3. Human Resource Security
This category addresses the need to ensure that employees, contractors, and third-party users understand their information security responsibilities and are suitable for the roles they are considered for. It covers security measures that should be taken during the pre-employment, employment, and termination or change of employment phases to protect the organization's information assets.
Controls (A.7):
Control A.7.1.1: Screening
Control A.7.1.2: Terms and Conditions of Employment
Control A.7.2.1: Management Responsibilities
Control A.7.2.2: Information Security Awareness, Education, and Training
Control A.7.2.3: Disciplinary Process
Control A.7.3.1: Termination or Change of Employment Responsibilities
Last updated