SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.6.2Terms and conditions of employment

Set out information security responsibilities in employment contracts and agreements, so staff understand their obligations from day one.

Mapping at a glance
A.6.2Terms and conditions of employmentISO/IEC 27001:2022

A.6.2 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

In practice

In practice this is a line or clause in the employment contract or an attached acceptable-use agreement that spells out security obligations before the person starts, not a generic mention that security matters. Auditors ask to see a signed copy for a recently hired employee and check whether the obligations referenced there match what the person is held to, such as confidentiality after departure or acceptable use of company systems. The common gap is a template clause drafted once by legal that nobody has updated to reflect current policy, so the contract and the security policy have drifted apart.

Common gaps

The employment contract references company security policies generically without naming which document or version the employee agreed to.
Contractors and temporary staff sign a different, older agreement that was never updated when the employee security clauses changed.
No one can produce a signed acknowledgement for employees hired more than a year ago, only for recent hires.

Questions your auditor will ask

What security obligations does an employment contract specify?
A signed clause or attachment naming confidentiality, acceptable use and applicable policies, matched to the version of the policy currently in force.
Do contractors sign the same security terms as employees?
Contractor agreements carry equivalent security clauses, reviewed against the same policy version employees are held to.
Can you show a signed acknowledgement for a recently hired employee?
A signed contract or onboarding acknowledgement on file, dated at or before the employee's start date.

Where regulation demands it

NIS2 10.1 requires human resources security measures, which start with security terms written into the employment relationship itself.
ENS org.1 requires a written security policy, the same policy staff are contractually bound to accept under A.6.2.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.6.2?”
Also via MCP, free with account