Months 13-15: Training and Culture

    • Security training made mandatory and paid (union requirement)
    • Created plant-specific security scenarios (OT security, physical security, process safety)
    • Created security awareness campaign in Odia and Hindi (local languages)
    • Integrated security into daily toolbox talks (5-minute security tip)
    • Created security suggestion scheme (employee suggestions rewarded)
    • Union representatives became security champions (peer-to-peer messaging)

Results:

  • CBA acceptance: First CBA in Indian manufacturing with complete security terms; became industry reference
  • Security incidents: fewer security incidents within 12 months
  • OT security: Zero OT security incidents; passed critical infrastructure audit
  • IP protection: 3 patents filed with proper assignment; no IP theft incidents
  • Contractor compliance: 100% contract worker security acknowledgment; 1 contractor violation detected and addressed
  • Union relations: Security terms strengthened union-management relationship (shared security goals)
  • efficiency gains: program cost vs. potential plant shutdown cost (+ crore/day) + IP loss
  • Industry recognition: Won FICCI Industrial Security Excellence Award; featured in national labor journal

Multi-Framework Mapping

The references below genuinely overlap with A.6.2. Use them when one set of evidence must satisfy several frameworks.

FrameworkReferenceHow it relates
NIST SP 800-53 Rev 5PS-6 Access agreements; PL-4 Rules of behavior; PS-8 Personnel sanctionsSecurity responsibilities written into agreements and acknowledged
PCI DSS v4.0.112.1.3 (roles and responsibilities acknowledged); 12.6.3 (policy acknowledged at least every 12 months)Personnel know and accept their security responsibilities
SOC 2 (2017 TSC)CC1.1 (integrity and ethical values; code of conduct); CC2.2Responsibilities communicated and accepted
COBIT 2019APO07 Managed human resourcesTerms of employment and contract staff
DPDP Act 2023s.7(i) processing for employment purposes; s.8(5) safeguardsEmployee data handled lawfully and protected
Indian labour lawIndustrial Relations Code 2020 (standing orders); state Shops and Establishments ActsTerms must be consistent with labour law

Regulatory and Industry Context

India Regulatory Framework

RegulationEmployment Terms RequirementPenalty
DPDP Act 2023Employee data processed for employment purposes (s.7(i)); staff handling personal data must follow the safeguards the fiduciary is accountable for (s.8(1), s.8(5))Up to ₹250 crore (failure to take reasonable security safeguards)
IT Act 2000 (Section 43A)Reasonable security practices including personnelCompensation
Companies Act 2013Section 166, director duties; Section 149, independent director requirementsDirector disqualification
RBI Cyber Security FrameworkEmployee security responsibilities in contractsLicense restrictions
SEBI CSCRF (2024)Personnel security terms for trading systemsTrading restrictions
IRDAI GuidelinesEmployee data protection responsibilitiesLicense suspension
POSH Act 2013Employee obligations under POSH policyEmployer liability
OSH Code 2020 (replaced the Factories Act 1948)Worker safety obligations; Standing Orders; imprisonment
Industrial Employment (SO) Act 1946Standing orders including disciplineLabour court disputes
State Shops and Establishments ActsConditions of employment for shops and offices (still state laws)Penalties under the state Act
Industrial Relations Code 2020 (formerly ID Act 1947)Unfair dismissal protections; due processReinstatement, back wages
OSH Code 2020 (replaced the Contract Labour Act 1970)Contract worker terms and conditionsPenalties
Code on Wages 2019 (replaced the Minimum Wages Act 1948)Terms must include minimum wage compliancePenalties
Code on Social Security 2020 (replaced the EPF Act 1952)Terms must include EPF contributionsProsecution
ESI Act 1948Terms must include ESI coverageProsecution

