3.7 People Controls: Screening, Awareness & Remote Working (A.6.1–A.6.8)
Key Takeaways
- Annex A Theme 6 consists of 8 People controls governing the human element across all phases of the employment lifecycle.
- Control A.6.1 mandates background screening proportional to business risk, data sensitivity, and role privileges, compliant with local privacy laws.
- Control A.6.3 requires ongoing security awareness, education, and role-based training evaluated through practical behavioral metrics (e.g., phishing reporting rates).
- Control A.6.7 (Remote Working) mandates robust policies, device encryption, zero-trust network access, and physical safeguards for mobile and home office environments.
- Control A.6.8 mandates accessible security event reporting mechanisms that foster a no-blame culture to encourage immediate incident disclosure.
3.5 People Controls: Screening, Awareness & Remote Working (A.6.1–A.6.8)
Human factors, social engineering tactics, and insider threats represent significant attack vectors targeting enterprise environments. Clause A.6 (People Theme) contains 8 essential controls designed to ensure that personnel are trustworthy, educated, aware of security obligations, and equipped to operate securely throughout the employment lifecycle.
Overview of Annex A Theme 6 (People Controls)
| Control ID | Control Name | Lifecycle Phase | Core Lead Implementer Objective |
|---|---|---|---|
| A.6.1 | Screening | Pre-Employment | Perform background checks proportional to business risk and data access level. |
| A.6.2 | Terms and conditions of employment | Employment Start | Incorporate explicit security obligations into employment contracts. |
| A.6.3 | Information security awareness, education & training | During Employment | Deliver continuous awareness and role-specific training evaluated by behavioral metrics. |
| A.6.4 | Disciplinary process | During Employment | Establish a formal framework to address security policy violations consistently. |
| A.6.5 | Responsibilities after termination or change | Termination / Transfer | Manage prompt access revocation, asset return, and post-employment duties. |
| A.6.6 | Confidentiality or non-disclosure agreements | Full Lifecycle | Enforce legally binding NDAs protecting sensitive information assets. |
| A.6.7 | Remote working | Operational / Mobile | Secure teleworking environments, remote endpoints, and mobile communications. |
| A.6.8 | Information security event reporting | Operational / Daily | Establish channels for personnel to report security weaknesses, events, and incidents. |
Pre-Employment Screening & Employment Terms (A.6.1 & A.6.2)
Background Screening (A.6.1)
Verification checks must be conducted on all candidates for employment, contracting, or third-party roles prior to granting access to organizational assets. Screening must comply with local privacy regulations (e.g., GDPR, local labor laws) and be proportional to the role's risk profile:
- Standard Roles: Identity verification, educational credential confirmation, previous employment history verification, and character references.
- Privileged / High-Risk Roles (System Administrators, Financial Officers, C-Suite): Criminal background checks, credit/financial background checks (where legally permissible), and advanced vetting.
Terms and Conditions of Employment (A.6.2)
Employment contracts must explicitly state that personnel are obligated to adhere to all ISMS policies. Security responsibilities must extend beyond normal office hours and continue after employment terminates.
Security Awareness, Education & Training (A.6.3)
Control A.6.3 mandates that all personnel receive appropriate awareness, education, and training tailored to their organizational responsibilities.
+-------------------------------------------------------------------------+
| AWARENESS & EDUCATION PROGRAM SPECTRUM (A.6.3) |
+-------------------------------------------------------------------------+
[General Onboarding] --> Password hygiene, phishing defense, clean desk.
[Periodic Refresher] --> Annual compliance reviews, policy updates.
[Role-Based Training]--> Developers (OWASP Top 10), Sysadmins (Hardening),
Finance (BEC fraud defense), Executives.
[Behavioral Testing]--> Simulated phishing campaigns, social engineering.
Measuring Awareness Program Effectiveness
Lead Implementers must evaluate training programs using empirical behavioral metrics rather than simple attendance records:
- Reduction in simulated phishing email click-through rates.
- Increase in the percentage of simulated phishing emails reported to the SOC.
- Decrease in security incidents caused by human error.
Disciplinary Process & Post-Employment Obligations (A.6.4 & A.6.5)
Disciplinary Process (A.6.4)
A formal, communicated disciplinary process must exist to handle security policy violations. The process must fairly distinguish between:
- Unintentional Errors: Addressed through mandatory re-education and retraining.
- Negligence: Addressed through formal written warnings or performance improvement plans.
- Willful Malicious Misconduct: Escalated to immediate termination, legal action, or law enforcement referral.
Post-Employment Access Revocation (A.6.5)
Upon employee termination or role change:
- All logical access permissions must be revoked immediately on or before the final working day.
- All physical assets (laptops, badges, tokens, keys) must be returned under Control A.5.11.
- Post-employment NDA obligations (A.6.6) must be formally re-acknowledged during exit interviews.
Deep-Dive: Remote Working & Mobile Policies (A.6.7)
Control A.6.7 governs security controls for remote working environments (home offices, travel, coffee shops). The Lead Implementer must establish a Remote Working Policy detailing:
- Physical Workspace Security: Clean desk and clear screen controls; preventing family members or unauthorized bystanders from viewing corporate screens.
- Endpoint Encryption & MDM: Mandatory full-disk encryption (BitLocker, FileVault), centralized Mobile Device Management (MDM), and remote-wipe capabilities.
- Secure Network Communications: Mandatory connection via encrypted VPN or Zero Trust Network Access (ZTNA) with MFA enforced; prohibiting untrusted public Wi-Fi without encryption.
- Bring Your Own Device (BYOD) Rules: Containerization of corporate applications on personal mobile devices to prevent data leakage into personal storage.
Security Event & Weakness Reporting (A.6.8)
Control A.6.8 mandates that personnel report observed or suspected security weaknesses, anomalies, or incidents immediately through designated SOC channels. Organizations must foster a no-blame culture for accidental slip-ups to encourage immediate disclosure before minor vulnerabilities escalate into major data breaches.
An employee working remotely from a public coffee shop leaves their company laptop unlocked while stepping away to order a drink. An unauthorized person accesses confidential customer files on the screen. Which two ISO/IEC 27001 controls were breached in this scenario?
Before granting a candidate access to critical financial ledgers, an organization verifies their identity, previous employment history, academic credentials, and criminal record. Under which control is this pre-employment verification performed?
An organization wants to evaluate the real-world effectiveness of its security awareness training program under Control A.6.3. Which metric provides the MOST direct evidence of behavioral improvement among employees?