In practice this is a line or clause in the employment contract or an attached acceptable-use agreement that spells out security obligations before the person starts, not a generic mention that security matters. Auditors ask to see a signed copy for a recently hired employee and check whether the obligations referenced there match what the person is held to, such as confidentiality after departure or acceptable use of company systems. The common gap is a template clause drafted once by legal that nobody has updated to reflect current policy, so the contract and the security policy have drifted apart.
Common gaps
The employment contract references company security policies generically without naming which document or version the employee agreed to.
Contractors and temporary staff sign a different, older agreement that was never updated when the employee security clauses changed.
No one can produce a signed acknowledgement for employees hired more than a year ago, only for recent hires.
Questions your auditor will ask
What security obligations does an employment contract specify?
A signed clause or attachment naming confidentiality, acceptable use and applicable policies, matched to the version of the policy currently in force.
Do contractors sign the same security terms as employees?
Contractor agreements carry equivalent security clauses, reviewed against the same policy version employees are held to.
Can you show a signed acknowledgement for a recently hired employee?
A signed contract or onboarding acknowledgement on file, dated at or before the employee's start date.
Where regulation demands it
NIS2 10.1 requires human resources security measures, which start with security terms written into the employment relationship itself.
ENS org.1 requires a written security policy, the same policy staff are contractually bound to accept under A.6.2.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.