A.6.5 People
Responsibilities after termination or change of employment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-4mostlyaligns with — Both controls require organizations to formally manage the revocation or reassignment of security responsibilities, access rights, and ongoing obligations when personnel depart or change roles.
- PS-4mostlycovers — A.6.5's broad post-termination/change responsibilities (protecting interests via defined processes) account for the bulk of PS-4's required termination actions, but leave a residual of specific technical steps (e.g., exact timing parameters, credential revocation mechanics, and exit-interview content) uncovered by the higher-level ISO control.
- PS-5mostlyaligns with — Both controls address the need to transfer security duties and update access authorizations when an individual moves to a different position within the organization.
- PS-5mostlycovers — A.6.5's post-termination/change process for protecting interests directly accounts for the bulk of PS-5's review-and-modify access on internal transfer, but a residual of PS-5 (explicit timing windows in the ODP parameters) sits outside the source.
- AC-2partialaligns with — Both controls require timely disabling or re-provisioning of accounts and privileges when employment status changes, ensuring residual access rights do not persist.
- PS-7partialaligns with — Both controls extend termination and role-change procedures to external or supplier personnel to maintain consistent security obligations beyond organizational boundaries.
- PS-9partialaligns with — Both controls ensure that security responsibilities tied to a position are explicitly documented so they can be enforced or transferred during role changes or terminations.
- PS-9covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (16)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-02mostlyaligns with — The ISO control ensures that security duties tied to a role are explicitly reassigned or retained when personnel depart or change positions, directly supporting the CSF outcome of establishing and communicating defined cybersecurity roles and responsibilities.
- GV.RR-04mostlyaligns with — By embedding continuing confidentiality and security obligations into employment terms and contracts, the ISO control integrates information-security accountability into human-resource lifecycle processes.
- GV.SC-02partialaligns with — The control extends the same termination and responsibility-transfer requirements to external personnel and suppliers, aligning with the CSF outcome that supplier and partner cybersecurity roles must be coordinated and communicated.
- ID.AM-08partialaligns with — Managing the transfer or revocation of security responsibilities when individuals leave or change roles contributes to the controlled life-cycle handling of the access rights and duties associated with organizational assets.
- PR.AA-05partialaligns with — Reassigning or revoking access-related duties and privileges upon termination or role change supports the CSF outcome that access authorizations are reviewed and adjusted as personnel status changes.
- GV.RR-02implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.RR-04implements — A.6.5 directly operationalizes the HR practices outcome in GV.RR-04 by specifying post-termination/change responsibilities that embed cybersecurity protections within those exact HR processes
- GV.SC-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (3)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — Mandating continued confidentiality obligations and the transfer of knowledge-handling duties lowers the probability that sensitive information will be disclosed by individuals who no longer have a legitimate need to know.
- CWE-284prevents — By explicitly transferring security roles and responsibilities when personnel change jobs or leave, the control reduces the chance that former employees retain access rights they no longer need, thereby limiting improper access control.
- CWE-286prevents — Responsibilities after termination or change of employment address removal of user access but not ongoing user management.
Mitigated MITRE ATT&CK techniques (65)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1078prevents — A.6.5 requires identifying, transferring, and communicating responsibilities (including access rights) upon termination or role change, which directly prevents abuse of inactive/former-employee accounts named in T1078; it does not reach credential compromise, permission overlap, or active-account abuse that form the bulk of the class.
- T1110.001prevents — A.6.5 requires that post-termination responsibilities (including confidentiality agreements and knowledge obtained) remain binding and be explicitly communicated to the departing individual; this directly constrains an insider who leaves or changes roles from later using retained credentials or knowledge to perform password guessing against accounts they should no longer access.
- T1199prevents — A.6.5 requires defining, communicating, and transferring post-termination security responsibilities (including for external suppliers/contractors) and managing role changes as a combined termination/initiation process, which constrains the trusted-relationship technique when the breach vector is an improperly offboarded or re-roled third-party account; it does not address ongoing access scoping, network segmentation, or technical protections for still-active trusted relationships.
- T1485recovers — A.6.5 requires that post-termination responsibilities (including confidentiality and IP protection) remain defined and transferred, and that changes be communicated; this can support recovery of knowledge/IP assets after an insider leaves and destroys data, but does not address restoration of destroyed files, systems, or availability for the bulk of T1485 scenarios.
- T1561.002recovers — A.6.5 requires that termination/change processes define, communicate and transfer information security responsibilities (including to external parties), which directly supports post-incident recovery of wiped systems by ensuring knowledge transfer, operating procedures and contacts are available to restore availability.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.