A.6.6 People
Confidentiality or non-disclosure agreements
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (8)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-6mostlyaligns with — Both controls require personnel to sign agreements that define obligations for protecting sensitive information and specify consequences for non-compliance.
- AC-21partialaligns with — Both establish rules governing the sharing of sensitive information with external parties and the protections that must accompany such exchanges.
- PS-4partialaligns with — Both address the need to enforce confidentiality obligations when personnel depart, including return or destruction of protected information.
- PS-9partialaligns with — Both ensure that position descriptions and associated agreements clearly articulate responsibilities for safeguarding confidential information.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-05mostlyaligns with — The ISO control establishes enforceable contractual terms that embed confidentiality obligations into supplier and partner relationships, directly supporting the CSF outcome of integrating cybersecurity requirements into contracts.
- GV.OC-03partialaligns with — The control incorporates legal and regulatory considerations by requiring agreements to comply with applicable jurisdictions, thereby addressing the CSF outcome of understanding legal and contractual cybersecurity obligations.
- GV.PO-01partialaligns with — The requirement to create and periodically review legally binding confidentiality agreements operationalizes the CSF outcome of establishing policy for managing cybersecurity risks based on organizational context.
- GV.SC-02partialaligns with — By defining responsibilities and permitted uses of confidential information for external parties, the control helps clarify and coordinate cybersecurity roles between the organization and its suppliers or partners.
- ID.RA-07partialaligns with — Periodic review of confidentiality agreements when requirements change supports the CSF outcome of managing changes and exceptions through risk-impact assessment and tracking.
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200mostlyprevents — Legally binding confidentiality obligations deter personnel and third parties from disclosing sensitive data they obtain during their engagement, thereby lowering the likelihood that information will be exposed to unauthorized actors.
- CWE-284partialmitigates — Explicit clauses that define ownership, permitted use, and access rights create contractual boundaries that reduce the chance of improper access control being exercised by signatories.
- CWE-359partialmitigates — The agreements impose enforceable restrictions on the handling of private personal information, thereby decreasing the risk that such data will be exposed to unauthorized parties.
- CWE-522partialmitigates — By requiring signatories to protect credentials and other authentication material under the same confidentiality terms, the control discourages the mishandling or exposure of credentials that could lead to unauthorized account access.
- CWE-532nonenone — Contractual duties to safeguard confidential information extend to log files that may contain sensitive data, reducing the probability that such logs will be left unprotected or inadvertently disclosed.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.