According to Verizon’s 2024 Data Breach Investigations Report, 74% of all breaches involve a human element whether that’s social engineering, misuse of privileges, credential theft, or simple error. ISO/IEC 27001:2022 confronts this reality directly through its people controls, a set of requirements spanning the entire employee lifecycle from pre-hire screening to post-termination access revocation.
For US organizations pursuing ISO 27001 certification particularly those managing HIPAA-covered data, operating under CMMC 2.0, or subject to SEC cybersecurity disclosure rules these people controls are not just audit checkboxes. They form the human layer of a defensible information security management system (ISMS). This article explains what each control requires, how they interconnect, and what auditors actually look for when they review your HR security documentation.
What ISO 27001:2022 People Controls Actually Cover
The 2022 revision of ISO 27001 restructured its control set significantly. Annex A now contains 93 controls organized across four themes: organizational, people, physical, and technological. The people controls numbered 6.1 through 6.8 govern how organizations manage the human dimension of information security.
This is not the same as traditional HR management. The standard is concerned with how employment relationships create, modify, and eliminate security risks. Every stage of the employee lifecycle carries distinct risk exposures, and the people controls map directly to those stages.
| ISO 27001:2022 Control | Control Name | Lifecycle Stage | US Framework Alignment |
|---|---|---|---|
| 6.1 | Screening | Pre-employment | NIST SP 800-53 PS-3 |
| 6.2 | Terms and conditions of employment | Onboarding | NIST SP 800-53 PS-6 |
| 6.3 | Information security awareness, education and training | Ongoing | NIST CSF PR.AT |
| 6.4 | Disciplinary process | During employment | NIST SP 800-53 PS-8 |
| 6.5 | Responsibilities after termination or change of employment | Offboarding | NIST SP 800-53 PS-4, PS-5 |
| 6.6 | Confidentiality or non-disclosure agreements | Onboarding + third parties | NIST SP 800-53 PS-6 |
| 6.7 | Remote working | During employment | NIST SP 800-53 AC-17 |
| 6.8 | Information security event reporting | During employment | NIST CSF DE.AE, RS.CO |
Each of these controls carries implementation guidance in ISO/IEC 27002:2022, the companion standard that provides the “how” behind the “what” of ISO 27001. Together, they define a people security program that goes well beyond annual security awareness training.
Before conducting ISMS audits, beginners can build a strong foundation through the ISO 27001 Foundation Certification for beginners, covering essential clauses, controls, and terminology.
Control 6.1 – Screening: What You Must Check Before Someone Joins
Background screening is where people security begins, and ISO 27001 is specific about the factors that must drive your screening decisions. Control 6.1 requires that background verification checks be carried out for all candidates for employment, proportional to the classification of information they will access, applicable laws, and the risks involved.
The phrase “proportional to” is doing significant work here. A developer with production database access warrants a different level of screening than a receptionist. An employee handling protected health information (PHI) under HIPAA carries regulatory weight that shapes what verification is legally permissible and practically necessary in the US context.
| What Screening Must Cover Under ISO 27001 |
| Identity verification against government-issued documentation |
| Employment history confirmation, including gaps |
| Educational credentials for roles where qualifications are claimed |
| Criminal background checks where legally permissible by state law |
| Credit history checks for roles with financial or privileged system access |
| Reference checks from previous employers |
| Social media and professional profile verification for senior roles |
US organizations must navigate state-by-state variation in what background checks are permissible. California, New York, and Illinois each impose distinct restrictions on criminal history inquiries and credit checks under ban-the-box legislation and the Fair Credit Reporting Act (FCRA). Your screening policy must be documented in your ISMS and reviewed annually to reflect changes in applicable law both because ISO 27001 requires it and because FCRA violations carry civil liability.
The audit evidence auditors expect: a written screening policy, screening records for a sample of employees, evidence that screening was completed before access was granted (not after), and documentation of how the organization handles candidates who fail screening checks.
Control 6.2 – Terms and Conditions of Employment: Making Security Obligations Explicit
Verbal agreements about information security responsibilities are worthless in an audit. Control 6.2 requires that employment contracts state the employee’s and the organization’s responsibilities for information security.
