3.3 People Controls (Theme 6)
Key Takeaways
- Theme 6 contains 8 human-centric security controls governing the entire employment lifecycle: pre-employment screening, employment terms, ongoing awareness, disciplinary procedures, offboarding, NDAs, remote working, and privacy.
- Control 6.3 (Information Security Awareness, Education, and Training) mandates role-based, continuous training and empirical verification of effectiveness (e.g., phishing simulation metrics).
- Control 6.5 (Responsibilities After Termination or Change of Employment) requires strict offboarding protocols, including immediate credential revocation and physical asset recovery upon termination.
- Control 6.7 (Remote Working) addresses teleworking risks, requiring robust remote access protocols, endpoint security, and home office environmental guidelines.
ISO/IEC 27001:2022 Theme 6: People Controls
Auditor Focus: Theme 6 comprises 8 controls (Controls 6.1 through 6.8) designed to manage human risk across all stages of employment and contracting. Lead auditors must assess how human resource security policies are integrated with technical access control, legal agreements, and corporate culture.
1. The Employment Lifecycle & People Controls Architecture
Human error and insider threats remain primary root causes of information security breaches. Theme 6 structures security expectations into three temporal employment phases plus operational working models and privacy considerations.
+-----------------------------------------------------------------------------------+
| THEME 6: PEOPLE CONTROLS (8) |
+-----------------------------------------------------------------------------------+
| PRE-EMPLOYMENT ---> 6.1 Screening |
| DURING EMPLOYMENT ---> 6.2 Terms & Conditions | 6.3 Awareness & Training |
| 6.4 Disciplinary Process |
| POST-EMPLOYMENT ---> 6.5 Termination Responsibilities | 6.6 NDAs |
| WORKING MODELS ---> 6.7 Remote Working |
| DATA PRIVACY ---> 6.8 Privacy and Protection of PII |
+-----------------------------------------------------------------------------------+
2. In-Depth Analysis of Theme 6 Controls
Control 6.1: Screening
- Background verification checks on all candidates for employment must be carried out in accordance with relevant laws, regulations, and ethics.
- Checks must be proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.
- Auditor Verification: Sample HR onboarding files for high-privilege roles (e.g., System Administrators, Database Administrators) to verify criminal background checks, identity verification, and credential validation were completed prior to granting system access.
Control 6.2: Terms and Conditions of Employment
- Contractual agreements with employees and contractors must state their responsibility for information security.
- Must specify obligations regarding policy adherence, code of conduct, and legal responsibilities.
Control 6.3: Information Security Awareness, Education and Training
- Personnel of the organization and relevant contractors must receive appropriate security awareness, education, and training, as well as regular updates in organizational policies.
- Modern auditors differentiate between general awareness (e.g., annual compliance e-learning) and role-based specialized training (e.g., secure coding for developers, social engineering defense for wire transfer personnel).
- Effectiveness Metrics: Auditors look for quantitative tracking—phishing simulation click-through rates, quiz scoring benchmarks, and remedial training triggers for repeat clickers.
+-----------------------------------------------------------------------------------+
| ROLE-BASED TRAINING FRAMEWORK (6.3) |
+-----------------------------------------------------------------------------------+
| General Staff ---> Phishing, Password Hygiene, Clean Desk, Social Eng. |
| Software Developers ---> Secure Coding (OWASP Top 10), SAST/DAST, Code Review |
| System Admins ---> Hardening baselines, Privileged IAM, Incident Response |
| Executive Leadership---> Spear Phishing, Crisis Comm, Supply Chain Risk |
+-----------------------------------------------------------------------------------+
Control 6.4: Disciplinary Process
- A formal, communicated disciplinary process must be in place to take action against personnel who have committed an information security violation.
- Auditors verify that security incidents caused by willful negligence lead to documented HR disciplinary reviews, preventing selective enforcement.
Control 6.5: Responsibilities After Termination or Change of Employment
- Information security responsibilities and duties that remain valid after termination or change of employment must be defined, enforced, and communicated.
- Offboarding Checklist: Requires automated or strictly audited workflows for:
- Revocation of logical access accounts (IAM, Single Sign-On, VPN) within defined SLA (e.g., 24 hours of termination).
- Retrieval of physical assets (laptops, security badges, hardware tokens).
- Conduct of exit interviews reinforcing post-employment confidentiality obligations.
Control 6.6: Confidentiality or Non-Disclosure Agreements (NDAs)
- NDAs reflecting the organization’s needs for the protection of information must be identified, documented, regularly reviewed, and signed by personnel and external parties.
