ISO 27001 Annex A.6 People Controls

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Eight controls covering the human element of the ISMS: screening, contractual obligations, awareness and training, disciplinary process, post-employment obligations, NDAs, remote work, and event reporting. Smallest theme by control count; the human element is consistently the largest breach-cause category, so the controls' weight is disproportionate to their number.

How to read this atom

Each control listed below has its reference number and title from ISO 27001:2022 Annex A. Notes cover purpose, typical implementation, common evidence, SRE / AI-agent fit notes.

No new controls in A.6 in :2022 (consolidations from :2013's A.7 People + parts of A.13).

A.6.1 Screening

Background verification of candidates for employment, contractors, and third-party users proportionate to the role, the access to be granted, and the classification of information they will handle. Re-screening at planned intervals for sensitive roles.

Common practice: identity verification, right-to-work check, reference checks, criminal-record check (jurisdiction-dependent), credit check (for roles handling financial systems), social media review (more contested).

Evidence: screening procedure, sample of completed screenings (redacted), supplier flow-down to background-screening provider.

A.6.2 Terms and conditions of employment

Employment contracts state the employee's and the org's responsibilities for information security. Confidentiality clauses, acceptable use commitments, post-termination obligations, IP assignment.

Evidence: contract template, signed contracts, clause-tracking.

A.6.3 Information security awareness, education and training

Personnel receive appropriate awareness, education, and training. Onboarding plus periodic refreshers plus role-targeted modules.

Mirrors Cl 7.2 (competence) and Cl 7.3 (awareness).

AI-agent fit: awareness for AI tool use (acceptable inputs, output trust calibration, prompt-injection recognition), training for engineers building AI features (OWASP LLM Top 10, secure prompting, tool-scope design, output validation), executive awareness on AI risk (model-vendor relationships, customer-facing AI accountability, AI Act obligations).

Evidence: training curriculum mapped to roles, completion records, refresher cadence, content currency (when was the AI-awareness module last updated?), effectiveness measurement (phishing click rate, knowledge test scores, observed behavior).

A.6.4 Disciplinary process

Formal disciplinary process for personnel committing a security breach. Communicated, documented, applied consistently.

Evidence: disciplinary procedure, HR-side records (typically not auditor-accessible at individual level; statistical summary suffices).

A.6.5 Responsibilities after termination or change of employment

Responsibilities and duties that remain valid post-termination or after a role change. Confidentiality, non-disclosure, return of assets (A.5.11), access removal.

Common gap: long-tail post-termination obligations not communicated. Auditor may interview a recently-promoted internal-mover and ask whether they know which of their previous-role obligations still apply.

A.6.6 Confidentiality or non-disclosure agreements

NDAs identified, documented, regularly reviewed, signed by personnel and parties as needed.

Common shapes: employee NDA (in contract), contractor NDA (separate document), customer NDA (per engagement), supplier NDA (in supplier contract or standalone).

A.6.7 Remote working

Security measures for remote work: equipment security, network security (VPN, ZTNA), data-handling rules in home / non-office environments, physical security of home workspace, family / household considerations.

AI-agent fit: BYO-machine considerations. If employees use personal devices for any AI tool access, the security boundary becomes ambiguous. Common implementation: managed devices only for confidential-or-higher data; defined posture requirements (encryption at rest, OS patching cadence, EDR coverage); session-level controls (MFA, conditional access, agent API key scope).

Evidence: remote working policy, equipment provisioning records, posture-check telemetry, secure-network-access architecture description.

A.6.8 Information security event reporting

Reporting channels for security events. Whistleblower-style accessibility, anonymous reporting option, clear escalation paths, no-blame culture for genuine reports.

Evidence: reporting channel documented, awareness materials referencing it, event-log showing reports flowing in, response-time metrics.

SRE and AI-agent quick map (load-bearing A.6 controls)

ConcernPrimary A.6 controls
Engineer competence for AI-system workA.6.3
Acceptable use of AI toolsA.6.2 (in contract), A.6.3 (in awareness)
Remote / hybrid security postureA.6.7
Joiner-mover-leaver for human + agent identitiesA.6.1, A.6.5, A.5.16, A.5.18
Security event reporting (incl AI-system anomalies)A.6.8

Common audit observations

  • Awareness is generic. Same module for engineers, sales, HR. Tailored content expected.
  • AI-specific training absent. Companies that ship AI features without role-targeted AI security training are increasingly flagged in 2025+ audits.
  • Re-screening cadence missed. Sensitive roles (admin, finance, security team) screened at hiring, never again. Recommended cadence: 3-5 years for sensitive roles.
  • Remote working policy outdated. Pre-pandemic policy with strict office-only-confidential rules, never updated to match remote-first reality. Either the policy is being followed and the business is unworkable, or the business has overridden it and the policy is fictional.

Stefan-context implementation sketch

  • Screening: self-applicable for solo work; for client work, screening commitments flow from client side and are honored.
  • Terms and conditions: client engagement letters carry the equivalent obligations (confidentiality, IP, post-engagement).
  • Awareness / training: continuous self-development; UTT course progress is evidence of competence currency.
  • Remote working: 100% remote across Macbook (canonical), Mac Studio (incoming retrieval router), [host] (build host), AWS headscale (control plane). Network security via headscale + Tailscale; device posture per Macbook security defaults plus FileVault, Secure Enclave, MFA on critical accounts.
  • Event reporting: self-reporting to bd. For client work, channels documented per engagement.

See also