People
What every person who works for the organisation is told and agrees to: acceptable use, screening, training, working away from the office, what happens when they leave.
Policy types in this family
9- Acceptable use policy policy
The rules every user of the organisation's information and systems must follow, and what they agree to when they sign in. Required by ISO 27001, NIS2; owner the information security lead (CISO or ISMS manager). - Background screening policy policy
What is verified about a person before they are given access, proportionate to the role, and how the checks are recorded. Required by ISO 27001; owner the head of HR. - Clear desk and clear screen policy policy
The rules for papers, media and unattended screens in the workplace, and what is checked. Required by ISO 27001, ISO 27701; owner the information security lead (CISO or ISMS manager). - Confidentiality and non-disclosure agreement record
The standard confidentiality terms staff, contractors and visitors sign, what they cover and how long they last. Required by ISO 27001, ISO 27701; owner legal or the compliance officer. - Disciplinary process procedure
What happens to a person who breaks a security or privacy rule: the steps, the proportionality and who decides. Required by ISO 27001; owner the head of HR. - HR security policy (joiners, movers, leavers) policy
Security before, during and at the end of employment: screening, terms, training, discipline, and the return of access and assets on leaving. Required by ISO 27001, NIS2; owner the head of HR. - Offboarding and termination procedure procedure
The steps when someone leaves or changes role: access removed, assets returned, obligations that continue, and the record that it was done. Required by ISO 27001; owner the head of HR. - Remote working policy policy
The conditions under which people work away from the organisation's premises: the equipment, the connection, the physical setting and the data they may take. Required by ISO 27001; owner the information security lead (CISO or ISMS manager). - Security awareness and training policy policy
Who is trained in what, how often, how it is recorded and how its effect is measured, for staff and for the management body. Required by ISO 27001, ISO 27701, ISO 42001, ISO 22301, NIS2; owner the information security lead (CISO or ISMS manager).
What reaches this family
| ISO 27001 | Expects: acceptable use policy, hr security policy (joiners, movers, leavers), remote working policy, security awareness and training policy. Requires, by clause: ISO 27001 5.10, ISO 27001 6.1, ISO 27001 7.7, ISO 27001 6.6, ISO 27001 6.4, ISO 27001 6.2, ISO 27001 6.5, ISO 27001 5.11, ISO 27001 5.18, ISO 27001 6.7, ISO 27001 6.3. |
|---|---|
| ISO 27701 | Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.3.19, ISO 27701 A.3.18, ISO 27701 7.3. |
| ISO 42001 | Expects: no document of this family on its gap list. Requires, by clause: ISO 42001 A.4.6. |
| ISO 22301 | Expects: security awareness and training policy. Requires, by clause: ISO 22301 7.3. |
| NIS2 | Expects: acceptable use policy, hr security policy (joiners, movers, leavers), security awareness and training policy. Requires, by clause: NIS2 Art. 21(2)(g), NIS2 Art. 21(2)(i), NIS2 Art. 20(2). |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register