International Regulations

RegulationEmployment Terms Requirement
GDPR (EU)Article 28, processor personnel; Article 32, security measures including personnel
HIPAA (US)§164.308(a)(3)(ii)(A), Workforce security; §164.308(a)(3)(ii)(C), Termination procedures
SOX (US)Internal controls including personnel accountability
FCRA (US)Background check disclosure and authorization
UK Employment Rights Act 1996Written statement of particulars including policies
EU Whistleblower DirectiveProtection for employees reporting violations
ILO ConventionWorker rights and protections

Sector-Specific Requirements

SectorEmployment Terms-Specific Requirements
BFSIRBI employee background and integrity requirements; SEBI dealer registration; fiduciary duties; in-term restrictions and confidentiality for traders
HealthcareClinical staff confidentiality; DPDP duties for health data; NABH standards where accredited
TelecomDOT security clearance for network personnel; subscriber data confidentiality; lawful interception obligations
Manufacturingstanding orders under the Industrial Relations Code; union CBA security terms; OT security operator obligations; safety + security integration
GovernmentOfficial Secrets Act obligations; security clearance; service rules; conduct rules; CVC guidelines
DefenceSecurity clearance; foreign contact reporting; side business disclosure; Official Secrets Act; export control
AviationDGCA security training requirements; substance testing; background verification; airside access obligations
EducationStudent data confidentiality; POCSO obligations; teacher conduct rules; child safety obligations
SaaS / B2BCustomer data confidentiality; SOC 2 personnel requirements; developer IP assignment; remote work terms
E-commerceCustomer data handling; payment data access; delivery personnel verification; warehouse security

Roles and Responsibilities (RACI)

ActivityAccountableResponsibleConsultedInformed
Security Terms PolicyCISOHR HeadLegalBoard
Contract Template UpdatesLegalHRCISOManagement
Role Responsibility DefinitionCISOSecurity ManagerHR, Hiring ManagerEmployees
Acknowledgment ProcessHRHR AdminCISO, ITEmployees
Annual Re-AcknowledgmentHRHR AdminCISOEmployees, Managers
Sanctions MatrixCISOSecurity ManagerHR, LegalManagement
Sanctions EnforcementHRHR ManagerCISO, Legal, ManagerEmployee
Appeal ProcessLegalHR HeadCISOEmployee, Board
Remote Work AddendumCISOHRLegal, ITEmployees
BYOD AddendumCISOITHR, LegalEmployees
Contractor Security TermsLegalProcurementCISO, HRContractors
Vendor Security TermsLegalContract ManagerCISO, ProcurementVendors
Performance IntegrationHRHR ManagerCISO, ManagerEmployees
Training on ResponsibilitiesCISOTraining TeamHREmployees
Policy Change CommunicationCISOHRLegalAll Employees
Union NegotiationLegalHR HeadCISOUnion, Board
Standing Orders UpdateLegalHRCISOLabor Department
Record ManagementHRHR AdminCISOCompliance
Metrics and ReportingCISOHR AnalystComplianceBoard
Audit and ComplianceInternal AuditHR, CISOLegalBoard

Documentation and Evidence Requirements

Required Documents

DocumentOwnerRetention PeriodFormat
Employment Security Terms PolicyCISO7 yearsPDF + Word
Employment Contract TemplatesLegal7 yearsWord + PDF
Role-Specific Security AddendumsCISO7 yearsWord + PDF
Security Acknowledgment FormsHR7 yearsSigned forms / digital
Remote Work AddendumHR7 yearsSigned forms / digital
BYOD AddendumHR7 yearsSigned forms / digital
IP Assignment ClausesLegal20 yearsContract extracts
NDA RecordsLegal7 yearsSigned forms / digital
Sanctions MatrixCISO7 yearsDocument
Sanction RecordsHR7 yearsCase files
Appeal RecordsLegal7 yearsCase files
Annual Re-Acknowledgment RecordsHR7 yearsDigital records
Policy Update CommunicationCISO3 yearsEmail / portal records
Training Completion RecordsHR5 yearsLMS records
Performance Review RecordsHR5 yearsPerformance system
CBA Security Terms (if applicable)LegalDuration of CBA + 7 yearsAgreement PDF
Standing OrdersLegal7 yearsApproved document
Contractor Security TermsLegalDuration of contract + 3 yearsContracts
Vendor Security TermsLegalDuration of contract + 3 yearsContracts
Union Negotiation RecordsLegal7 yearsMeeting minutes
Audit EvidenceInternal Audit5 yearsAudit reports

