A.6.2Terms and conditions of employment
Set out information security responsibilities in employment contracts and agreements, so staff understand their obligations from day one.
A.6.2 is covered by 1 Sekit CSF control. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
In practice
In practice this is a line or clause in the employment contract or an attached acceptable-use agreement that spells out security obligations before the person starts, not a generic mention that security matters. Auditors ask to see a signed copy for a recently hired employee and check whether the obligations referenced there match what the person is held to, such as confidentiality after departure or acceptable use of company systems. The common gap is a template clause drafted once by legal that nobody has updated to reflect current policy, so the contract and the security policy have drifted apart.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.