This does not mean burying a paragraph about passwords in a fifty-page employment agreement. Effective implementation means the security responsibilities are specific, comprehensible, and acknowledged. The employee must understand what they are agreeing to not just sign a document.
What Employment Contracts Must Address
ISO 27002 guidance on control 6.2 identifies several areas that employment terms should cover: confidentiality and non-disclosure obligations, acceptable use of organizational information and systems, actions taken when the employee receives information assets, actions required when the employee leaves, and the organization’s right to monitor activity on its systems.
The last point requires particular care in US employment law. The Electronic Communications Privacy Act (ECPA) and state equivalents create specific requirements around employee monitoring disclosure. Your employment terms must include monitoring language that satisfies both ISO 27001’s requirement for explicit security obligations and applicable US privacy statutes.
The alignment with NIST SP 800-53 control PS-6 (Access Agreements) is direct: both frameworks require documented, signed agreements before access is granted. For organizations pursuing FedRAMP authorization alongside ISO 27001 certification, this convergence simplifies documentation a single well-constructed access agreement can satisfy both frameworks simultaneously.
Control 6.3 – Security Awareness Training: Beyond the Annual Checkbox
Security awareness training is the people control that most organizations believe they have covered and the one where auditors most frequently find significant gaps. Control 6.3 requires that all personnel receive appropriate security awareness, education, and training relevant to their role and that they are kept up to date with organizational policies and procedures.
The word “appropriate” is the pivot. Annual generic phishing training does not satisfy this control for a cloud architect with privileged access to production infrastructure. The control explicitly requires that training be relevant to the individual’s role and that it continues throughout employment, not just at onboarding.
| Role Category | Required Training Elements | Recommended Frequency | NIST CSF Alignment |
|---|---|---|---|
| All staff | Security policies, phishing awareness, incident reporting | Annual + phishing simulations quarterly | PR.AT-1 |
| IT and system administrators | Privileged access risks, patch management, logging requirements | Semi-annual | PR.AT-3 |
| Developers | Secure coding, OWASP Top 10, code review practices | Annual + project-specific | PR.AT-3 |
| HR and managers | Onboarding/offboarding checklists, insider threat indicators | Annual | PR.AT-2 |
| Executives | Board-level cyber risk, SEC disclosure obligations, ransomware scenarios | Annual | PR.AT-5 |
| Third-party contractors | Data handling requirements, acceptable use, breach reporting | Before access granted | PR.AT-4 |
The IBM Cost of a Data Breach Report 2024 found that organizations with mature security training programs detected breaches 35 days faster and contained them 27 days faster than organizations with minimal training programs translating to an average cost difference of $1.49 million per incident. For US organizations subject to SEC cybersecurity disclosure rules, faster detection directly reduces the risk of failing to meet the four-business-day material incident disclosure deadline.
Your ISMS documentation needs to show: a training matrix mapping roles to required training, records of training completion, evidence of training content updates in response to emerging threats, and a process for ensuring new hires complete training before they gain access to sensitive systems.
Control 6.4 – Disciplinary Process: When Policy Violations Occur
Organizations that cannot demonstrate a formal process for handling security policy violations have a credibility problem with auditors. Control 6.4 requires a formal and communicated disciplinary process for employees who violate security policies.
The control serves two purposes. The deterrent effect is obvious people are less likely to misuse information assets when consequences are defined and enforced. Less obviously, the process protects the organization legally. In the US, disciplinary actions that appear arbitrary or inconsistent create exposure under employment discrimination law. A documented, proportionate, consistently applied disciplinary framework mitigates this risk while satisfying the ISO 27001 requirement.
| What Screening Must Cover Under ISO 27001 |
| Identity verification against government-issued documentation |
| Employment history confirmation, including gaps |
| Educational credentials for roles where qualifications are claimed |
| Criminal background checks where legally permissible by state law |
| Credit history checks for roles with financial or privileged system access |
| Reference checks from previous employers |
| Social media and professional profile verification for senior roles |
The standard does not prescribe specific penalties it requires that the process exist, be communicated to employees, and be applied consistently. Your employee handbook should include the framework. HR and line managers should be trained on it. And disciplinary records (appropriately anonymized for audit purposes) should demonstrate that the process has actually been used.
