A.6.2 People
Terms and conditions of employment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-6mostlyaligns with — Both controls require personnel to formally acknowledge security responsibilities and obligations before receiving access to organizational assets.
- PS-8mostlyaligns with — Both controls establish that personnel must understand and accept the consequences of failing to meet security requirements as a condition of employment.
- AC-2partialaligns with — Both controls tie the granting and continuation of system access to the individual's acceptance of defined security responsibilities.
- AT-2partialaligns with — Both controls require that security expectations and obligations are conveyed to individuals prior to or at the start of their access to organizational systems.
- PS-6partialcovers — A.6.2's focus on employment terms to communicate security responsibilities (including access-related ones) addresses only a slice of PS-6's requirements to develop, document, review, update, and enforce signed access agreements.
- PS-9partialaligns with — Both controls ensure that security-related duties are explicitly documented and communicated as part of an individual's assigned role.
- PS-9partialcovers — A.6.2's focus on communicating security responsibilities via employment terms and conditions addresses only a slice of what ps-9 requires (explicitly incorporating those roles/responsibilities into formal position descriptions themselves); the bulk of the target's requirement sits in the upstream documentation step that A.6.2 assumes but does not perform.
- PS-8covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (16)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-02mostlyaligns with — Embedding security obligations into employment contracts directly supports the establishment and communication of cybersecurity roles, responsibilities, and authorities to personnel.
- GV.RR-04mostlyaligns with — Requiring personnel to accept information-security terms and conditions as part of the employment lifecycle integrates cybersecurity expectations into human-resources practices.
- GV.PO-02partialaligns with — Mandating that employment terms reflect current policies and legal requirements helps ensure policies are communicated, enforced, and kept up to date.
- GV.SC-10partialaligns with — Extending confidentiality and security obligations beyond the end of employment mirrors the post-contract provisions required for supply-chain relationships.
- PR.AA-05partialaligns with — Defining and agreeing to access-related responsibilities in employment contracts contributes to the policy-driven management of entitlements and authorizations.
- GV.PO-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.RR-02implements — A.6.2 directly operationalizes the establishment, communication, and understanding of cybersecurity-related roles/responsibilities (via employment terms that explicitly cover information security duties), which is exactly what GV.RR-02 requires.
- GV.RR-04implements — A.6.2 directly operationalizes the HR-practice outcome by mandating that employment terms and conditions explicitly communicate information-security responsibilities, which is the exact mechanism GV.RR-04 requires for including cybersecurity in HR practices.
- GV.SC-10implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — Explicit non-disclosure and legal-responsibility clauses deter unauthorized disclosure of sensitive information by making the consequences of such disclosure contractually clear.
- CWE-284prevents — Requiring personnel to formally accept confidentiality, classification, and handling obligations before receiving access reduces the chance that staff will later misuse or exceed their granted privileges.
- CWE-522prevents — Contractual clauses that survive termination help ensure that credentials and other secrets are not retained or misused after employment ends.
- CWE-732prevents — By assigning explicit asset-classification and handling duties, the control discourages personnel from applying overly permissive permissions to critical resources.
Mitigated MITRE ATT&CK techniques (169)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1021.004prevents — A.6.2's terms of employment, NDAs, role responsibilities, and post-employment obligations can constrain misuse of valid accounts/SSH by authorized insiders (who must understand and agree to security rules), but this does not prevent external adversaries or compromised accounts from using the technique.
- T1052prevents — contractual terms, NDAs, asset-handling responsibilities and post-employment obligations communicated to personnel directly constrain insider-assisted physical exfiltration (especially the user-introduced device scenario in air-gapped networks) but leave external-threat and non-insider vectors untouched
- T1078prevents — Binding employees to confidentiality agreements and post-employment obligations reduces the likelihood that valid credentials will be misused after separation or shared with external parties.
- T1110.001prevents — A.6.2 mandates that employment contracts and pre-employment communications set out information security responsibilities, including legal obligations, handling rules, and consequences for disregarding security requirements; this directly constrains the human-enabled portion of password guessing (e.g., policy-compliant account lockouts, complexity rules, and post-employment obligations) in the same way the A.8.5 anchor constrains guessing via proportionate authentication strength, leaving only the technical bypass slice as named remainder.