Control 6.7: Remote Working
- Security measures must be implemented when personnel are working remotely to protect information accessed, processed, or stored outside organizational premises.
- Key elements evaluated by lead auditors:
- Mandatory use of central managed Virtual Private Networks (VPN) or Zero Trust Network Access (ZTNA) with Multi-Factor Authentication (MFA).
- Prohibition of local unencrypted storage on personal devices (BYOD policy enforcement).
- Physical privacy controls (e.g., privacy screens, secure storage for printed paper at home offices).
Control 6.8: Privacy and Protection of PII (Personally Identifiable Information)
- The organization must ensure privacy and protection of PII as required in applicable laws and regulations and contractual requirements.
- Requires alignment between ISMS controls and global privacy regulations (e.g., GDPR, CCPA, HIPAA).
- Auditors review Data Inventory / Mapping, Privacy Impact Assessments (PIAs), Data Protection Officer (DPO) involvement, and Subject Access Request (SAR) handling procedures.
3. Human Resource Security Lifecycle Audit Guide
| Employment Phase | Target Control | Key Audit Artifacts | Audit Sampling Method |
|---|---|---|---|
| Pre-Employment | 6.1 Screening | Onboarding policy, background check consent forms, verification logs. | Sample 10 recent hires (5 general, 5 privileged); verify background checks completed prior to start date. |
| During Employment | 6.3 Training | LMS completion logs, phishing simulation metrics, training slides. | Verify 100% completion of annual training; inspect phishing fail-rates and remedial actions. |
| During Employment | 6.7 Remote Work | Remote work policy, MDM compliance logs, split-tunneling VPN config. | Check 10 remote endpoints; verify disk encryption (BitLocker/FileVault) and active EDR agent. |
| Post-Employment | 6.5 Offboarding | HR termination logs, Active Directory disablement timestamps, asset return forms. | Sample 5 recently terminated employees; compare HR termination timestamp against IAM account disablement timestamp (SLA < 24h). |
| Ongoing Privacy | 6.8 Privacy/PII | Privacy notices, PII register, Consent logs, Data Retention schedules. | Inspect PII database schemas; verify data minimization and encryption at rest. |
4. Lead Auditor Worked Scenario
Scenario Background
Lead Auditor Sophia is conducting a Stage 2 audit at Global Health Data Inc., a medical technology firm managing patient health portals. The workforce is 80% remote.
Audit Observations & Evidence Gathering
-
Offboarding Verification (Control 6.5):
- Sophia requests HR termination logs for the past 6 months and selects 5 employees to sample.
- For Employee X (a senior DevOps engineer terminated on March 12th), HR recorded offboarding completion on March 12th.
- However, Active Directory and AWS IAM audit logs reveal Employee X's cloud admin credentials remained active until March 18th (6 days post-termination), during which 14 git commits and login sessions occurred.
-
Security Awareness & Phishing (Control 6.3):
- Global Health Data runs quarterly phishing simulations.
- The Q1 simulation report showed a 22% employee failure rate (clicked malicious links). However, no follow-up training was assigned to clickers, and executive management was excluded from phishing campaigns entirely.
-
Remote Working & PII (Control 6.7 & 6.8):
- During remote staff interviews, Sophia discovered that customer support staff handling patient PII were permitted to print medical records at home without logging or shredding requirements.
Nonconformities Issued by Sophia
- Major Nonconformity against Control 6.5 & Clause 9.1 (Termination & Monitoring): Failure to revoke privileged cloud access for a terminated DevOps engineer for 6 days post-employment resulted in unauthorized post-termination system access, demonstrating a critical failure of offboarding controls.
- Minor Nonconformity against Control 6.3 (Awareness & Training): Security awareness campaigns excluded executive management and failed to implement remedial training for employees who failed phishing simulations.
- Major Nonconformity against Control 6.7 & 6.8 (Remote Work & PII Protection): Allowing remote personnel to print unencrypted patient PII at home without physical security guidelines or disposal mechanisms violates remote working and privacy controls.
During an audit of Control 6.5 (Responsibilities after termination or change of employment), an auditor compares HR termination records with Active Directory disablement logs. Which finding constitutes a Major Nonconformity?
How should an organization demonstrate the effectiveness of its security awareness program under Control 6.3?
Control 6.7 (Remote working) requires specific safeguards for teleworking environments. Which combination of technical controls best supports compliance for remote employees accessing sensitive financial records?