One nuance US organizations frequently overlook: the disciplinary process must cover contractors and third-party personnel operating under your ISMS scope, not just direct employees. If a contractor violates your security policies, the audit trail should show that your contractual arrangements provide a mechanism for enforcement.
Control 6.5 – Responsibilities After Termination: Closing the Door Properly
Employee departures voluntary or involuntary create predictable security risks. Former employees retain knowledge of system architectures, access credentials that were not properly revoked, and in some cases active access if offboarding was not completed promptly. Control 6.5 requires that the organization’s information security responsibilities and duties that remain valid after termination or change of employment be defined, communicated, and enforced.
The bidirectional nature of this control matters. It applies both to what former employees must do (return assets, maintain confidentiality) and to what the organization must do (revoke access, disable credentials, retrieve physical and digital assets).
| Offboarding Action | Responsible Party | Maximum Timeframe | Evidence for Audit |
|---|---|---|---|
| Disable directory account (AD/Okta/Azure AD) | IT/IAM team | Day of departure | IAM system log with timestamp |
| Revoke VPN and remote access certificates | IT Security | Day of departure | Certificate revocation record |
| Remove from all SaaS platforms | IT/System owners | Within 24 hours | Access deprovisioning ticket |
| Retrieve company devices and physical access cards | HR / Facilities | Day of departure | Asset return acknowledgment |
| Transfer or archive email and files | IT / Line manager | Within 48 hours | Data transfer record |
| Rotate shared credentials the employee knew | System owners | Within 72 hours | Credential rotation log |
| Collect signed acknowledgment of continuing confidentiality obligations | HR / Legal | Day of departure | Signed document on file |
NIST SP 800-53 controls PS-4 (Personnel Termination) and PS-5 (Personnel Transfer) mirror these requirements precisely. For CMMC 2.0 Level 2 organizations, this control maps to the Personnel Security (PS) domain, making thorough offboarding documentation essential for both certifications simultaneously.
The Offboarding Security Checklist
A defensible ISO 27001 offboarding process covers every category of access and asset the departing employee held. Access revocation is typically the highest-priority action ideally executed on the same day the employment ends, and in involuntary termination cases, before or simultaneous with notification.
The scope of access revocation in modern organizations is broader than most HR departments realize. Beyond the obvious email and VPN accounts, departing employees may hold access to SaaS platforms, shared credentials, cloud service consoles, physical key cards, code repositories, and API keys. A comprehensive offboarding checklist maps every system category to a revocation action and assigns ownership for completing each step within a defined time window.
Control 6.6 – Confidentiality and Non-Disclosure Agreements
Non-disclosure agreements (NDAs) are familiar territory for legal and HR teams. Control 6.6 specifically places them within the information security control set, requiring that confidentiality or NDA requirements reflecting the organization’s needs for information protection be identified, documented, and regularly reviewed.
The control is broader than employment contracts alone. It extends to contractors, consultants, third-party service providers, and anyone else who accesses the organization’s information through a business relationship. For US healthcare organizations, NDAs must align with HIPAA Business Associate Agreement requirements. For defense contractors, they must complement CMMC-required technical access controls.
| What ISO 27001-Aligned NDAs Must Specify |
| Clear definition of what constitutes confidential information under the agreement |
| Duration of confidentiality obligations, including post-termination terms |
| Permitted uses of confidential information and explicit prohibitions |
| Return or destruction obligations upon termination of the relationship |
| Consequences of unauthorized disclosure, including indemnification provisions |
| Governing law and jurisdiction for dispute resolution |
| Notification obligations if a breach of confidentiality is suspected or confirmed |
Generic NDAs downloaded from legal template sites often fail ISO 27001 requirements because they omit specific reference to information classification categories, fail to address electronic media handling, and do not include adequate breach notification language. Your ISMS documentation should include an NDA template review schedule aligned with annual policy reviews.
