A.6.6 People
Confidentiality or non-disclosure agreements
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-6mostlyaligns with — Both controls require personnel to sign agreements that define obligations for protecting sensitive information and specify consequences for non-compliance.
- PS-6mostlycovers — A.6.6's NDA-focused confidentiality agreements form the core of what PS-6 requires for access agreements (especially the sign/re-sign verification), but PS-6 is broader in scope (any access terms, not just confidentiality) leaving a residual of the target uncovered
- AC-21partialaligns with — Both establish rules governing the sharing of sensitive information with external parties and the protections that must accompany such exchanges.
- PS-4partialaligns with — Both address the need to enforce confidentiality obligations when personnel depart, including return or destruction of protected information.
- PS-9partialaligns with — Both ensure that position descriptions and associated agreements clearly articulate responsibilities for safeguarding confidential information.
- AC-21covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PS-9covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (19)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-05mostlyaligns with — The ISO control establishes enforceable contractual terms that embed confidentiality obligations into supplier and partner relationships, directly supporting the CSF outcome of integrating cybersecurity requirements into contracts.
- GV.OC-03partialaligns with — The control incorporates legal and regulatory considerations by requiring agreements to comply with applicable jurisdictions, thereby addressing the CSF outcome of understanding legal and contractual cybersecurity obligations.
- GV.PO-01partialaligns with — The requirement to create and periodically review legally binding confidentiality agreements operationalizes the CSF outcome of establishing policy for managing cybersecurity risks based on organizational context.
- GV.SC-02partialaligns with — By defining responsibilities and permitted uses of confidential information for external parties, the control helps clarify and coordinate cybersecurity roles between the organization and its suppliers or partners.
- ID.RA-07partialaligns with — Periodic review of confidentiality agreements when requirements change supports the CSF outcome of managing changes and exceptions through risk-impact assessment and tracking.
- GV.OC-03implements — GV.OC-03 requires understanding and managing all legal/regulatory/contractual cybersecurity obligations (explicitly including privacy); A.6.6 is the specific technical/operational control that directly operationalizes the contractual NDA slice of that governance outcome within its domain.
- GV.PO-01implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.SC-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.SC-05implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-07implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — Legally binding confidentiality obligations deter personnel and third parties from disclosing sensitive data they obtain during their engagement, thereby lowering the likelihood that information will be exposed to unauthorized actors.
- CWE-284mitigates — Explicit clauses that define ownership, permitted use, and access rights create contractual boundaries that reduce the chance of improper access control being exercised by signatories.
- CWE-359mitigates — The agreements impose enforceable restrictions on the handling of private personal information, thereby decreasing the risk that such data will be exposed to unauthorized parties.
- CWE-522mitigates — By requiring signatories to protect credentials and other authentication material under the same confidentiality terms, the control discourages the mishandling or exposure of credentials that could lead to unauthorized account access.
Mitigated MITRE ATT&CK techniques (147)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1110.001prevents — A.6.6 legally binds personnel and external parties (including those with access to management services, SSO, cloud apps, or network devices) to protect credentials and report unauthorized disclosure attempts, which directly constrains the human-enabled guessing vector in the technique; the bounded remainder is fully automated guessing against non-human accounts or systems where no NDA applies.
- T1199prevents — NDAs with legally enforceable terms, responsibilities to avoid unauthorized disclosure, permitted-use clauses, audit rights, breach-notification duties, and return/destruction requirements directly constrain the third-party-provider scenario that T1199 names, but do not stop the initial compromise of the provider, the abuse of already-granted elevated/valid accounts, or the supply-chain trust that lets the technique succeed.
- T1213prevents — NDAs legally bind personnel and external parties against unauthorized disclosure or external sharing of repository contents (including the listed sensitive items), constraining the technique's success when the actor is a signatory; this is only a slice of the class because the technique also succeeds via technical access-control failures on the repositories themselves, which NDAs do not address.
- T1213.002prevents — A.6.6 legally binds personnel and external parties (via NDAs) to protect classified information they access, which directly constrains the insider or authorized-user subset of SharePoint mining (e.g. policies, diagrams, credentials) but leaves the external adversary path, misconfigurations, and post-breach exfiltration untouched.
- T1213.005prevents — NDA clauses on definition of protected info, permitted use, ownership, notification of leaks, and non-compliance actions directly constrain the technique of mining proprietary/source/credential data from internal messaging apps by authorized users, but do not stop external adversaries, post-breach exfiltration, or technical access once data is already in the app.
- T1598prevents — NDAs legally bind personnel and external parties against unauthorized disclosure of defined confidential information, which constrains the success of phishing-for-information techniques that target those parties (especially internal staff or trusted externals) by raising consequences and reminding them of obligations, but does not stop the adversary from sending the messages or prevent all cases (e.g., non-bound victims, social engineering that evades awareness of the agreement).
- T1598.004prevents — NDAs legally bind personnel and external parties against unauthorized disclosure of defined confidential information, which directly constrains the success of vishing attempts that rely on tricking those parties into divulging it; partial because the control is a governance/contractual instrument that does not stop the adversary technique from being attempted or reaching non-bound parties.
- T1684prevents — A.6.6 legally binds personnel and external parties to protect confidential information and avoid unauthorized disclosure, which directly constrains the social-engineering outcome of tricking authorized disclosure; it does not stop the adversary from running the influence technique itself or from targeting non-bound parties, so the covered slice is genuine but bounded.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.