A.6.2 People
Terms and conditions of employment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-6mostlyaligns with — Both controls require personnel to formally acknowledge security responsibilities and obligations before receiving access to organizational assets.
- PS-8mostlyaligns with — Both controls establish that personnel must understand and accept the consequences of failing to meet security requirements as a condition of employment.
- AC-2partialaligns with — Both controls tie the granting and continuation of system access to the individual's acceptance of defined security responsibilities.
- AT-2partialaligns with — Both controls require that security expectations and obligations are conveyed to individuals prior to or at the start of their access to organizational systems.
- PS-9partialaligns with — Both controls ensure that security-related duties are explicitly documented and communicated as part of an individual's assigned role.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-02mostlyaligns with — Embedding security obligations into employment contracts directly supports the establishment and communication of cybersecurity roles, responsibilities, and authorities to personnel.
- GV.RR-04mostlyaligns with — Requiring personnel to accept information-security terms and conditions as part of the employment lifecycle integrates cybersecurity expectations into human-resources practices.
- GV.PO-02partialaligns with — Mandating that employment terms reflect current policies and legal requirements helps ensure policies are communicated, enforced, and kept up to date.
- GV.SC-10partialaligns with — Extending confidentiality and security obligations beyond the end of employment mirrors the post-contract provisions required for supply-chain relationships.
- PR.AA-05partialaligns with — Defining and agreeing to access-related responsibilities in employment contracts contributes to the policy-driven management of entitlements and authorizations.
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — Explicit non-disclosure and legal-responsibility clauses deter unauthorized disclosure of sensitive information by making the consequences of such disclosure contractually clear.
- CWE-284partialprevents — Requiring personnel to formally accept confidentiality, classification, and handling obligations before receiving access reduces the chance that staff will later misuse or exceed their granted privileges.
- CWE-522partialprevents — Contractual clauses that survive termination help ensure that credentials and other secrets are not retained or misused after employment ends.
- CWE-732partialprevents — By assigning explicit asset-classification and handling duties, the control discourages personnel from applying overly permissive permissions to critical resources.
Mitigated MITRE ATT&CK techniques (4)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Clear contractual obligations regarding the proper management of organizational assets reduce the chance that employees will deliberately copy sensitive files from local systems.
- T1078partialprevents — Binding employees to confidentiality agreements and post-employment obligations reduces the likelihood that valid credentials will be misused after separation or shared with external parties.
- T1530nonemitigates — Requiring personnel to acknowledge responsibilities for classified information and data-handling procedures limits unauthorized collection of data stored in cloud repositories.
- T1552nonemitigates — Explicit contractual duties for handling and protecting credentials and other sensitive data discourage personnel from leaving credentials in unsecured files or locations.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.