Continuous Improvement

Maturity Model (Level 1-5)

LevelNameDescription
1InitialGeneric contract clause; no acknowledgment; no sanctions; no records
2ManagedSecurity clause in all contracts; basic acknowledgment; informal sanctions; paper records
3DefinedRole-specific responsibilities; formal acknowledgment; graduated sanctions; annual re-acknowledgment; contractor terms; performance integration
4Quantitatively ManagedAutomated acknowledgment tracking; IAM integration; metrics-driven; remote/BYOD addendums; union compliance; dynamic updates
5OptimizingAI-driven responsibility personalization; predictive compliance; behavioral analytics; integrated security culture; continuous improvement; industry leadership

Improvement Cycle

  • Plan: Annual review of terms; quarterly metrics; regulatory change monitoring; industry benchmarking
  • Do: Update contracts; deploy new tools; train managers; enhance sanctions; improve communication
  • Check: Measure understanding; audit enforcement; benchmark; gather feedback; review disputes
  • Act: Standardize; communicate; update procedures; report to management; share best practices
  • Dynamic Contracts: AI-generated role-specific contract terms based on access and risk
  • Blockchain Acknowledgment: Immutable acknowledgment records for audit and legal evidence
  • Behavioral Analytics: Predicting compliance risk based on behavior patterns
  • Continuous Acknowledgment: Real-time policy acknowledgment as policies change
  • Natural Language Contracts: Simplified contract language for better employee understanding
  • Gamified Compliance: Engagement-driven acknowledgment and training
  • Union-Tech Platforms: Digital platforms for union-management security collaboration

FAQ

Frequently Asked Questions (20 Questions)

Q1: Are security terms enforceable in Indian employment contracts? A: Yes, if they are reasonable, clearly communicated, and comply with labor law. They cannot violate fundamental labor rights. Sanctions must be proportionate and follow due process.

Q2: Can we terminate an employee for a security violation? A: Yes, for serious violations, but you must follow due process: show cause notice, inquiry, opportunity to defend, reasoned order. For critical violations (theft, sabotage), immediate suspension is possible pending inquiry. Consult Legal.

Q3: Do security terms apply to unionized workers? A: Yes, but they may need to be negotiated through collective bargaining or included in standing orders. Unilateral changes may be challenged. Engage union early and frame security as job protection.

Q4: What if an employee refuses to sign the security acknowledgment? A: You can withhold system access and escalate to HR and Legal. If they continue to refuse, disciplinary action up to termination may be warranted (subject to due process). Document all steps.

Q5: Can we change security terms without employee consent? A: For non-union employees, you can update terms with reasonable notice (typically 30 days) if the contract allows. For union employees, changes may require negotiation. Always provide notice and re-acknowledgment.

Q6: Are non-compete clauses enforceable in India? A: Section 27 of the Indian Contract Act generally renders non-compete clauses void as restraint of trade. However, courts have enforced reasonable confidentiality and non-solicitation clauses. Focus on NDA and IP protection rather than non-compete.

Q7: Do we need separate security terms for remote workers? A: Yes. Remote work introduces unique risks (home environment, personal networks, family access). A specific remote work addendum should address workspace security, VPN use, device security, and data handling at home.

Q8: Can contractors be held to the same security terms as employees? A: Yes, through contractor agreements. However, enforcement mechanisms differ. Ensure contractor agreements have clear security terms, and require contractor companies to enforce them. Joint liability can be structured.

Q9: What should be in a BYOD addendum? A: Device registration, encryption requirement, MDM enrollment, approved apps, data separation, remote wipe authorization, no jailbreak/root, OS updates, and data transfer restrictions.