- T1110.002prevents — A.6.2 mandates signed terms, NDAs, explicit responsibilities for handling/classifying assets, and post-employment obligations that directly constrain insider or former-insider disclosure of hashes, weak passwords, or cracking tools, preventing the technique in the dominant human-factor slice while leaving external offline cracking of obtained hashes as the bounded remainder.
- T1110.003prevents — A.6.2 requires communicating security responsibilities and signing appropriate terms (including legal obligations, handling rules, and consequences for violations) to personnel before access is granted, which constrains insider misuse of credentials but does not stop external adversaries from spraying guessed passwords against accounts or services.
- T1110.004prevents — A.6.2 requires communicating security responsibilities and signing NDAs/terms that can include password/credential handling and post-employment obligations, which can reduce (but not stop) reuse of personal credentials that enables stuffing; it does not address technical authentication strength, lockouts, or the breach-dump source itself.
- T1137.001prevents — A.6.2's contractual terms, NDAs, policy awareness and post-employment clauses can constrain an insider (or pre-hire) from deliberately planting a malicious Office template macro, but do nothing against an already-compromised account, external adversary, or unwitting user enabling the technique.
- T1137.004prevents — A.6.2's contractual terms, NDAs, communicated responsibilities, and post-employment clauses can constrain legitimate users from deliberately or negligently adding malicious Outlook Home Pages, but do not stop an already-compromised account or bypassed process from introducing the persistence technique.
- T1137.005prevents — A.6.2's contractual terms, NDAs, role responsibilities, and post-employment clauses can constrain insider misuse of Outlook rules for persistence (especially if the actor is an employee/contractor), but do not stop an external adversary who has already compromised a mailbox from adding malicious rules.
- T1137.006prevents — A.6.2 requires communicating and contractually binding personnel (including during pre-employment) to security responsibilities, policies, and consequences for violations, which can constrain insiders from deliberately installing malicious add-ins for persistence; it does not stop post-compromise abuse of add-ins by external adversaries or technical execution of the technique.
- T1199prevents — A.6.2 requires clear contractual terms, NDAs, defined responsibilities and post-employment obligations for third-party personnel who receive access, which can prevent some supply-chain trust abuses when enforced at contracting time, but does not stop compromise of already-granted accounts, delegation relationships, or lateral movement once the trusted provider is breached.
- T1204prevents — A.6.2's contractual terms, NDAs, policy awareness, and post-employment obligations set expectations and consequences that can deter some users from executing adversary-supplied payloads under social engineering, but do not stop the technique from succeeding when users are deceived or coerced.
- T1204.001prevents — A.6.2's contractual terms, NDAs, policy awareness, and post-employment obligations reduce the chance that a user will click a malicious link by clarifying responsibilities and consequences, but do not stop the social-engineering vector or the click itself.
- T1204.002prevents — A.6.2's contractual terms, NDAs, policy awareness, and post-employment clauses set user responsibilities and consequences that can deter opening suspicious files via awareness and accountability, but do not stop the social-engineering or masquerading vectors that drive the technique.
- T1204.004prevents — A.6.2's pre-employment communication of security responsibilities and contractual terms (including handling of information, actions for disregarding requirements, and post-employment obligations) can reduce the likelihood that users fall for social-engineering lures to copy-paste malicious commands, but does not stop the technique from being attempted or succeeding when users still comply.
- T1213prevents — A.6.2's contractual terms, NDAs, role responsibilities, and post-employment obligations directly constrain insider personnel from mishandling or externally sharing repository data (including policies, diagrams, credentials, and PII), which is a core slice of the technique; it does not address external adversaries, misconfigurations, or public/unauthenticated access vectors that dominate the technique's description and citations.
- T1213.002prevents — A.6.2 requires personnel to understand and agree to responsibilities including classification, handling, and protection of information (explicitly naming policies, procedures, and assets), which constrains insiders from exposing or mishandling SharePoint content that would aid the technique; this is a genuine but minority slice because the technique can still be executed by external adversaries, misconfigured permissions, or non-personnel vectors.
