3.7 People Controls: Screening, Awareness & Remote Working (A.6.1–A.6.8)

Key Takeaways

  • Annex A Theme 6 consists of 8 People controls governing the human element across all phases of the employment lifecycle.
  • Control A.6.1 mandates background screening proportional to business risk, data sensitivity, and role privileges, compliant with local privacy laws.
  • Control A.6.3 requires ongoing security awareness, education, and role-based training evaluated through practical behavioral metrics (e.g., phishing reporting rates).
  • Control A.6.7 (Remote Working) mandates robust policies, device encryption, zero-trust network access, and physical safeguards for mobile and home office environments.
  • Control A.6.8 mandates accessible security event reporting mechanisms that foster a no-blame culture to encourage immediate incident disclosure.
Last updated: July 2026

3.5 People Controls: Screening, Awareness & Remote Working (A.6.1–A.6.8)

Human factors, social engineering tactics, and insider threats represent significant attack vectors targeting enterprise environments. Clause A.6 (People Theme) contains 8 essential controls designed to ensure that personnel are trustworthy, educated, aware of security obligations, and equipped to operate securely throughout the employment lifecycle.


Overview of Annex A Theme 6 (People Controls)

Control IDControl NameLifecycle PhaseCore Lead Implementer Objective
A.6.1ScreeningPre-EmploymentPerform background checks proportional to business risk and data access level.
A.6.2Terms and conditions of employmentEmployment StartIncorporate explicit security obligations into employment contracts.
A.6.3Information security awareness, education & trainingDuring EmploymentDeliver continuous awareness and role-specific training evaluated by behavioral metrics.
A.6.4Disciplinary processDuring EmploymentEstablish a formal framework to address security policy violations consistently.
A.6.5Responsibilities after termination or changeTermination / TransferManage prompt access revocation, asset return, and post-employment duties.
A.6.6Confidentiality or non-disclosure agreementsFull LifecycleEnforce legally binding NDAs protecting sensitive information assets.
A.6.7Remote workingOperational / MobileSecure teleworking environments, remote endpoints, and mobile communications.
A.6.8Information security event reportingOperational / DailyEstablish channels for personnel to report security weaknesses, events, and incidents.

Pre-Employment Screening & Employment Terms (A.6.1 & A.6.2)

Background Screening (A.6.1)

Verification checks must be conducted on all candidates for employment, contracting, or third-party roles prior to granting access to organizational assets. Screening must comply with local privacy regulations (e.g., GDPR, local labor laws) and be proportional to the role's risk profile:

  • Standard Roles: Identity verification, educational credential confirmation, previous employment history verification, and character references.
  • Privileged / High-Risk Roles (System Administrators, Financial Officers, C-Suite): Criminal background checks, credit/financial background checks (where legally permissible), and advanced vetting.

Terms and Conditions of Employment (A.6.2)

Employment contracts must explicitly state that personnel are obligated to adhere to all ISMS policies. Security responsibilities must extend beyond normal office hours and continue after employment terminates.


Security Awareness, Education & Training (A.6.3)

Control A.6.3 mandates that all personnel receive appropriate awareness, education, and training tailored to their organizational responsibilities.

+-------------------------------------------------------------------------+
| AWARENESS & EDUCATION PROGRAM SPECTRUM (A.6.3)                          |
+-------------------------------------------------------------------------+
  [General Onboarding] --> Password hygiene, phishing defense, clean desk.
  [Periodic Refresher] --> Annual compliance reviews, policy updates.
  [Role-Based Training]--> Developers (OWASP Top 10), Sysadmins (Hardening),
                           Finance (BEC fraud defense), Executives.
  [Behavioral Testing]--> Simulated phishing campaigns, social engineering.

Measuring Awareness Program Effectiveness

Lead Implementers must evaluate training programs using empirical behavioral metrics rather than simple attendance records:

  • Reduction in simulated phishing email click-through rates.
  • Increase in the percentage of simulated phishing emails reported to the SOC.
  • Decrease in security incidents caused by human error.

Disciplinary Process & Post-Employment Obligations (A.6.4 & A.6.5)

Disciplinary Process (A.6.4)

A formal, communicated disciplinary process must exist to handle security policy violations. The process must fairly distinguish between:

  • Unintentional Errors: Addressed through mandatory re-education and retraining.
  • Negligence: Addressed through formal written warnings or performance improvement plans.
  • Willful Malicious Misconduct: Escalated to immediate termination, legal action, or law enforcement referral.

Post-Employment Access Revocation (A.6.5)

Upon employee termination or role change:

  • All logical access permissions must be revoked immediately on or before the final working day.
  • All physical assets (laptops, badges, tokens, keys) must be returned under Control A.5.11.
  • Post-employment NDA obligations (A.6.6) must be formally re-acknowledged during exit interviews.

Deep-Dive: Remote Working & Mobile Policies (A.6.7)

Control A.6.7 governs security controls for remote working environments (home offices, travel, coffee shops). The Lead Implementer must establish a Remote Working Policy detailing:

  1. Physical Workspace Security: Clean desk and clear screen controls; preventing family members or unauthorized bystanders from viewing corporate screens.
  2. Endpoint Encryption & MDM: Mandatory full-disk encryption (BitLocker, FileVault), centralized Mobile Device Management (MDM), and remote-wipe capabilities.
  3. Secure Network Communications: Mandatory connection via encrypted VPN or Zero Trust Network Access (ZTNA) with MFA enforced; prohibiting untrusted public Wi-Fi without encryption.
  4. Bring Your Own Device (BYOD) Rules: Containerization of corporate applications on personal mobile devices to prevent data leakage into personal storage.

Security Event & Weakness Reporting (A.6.8)

Control A.6.8 mandates that personnel report observed or suspected security weaknesses, anomalies, or incidents immediately through designated SOC channels. Organizations must foster a no-blame culture for accidental slip-ups to encourage immediate disclosure before minor vulnerabilities escalate into major data breaches.

Test Your Knowledge

An employee working remotely from a public coffee shop leaves their company laptop unlocked while stepping away to order a drink. An unauthorized person accesses confidential customer files on the screen. Which two ISO/IEC 27001 controls were breached in this scenario?

A
B
C
D
Test Your Knowledge

Before granting a candidate access to critical financial ledgers, an organization verifies their identity, previous employment history, academic credentials, and criminal record. Under which control is this pre-employment verification performed?

A
B
C
D
Test Your Knowledge

An organization wants to evaluate the real-world effectiveness of its security awareness training program under Control A.6.3. Which metric provides the MOST direct evidence of behavioral improvement among employees?

A
B
C
D