Control 6.7 – Remote Working: Securing the Distributed Workforce
Remote working arrangements create information security risks that on-premises work does not. Home networks lack enterprise-grade controls, personal devices may hold work data, and physical security of screens and conversations is harder to enforce. Control 6.7 requires that security measures be implemented when personnel work remotely to protect information accessed, processed, or stored outside the organization’s premises.
The scale of remote work in the US makes this control operationally significant. As of 2024, approximately 22% of the US workforce works remotely full-time and another 28% works in hybrid arrangements, according to McKinsey research. An ISMS that does not address remote working is incomplete for most US organizations.
Remote Working Controls That Satisfy Auditors
Effective remote working security is not about blanket prohibition it is about compensating controls that maintain the same information security posture regardless of physical location. The controls that matter most are: mandatory VPN or zero-trust network access for connection to organizational systems; endpoint management (MDM/EDR) ensuring organizational control of any device accessing organizational data; clear policy on approved devices and prohibition on use of personal devices for classified information; physical security requirements for the home workspace (screen privacy filters, locking devices when unattended); and prohibition on working in public locations without privacy screens or when handling sensitive information.
US-specific regulatory considerations apply here as well. HIPAA requires covered entities to address remote work in their workforce security policies. SEC registrants disclosing cybersecurity risks must include material risks arising from remote working arrangements in their cybersecurity risk disclosures.
Control 6.8 – Security Event Reporting: Building a Culture Where People Tell You
The most technically sophisticated monitoring infrastructure is no substitute for an employee who notices something wrong and reports it. Control 6.8 requires that all employees and contractors be aware of their responsibility to report security events and weaknesses as quickly as possible through appropriate channels.
The control addresses a behavioral problem as much as a procedural one. Employees who do not report security incidents often fail to do so because they fear punishment, do not know who to tell, or do not recognize what constitutes a reportable event. Fixing these barriers requires more than a policy document.
| Building Effective Incident Reporting Channels |
| Dedicated reporting mechanisms: email alias (e.g., security@company.com), ticketing system, or hotline |
| No-blame reporting culture explicitly stated in policy and reinforced by management behavior |
| Clear definitions of what constitutes a reportable event, with examples relevant to each role |
| Defined response time commitments from the security team to acknowledge reports |
| Regular feedback to employees on reports received (anonymized) and actions taken |
| Positive recognition for employees who report incidents that prevent or limit breaches |
The alignment with NIST CSF functions DE.AE (Anomalies and Events) and RS.CO (Communications) is direct. Both frameworks recognize that detection and response depend on human reporting as much as technical monitoring. For organizations subject to the SEC’s cybersecurity incident disclosure rule, the speed and accuracy of internal reporting directly affects whether the organization can assess materiality within the required timeframe.
Auditors examine incident logs for evidence that employee-reported events are being captured and handled, not just technical alerts from monitoring tools. If your incident register contains only SIEM-generated alerts and no employee-initiated reports, that is a gap it suggests either that your reporting culture is broken or that incidents are not being recorded properly.
Defining Roles and Responsibilities Within the People Controls Framework
ISO 27001 Clause 5.3 requires that roles, responsibilities, and authorities for information security be assigned and communicated. The people controls in Annex A cannot function without this foundation. When no one owns screening, training laps in frequency, or offboarding checklists get skipped, it is almost always because accountability was not clearly assigned.
The standard does not prescribe an organizational structure. A small US company might assign all people security responsibilities to a single security-aware HR manager. A large enterprise might have dedicated functions for security training, insider threat programs, and access management. What matters is that every people control has a named owner with defined responsibilities.
| People Control | Primary Owner | Supporting Parties | Documented In |
|---|---|---|---|
| Screening (6.1) | HR / Talent Acquisition | Security team, Legal | HR Security Policy |
| Employment terms (6.2) | HR / Legal | CISO, line managers | Employment Contract Template |
| Awareness training (6.3) | Security Awareness Program Manager | HR, IT, business units | Training Matrix + Schedule |
| Disciplinary process (6.4) | HR | Legal, CISO, line managers | Employee Handbook |
| Termination controls (6.5) | HR + IT | IAM team, facilities | Offboarding Checklist |
| NDAs (6.6) | Legal / HR | CISO, procurement | NDA Template Library |
| Remote working (6.7) | CISO / IT Security | HR, business units | Remote Work Policy |
| Event reporting (6.8) | CISO / SOC | HR, all managers | Incident Reporting Procedure |
The RACI documentation does not need to be elaborate a single matrix embedded in your Information Security Roles and Responsibilities Policy satisfies ISO 27001 requirements and gives auditors a clear artifact to review. What it cannot do is be aspirational. If the RACI says the Security Awareness Program Manager owns training delivery but no such role exists, auditors will identify this as a non-conformity.
