A.6.5 People
Responsibilities after termination or change of employment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-4mostlyaligns with — Both controls require organizations to formally manage the revocation or reassignment of security responsibilities, access rights, and ongoing obligations when personnel depart or change roles.
- PS-5mostlyaligns with — Both controls address the need to transfer security duties and update access authorizations when an individual moves to a different position within the organization.
- AC-2partialaligns with — Both controls require timely disabling or re-provisioning of accounts and privileges when employment status changes, ensuring residual access rights do not persist.
- PS-7partialaligns with — Both controls extend termination and role-change procedures to external or supplier personnel to maintain consistent security obligations beyond organizational boundaries.
- PS-9partialaligns with — Both controls ensure that security responsibilities tied to a position are explicitly documented so they can be enforced or transferred during role changes or terminations.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-02mostlyaligns with — The ISO control ensures that security duties tied to a role are explicitly reassigned or retained when personnel depart or change positions, directly supporting the CSF outcome of establishing and communicating defined cybersecurity roles and responsibilities.
- GV.RR-04mostlyaligns with — By embedding continuing confidentiality and security obligations into employment terms and contracts, the ISO control integrates information-security accountability into human-resource lifecycle processes.
- GV.SC-02partialaligns with — The control extends the same termination and responsibility-transfer requirements to external personnel and suppliers, aligning with the CSF outcome that supplier and partner cybersecurity roles must be coordinated and communicated.
- ID.AM-08partialaligns with — Managing the transfer or revocation of security responsibilities when individuals leave or change roles contributes to the controlled life-cycle handling of the access rights and duties associated with organizational assets.
- PR.AA-05partialaligns with — Reassigning or revoking access-related duties and privileges upon termination or role change supports the CSF outcome that access authorizations are reviewed and adjusted as personnel status changes.
Related OWASP ASVS 5.0 requirements (3)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284mostlyprevents — By explicitly transferring security roles and responsibilities when personnel change jobs or leave, the control reduces the chance that former employees retain access rights they no longer need, thereby limiting improper access control.
- CWE-286mostlyprevents — Responsibilities after termination or change of employment address removal of user access but not ongoing user management.
- CWE-200partialprevents — Mandating continued confidentiality obligations and the transfer of knowledge-handling duties lowers the probability that sensitive information will be disclosed by individuals who no longer have a legitimate need to know.
- CWE-732nonenone — Ensuring that permissions tied to a position are reviewed and reassigned when employment changes prevents lingering incorrect permission assignments on critical resources.
- CWE-862nonenone — Requiring that access-linked duties be reassigned or revoked at termination or role change directly decreases the likelihood that actions can be performed without proper authorization checks.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.