About this program
Annex A.6 has 8 controls — the people side of ISO 27001. Screening, terms of employment, awareness training, disciplinary process, leaver procedures, NDAs, remote working (NEW), and event reporting. After each answer you can expand an “Auditor’s view” with how the control is tested, what evidence to collect, and the ideal answer.
Controls (8)
-
A.6.1 — Are background screening checks performed on candidates before employment, proportionate to the role?
MediumThis control requires organizations to conduct background verification checks on employment candidates before hiring, with the scope and depth of screening proportionate to the sensitivity of the role, access levels required, and applicable legal requirements. Screening may include identity verification,…
How to test + evidence
Risk: Risk-based screening (more rigorous for sensitive roles) plus periodic refresh for those in privileged positions catches changes that a one-off pre-hire check misses.
Testing procedure: Sample 25 hires from the audit period. For each, request the screening record from HR — verify checks proportionate to the role were completed and dated before the start date.
Evidence to collect: Screening policy with role-based requirements Sample of completed screening reports per hire HR record showing check completion before start date
-
A.6.2 / A.6.6 — Do employment contracts include IS responsibilities and confidentiality / NDA clauses?
MediumThis control ensures that employment contracts and terms of engagement explicitly define information security responsibilities, confidentiality obligations, and non-disclosure requirements for employees, contractors, and third-party personnel. Contracts must specify acceptable use of information assets, consequences of policy violations, and obligations…
How to test + evidence
Risk: Without contractual IS responsibilities you have no enforceable basis for the disciplinary process (A.6.4) or post-termination obligations (A.6.5).
Testing procedure: Request the standard employment contract template + a sample of executed contracts (10–15) covering employees, contractors and interns. Verify NDA + IS responsibilities clauses in each.
Evidence to collect: Standard contract template with IS clauses highlighted Sample of signed contracts across staff types Separate NDAs for contractors / vendors if used
-
A.6.3 — Do all staff receive IS awareness, education and training relevant to their role?
MediumThis control ensures all personnel receive role-appropriate information security awareness training covering organizational policies, acceptable use, threat recognition, incident reporting, and secure working practices. Training programs must be tailored based on job responsibilities, updated regularly to address emerging threats, and…
How to test + evidence
Risk: Continuous training + role-based content moves the dial on behaviour. Annual generic training measurably loses effect within months.
Testing procedure: Request the training matrix and completion report for the audit period. Verify high-risk roles (finance, IT admins, executives) received role-specific training. Sample 10 employees and confirm completion records.
Evidence to collect: Training plan with cadence + role coverage LMS completion report (% complete by role) Sample of training certificates per employee Phishing simulation report if used
-
A.6.4 — Is there a formal disciplinary process for staff who violate IS policy?
MediumThis control requires the organization to establish and document a formal disciplinary process specifically addressing violations of information security policies. The process must define progressive consequences for policy breaches, from verbal warnings to termination, and ensure consistent application across all…
How to test + evidence
Risk: A documented but unused process is fine; auditors don't want to see violations either. The point is that staff know consequences exist and that they're consistent.
Testing procedure: Inspect the disciplinary process document. Verify it explicitly references IS policy violations and includes proportionate consequences. Request anonymised examples of where it has been applied (if any).
Evidence to collect: Disciplinary policy mentioning IS violations Communication record showing policy distributed to staff Anonymised case log (if any disciplinary action taken) HR + legal sign-off on the process
-
A.6.5 — Are responsibilities and duties on termination/change of employment documented and applied?
MediumThis control ensures that when an employee's role changes or their employment terminates, all security-related responsibilities—such as access removal, asset return, knowledge transfer, and confidentiality obligations—are formally documented and systematically executed. Organizations typically maintain termination checklists, update HR and IT…
How to test + evidence
Risk: Same-day, checklist-driven offboarding with NDA reminder closes the most common audit finding in this area: leaver still had access weeks after departure.
Testing procedure: Sample 25 leavers from HR. For each, trace through the exit checklist: equipment returned, access revoked across all systems, NDA reminder, exit interview record. Match dates against termination date.
Evidence to collect: Exit checklist template Sample of completed checklists per leaver Access logs showing same-day disablement Equipment return receipts
-
A.6.7 — Is remote working covered by a documented policy, technical controls and training? (NEW in 2022)
MediumThis control requires organizations to establish and maintain a comprehensive remote working security framework consisting of three pillars: a documented policy defining requirements and responsibilities, technical controls (VPN, endpoint security, MFA, encryption) enforcing those requirements, and training programs ensuring remote…
How to test + evidence
Risk: A.6.7 is new in 2022 and explicitly tested in modern audits. A policy alone isn't enough; auditors look for technical enforcement (MDM, conditional access, VPN posture).
Testing procedure: Inspect the remote-working policy. Verify it covers physical environment (privacy, lock screens), network (no public Wi-Fi without VPN), device (encryption, MDM), and data (no exfil to personal cloud). Sample 5 remote workers and check their laptop config.
Evidence to collect: Remote working policy (current version) MDM enrolment report covering remote devices VPN/ZTNA usage reports Training module content addressing remote-work risks
-
A.6.8 — Do employees know how to report IS events, and is reporting actively encouraged?
MediumThis control ensures that employees are trained and equipped with clear procedures to report information security events, incidents, weaknesses, and potential threats through established channels. Organizations must provide accessible reporting mechanisms (e.g., email aliases, ticketing systems, hotlines), communicate them regularly…
How to test + evidence
Risk: A one-click report button + non-punitive culture surfaces phishing in minutes instead of hours. Most audit findings here are about absent or hostile reporting culture.
Testing procedure: Inspect the reporting channel + supporting training material. Pull a report rate over the audit period; ideally tied to phishing simulations. Confirm leadership communications reinforce a non-punitive culture.
Evidence to collect: Reporting channel screenshot (button / inbox) Triage SLA + sample triaged reports Phishing simulation report rate trend Leadership communication reinforcing reporting
-
Beyond compliance: do staff understand cyber risk well enough to make sensible day-to-day decisions?
MediumThis control evaluates whether staff possess practical cybersecurity risk awareness that enables them to make appropriate security decisions during routine work activities, beyond rote compliance with policies. It assesses whether employees understand the 'why' behind security controls and can apply…
How to test + evidence
Risk: A strong culture is the cheapest, highest-leverage control. Staff who push back on risky requests prevent incidents that no technical control can.
Testing procedure: Run a culture pulse survey or conduct interviews across departments. Ask scenario-based questions ("Finance receives an urgent CEO email asking for a wire transfer — what do they do?"). Cross-reference with phishing simulation results.
Evidence to collect: Culture pulse survey results Interview notes from cross-departmental sample Phishing simulation results per role Examples of staff escalations (positive signal)