Security leaders responsible for designing and managing an ISMS can advance their expertise through the ISO 27001 Lead Implementer Certification, focused on practical implementation and governance.
US Regulatory Alignment: How People Controls Map to HIPAA, CMMC, and SEC Rules
The people controls in ISO 27001 do not exist in regulatory isolation for US organizations. Three frameworks in particular create obligations that closely parallel ISO 27001’s people security requirements and in some cases extend them.
HIPAA Workforce Security Requirements
The HIPAA Security Rule’s Workforce Security standard (§164.308(a)(3)) requires covered entities and business associates to implement policies and procedures to ensure that all members of the workforce have appropriate access to electronic PHI. This maps directly to ISO 27001 controls 6.1 (screening), 6.2 (employment terms), and 6.5 (termination). The Authorization and/or Supervision requirement under HIPAA aligns with ISO 27001’s role-based access controls and accountability framework. HIPAA’s Workforce Clearance Procedure maps to ISO 27001 control 6.1 screening requirements.
For healthcare organizations, implementing ISO 27001 people controls provides a structured approach to satisfying HIPAA workforce security requirements, with the ISO documentation serving as evidence in HIPAA compliance audits.
CMMC 2.0 Personnel Security Domain
CMMC 2.0 Level 2 includes the Personnel Security (PS) domain, which derives from NIST SP 800-171 controls 3.9.1 and 3.9.2. These require screening individuals prior to authorizing access to organizational systems containing CUI (Controlled Unclassified Information) and ensuring that CUI is protected during and after personnel actions such as terminations and transfers.
Defense contractors pursuing CMMC 2.0 certification alongside ISO 27001 can satisfy both frameworks’ people security requirements with a single integrated set of controls. The ISO 27001 screening policy (6.1), offboarding checklist (6.5), and employment terms (6.2) directly address CMMC PS domain requirements, with minor additions for CUI-specific handling.
SEC Cybersecurity Disclosure Rules
The SEC’s cybersecurity disclosure rules, in effect since December 2023 for large accelerated filers, require public companies to describe their processes for assessing, identifying, and managing material cybersecurity risks, including risks arising from human factors. People controls feature directly in this disclosure: organizations must describe their security awareness programs, their processes for managing third-party human security risks, and their incident reporting mechanisms.
ISO 27001 people control documentation provides exactly the structured evidence base that supports accurate SEC cybersecurity disclosures. The training matrix (6.3), NDA framework (6.6), and incident reporting procedure (6.8) each address aspects of what the SEC expects to see described.
Preparing for Your ISO 27001 Audit: What Auditors Look for in People Controls
Stage 2 ISO 27001 audits routinely find non-conformities in people controls, and the patterns are consistent. Understanding what auditors actually test helps organizations focus preparation effort where it matters most.
| Common People Controls Non-Conformities Found in ISO 27001 Audits |
| Screening policy exists but evidence shows access was granted before screening was completed |
| Employment contracts do not include specific information security responsibilities only generic HR language |
| Security awareness training records are incomplete contractors and temporary staff are not covered |
| Training content has not been updated to reflect current threat landscape or recent security incidents |
| No documented disciplinary process, or process exists but has never been applied (no records) |
| Offboarding is manual and ad hoc no checklist, no defined timeframes, no IT sign-off requirement |
| NDAs exist for employees but third-party contractors operate without signed agreements |
| Remote working policy does not address personal device use or home network security |
The audit evidence bundle for people controls should include, at minimum: the HR Security Policy document (version controlled), your ISMS Roles and Responsibilities matrix, completed screening records for a sample of employees, signed employment security agreements, training completion records with content documentation, the disciplinary process procedure, a sample of completed offboarding checklists with IT sign-off, current NDA templates and a log of executed agreements, and the remote working security policy with evidence of communication to staff.