- T1528prevents — A.6.2's contractual terms, NDAs, role responsibilities, and post-employment clauses (including awareness of policies on handling assets and consequences) can constrain insider misuse or social-engineering paths to token theft, but do not stop technical compromise vectors like container breaches, CI/CD pipeline compromise, or IMDS token requests that dominate the technique.
- T1534prevents — Contractual terms, NDAs, communicated responsibilities, and post-employment obligations reduce the chance that an insider (or compromised account) will aid or fall for internal spearphishing, but do not stop the multi-staged technique once an account is already compromised.
- T1566prevents — Contractual terms, NDAs, communicated responsibilities and post-employment obligations reduce the chance that an insider will aid, ignore, or fall for a phishing campaign, but do not stop external adversaries from sending the messages or prevent all human error in response.
- T1566.001prevents — A.6.2 sets employment terms that communicate security responsibilities and consequences (including handling of received information and actions for disregarding requirements), which can reduce successful user execution of malicious attachments via awareness and policy; this constrains the social-engineering/user-action slice of the technique but does not stop the adversary from sending the email or the malware from executing if opened.
- T1566.002prevents — contractual terms, NDAs, communicated responsibilities and post-employment obligations reduce the chance that an insider will click the link or grant consent, but do not stop external spearphishing emails from being delivered or the social-engineering technique from reaching the user
- T1566.003prevents — A.6.2's pre-employment communication of security responsibilities, NDAs, handling rules, and post-employment obligations can reduce the likelihood that personnel will engage with or act on spearphishing lures (especially those using job-opportunity pretexts or asking about internal policies), but cannot stop the adversary from sending the messages or guarantee that every employee will recognize and refuse the social-engineering vector.
- T1566.004prevents — A.6.2's contractual terms, NDAs, role responsibilities, and post-employment obligations set expectations and accountability for personnel on handling social engineering and protecting assets, which can prevent some user-enabled voice phishing successes, but does not stop the technique from being attempted or succeeding against untrained or non-compliant users.
- T1598prevents — Contractual terms, NDAs, awareness of responsibilities, and post-employment obligations reduce the chance that organizational personnel will divulge information when phished, but do not stop external targeted individuals or non-personnel from being tricked.
- T1598.001prevents — A.6.2's pre-employment communication of security responsibilities, NDAs, and post-employment obligations can reduce the likelihood that targeted employees will divulge information when approached via spearphishing lures (e.g., fake job offers), but does not stop the adversary technique itself from being executed against personnel.
- T1598.002prevents — A.6.2's contractual terms, NDAs, and explicit communication of information security responsibilities (including handling of received information and post-employment obligations) reduce the chance that targeted personnel will open attachments or divulge data under social engineering, but do not stop the adversary from sending the message or guarantee that every employee will comply.
- T1598.003prevents — Contractual terms, NDAs, security responsibilities, and post-employment obligations communicated during pre-employment directly reduce the chance that an insider will assist, fall for, or propagate a spearphishing link, which is a meaningful but minority slice of the social-engineering technique that primarily targets external victims.
- T1598.004prevents — A.6.2's pre-employment communication of security responsibilities, NDAs, and post-employment obligations can reduce successful vishing by making personnel less likely to divulge information, but does not stop the social engineering technique itself from being attempted or succeeding against untrained or non-compliant individuals.
- T1657prevents — A.6.2's pre-employment communication of security responsibilities, contractual NDAs, and post-employment obligations can prevent some insider-enabled financial theft vectors (e.g., social engineering or unauthorized transfers by personnel), but leaves the bulk of external adversary techniques (ransomware extortion, BEC, cryptocurrency exploits, technical theft) untouched.
- T1684prevents — A.6.2's pre-employment communication of security responsibilities plus signed terms (including consequences for disregarding requirements) constrains the slice of social engineering that relies on unwitting or compliant insiders, but leaves the bulk of the technique (persuasion, urgency, trust-building, and phishing patterns) untouched.
- T1684.001prevents — A.6.2's contractual terms, NDAs, role-specific responsibilities, and post-employment obligations (especially for those with access) reduce the likelihood that authorized insiders will fall for or act on impersonation attempts, but do not stop external social-engineering campaigns, reconnaissance, or non-insider victims.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.