Q10: How do we handle security terms for international employees? A: Comply with local labor law in each country. Security terms should be globally consistent but locally compliant. Use local legal counsel for contract review. Data protection terms must comply with local privacy law (GDPR, etc.).

Q11: Can we include security responsibilities in the offer letter? A: Yes, offer letters can include a summary of security responsibilities with a reference to the full security policy and acknowledgment form. This sets expectations before the detailed contract.

Q12: What is the difference between a security policy and security terms in a contract? A: The security policy defines what the organization requires. The contract terms make compliance a contractual obligation with consequences for breach. Both are needed, the policy educates, the contract enforces.

Q13: Do interns and trainees need security terms? A: Yes, if they have access to information or systems. Use simplified terms appropriate to their role and duration. Include confidentiality obligations and return of assets.

Q14: How do we handle security terms for board members? A: Board members should sign NDAs and confidentiality agreements. They should acknowledge security responsibilities if they have access to sensitive information. Director agreements under Companies Act should include relevant terms.

Q15: Can we monitor employees based on security terms? A: Yes, but monitoring must be proportionate, transparent, and comply with DPDP Act 2023 and labor law. Employees should be informed of monitoring. Personal monitoring must be minimized. Consult Legal.

Q16: What is a garden leave and when should we use it? A: Garden leave is when an employee remains employed during notice period but does not work. It's useful for sensitive roles to prevent data theft during transition. Must be in contract and complies with labor law.

Q17: Do we need an employment bond for security? A: Indian courts generally enforce only reasonable recovery of genuine training costs (Indian Contract Act s.74); penalty-style bonds are not enforced. For security, focus on enforceable terms (NDA, IP assignment, return of assets) rather than bonds.

Q18: How do we integrate security into performance reviews? A: Define security KPIs (training completion, incident involvement, policy compliance, security suggestions). Include them as 5-10% of performance score for relevant roles. Recognize security excellence.

Q19: What is the role of CISO in employment security terms? A: CISO defines security responsibilities, sanctions, and policy content. CISO reviews violations, participates in sanctions committee, and ensures security terms are technically enforceable.

Q20: What will an ISO 27001 auditor look for in A.6.2? A: The auditor will verify: (1) security responsibilities are in employment contracts, (2) responsibilities are communicated to employees, (3) employees acknowledge responsibilities, (4) sanctions are defined, (5) sanctions are applied when appropriate, (6) contractor terms exist, (7) records are maintained, and (8) the program is reviewed.


References and Further Reading

ISO Standards

  • ISO 27001:2022: Information Security Management Systems
  • ISO 27002:2022: Information Security Controls
  • ISO 27701:2019: Privacy Information Management System
  • ISO 27036: Information Security for Supplier Relationships

Indian Law

  • Indian Contract Act 1872: Section 27 (restraint of trade)
  • Industrial Relations Code 2020 (standing orders; replaced the Industrial Employment (Standing Orders) Act 1946)
  • Industrial Relations Code 2020 (replaced the Industrial Disputes Act 1947)
  • OSH Code 2020 (replaced the Factories Act 1948)
  • Shops and Establishments Act (state-specific)
  • Companies Act 2013: Director duties, DIN
  • DPDP Act 2023: Data protection obligations
  • IT Act 2000: Reasonable security practices
  • POSH Act 2013: Employee obligations
  • OSH Code 2020 (replaced the Contract Labour Act 1970)
  • Code on Wages 2019 (replaced the Minimum Wages Act 1948)
  • Code on Social Security 2020 (replaced the EPF Act 1952)
  • ESI Act 1948

International

  • GDPR (EU): Articles 5, 28, 32
  • HIPAA (US): §164.308(a)(3)**, Workforce security
  • SOX (US): Internal controls
  • UK Employment Rights Act 1996
  • EU Whistleblower Directive
  • ILO Conventions: Worker rights

Industry

  • NASSCOM: IT industry employment practices
  • ISACA: Security and governance guidance
  • CII: Industrial employment practices
  • FICCI: Business and employment law

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.