The test auditors apply is straightforward: does the documented process reflect actual practice? Policies that describe processes no one follows are more damaging in an audit than having no policy at all, because they demonstrate awareness of the requirement and deliberate non-compliance.
Frequently Asked Questions
What is the difference between ISO 27001 people controls in the 2013 and 2022 versions?
The 2022 revision moved people controls into a dedicated Annex A theme (controls 6.1–6.8) and added two new controls: remote working (6.7) and information security event reporting (6.8). The 2013 version covered HR security across Clause A.7, with 13 controls spread across three sub-sections. The 2022 restructure consolidates people security requirements and explicitly addresses the remote workforce, which was a significant gap in the previous version.
Can ISO 27001 people controls satisfy HIPAA workforce security requirements simultaneously?
Yes with careful mapping. ISO 27001 controls 6.1 (screening), 6.2 (employment terms), 6.3 (training), and 6.5 (termination) directly address the HIPAA Security Rule’s Workforce Security standard (§164.308(a)(3)). Organizations should document the mapping explicitly in their ISMS, as this supports HIPAA compliance audits and avoids duplicating documentation efforts.
How often must security awareness training be conducted under ISO 27001?
ISO 27001 does not specify a fixed frequency it requires training to be ‘appropriate’ and ‘kept up to date.’ In practice, most auditors expect at minimum annual training for all staff, quarterly phishing simulations, and role-specific training for high-risk roles. Training content must be reviewed whenever significant changes occur to the threat landscape, organizational systems, or security policies.
What counts as acceptable evidence of background screening for ISO 27001 audits?
Auditors look for written confirmation from the screening provider, the date screening was completed relative to the date access was granted, the scope of checks performed, and evidence that the screening policy was followed. For US organizations, documentation should also show awareness of FCRA and applicable state law constraints on the checks performed.
Do ISO 27001 people controls apply to contractors and third-party staff?
Yes, the people controls apply to all personnel working within the ISMS scope, including contractors, temporary staff, and third-party service providers. Control 6.6 (NDAs) specifically addresses third parties. Offboarding controls under 6.5 must cover contractors whose engagements end. The ISO 27001 audit will include sampling of contractor personnel management alongside direct employees.
What is the minimum documentation required for people controls to pass an ISO 27001 audit?
At minimum: a documented HR Security Policy covering all eight people controls, role-based training records, a completed offboarding checklist template with evidence of use, employment contract security provisions, NDA templates and an execution log, and a screening procedure with supporting records. The documentation does not need to be elaborate it needs to be accurate, current, and demonstrate actual practice.
How do remote working controls under ISO 27001 6.7 relate to NIST CSF?
Control 6.7 maps most directly to NIST SP 800-53 control AC-17 (Remote Access), which requires documented authorization, encryption of remote sessions, and monitoring of remote connections. NIST CSF functions PR.AC (Identity Management and Access Control) and PR.PT (Protective Technology) cover the broader protective measures that ISO 27001 6.7 requires for remote working environments.
Conclusion
People controls are where information security frameworks meet organizational reality. The eight controls in ISO 27001 Annex A covering screening, employment terms, training, discipline, termination, NDAs, remote work, and event reporting collectively define whether your ISMS is a document or a functioning program.
Start with the highest-risk gaps: access revocation at offboarding, training coverage for contractors, and the completeness of your employment security terms. These are the three areas where auditors find non-conformities most consistently.
Ready to formalize your people security program under ISO 27001? The GAICC ISO/IEC 27001 Lead Implementer Certification provides structured training on building and auditing every control domain, including the full Annex A people controls suite.
| Advance Your ISO 27001 Career with GAICC: The GAICC ISO/IEC 27001 Lead Implementer certification gives you structured training on building and auditing every ISMS control domain, including the complete Annex A people controls suite. Designed for US professionals in information security, GRC and compliance. |

