Most security discussions jump straight to technical controls. But ISO 27001 reminds us that ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐๐ฎ๐ฟ๐๐ ๐๐ถ๐๐ต ๐ฝ๐ฒ๐ผ๐ฝ๐น๐ฒ โ long before an employee even joins the company.
Annex A.6 (People Controls) focuses on making your workforce a security asset rather than a liability. Here are the three critical phases every organization must get right:
1๏ธโฃ ๐ฃ๐ฟ๐ถ๐ผ๐ฟ ๐๐ผ ๐๐บ๐ฝ๐น๐ผ๐๐บ๐ฒ๐ป๐: ๐ฅ๐ถ๐๐ธ-๐๐ฎ๐๐ฒ๐ฑ ๐ฆ๐ฐ๐ฟ๐ฒ๐ฒ๐ป๐ถ๐ป๐ด
Itโs not just a basic background check. ISO 27001 requires screening based on the role and sensitivity of the information the person will access.
ใVerify identity, employment history, academic qualifications, and professional references.
ใThe higher the risk, the deeper the screening.
IT ensures hiring people who are both competent and trustworthy.
2๏ธโฃ ๐๐๐ฟ๐ถ๐ป๐ด ๐๐บ๐ฝ๐น๐ผ๐๐บ๐ฒ๐ป๐: ๐๐๐ถ๐น๐ฑ๐ถ๐ป๐ด ๐ฎ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐๐น๐๐๐ฟ๐ฒ
This is where many companies fall short โ treating security as a once-a-year compliance exercise.
Annex A.6 emphasizes that employees must understand and apply security policies relevant to their role.
ใDeliver ๐ฎ๐๐ฎ๐ฟ๐ฒ๐ป๐ฒ๐๐ ๐๐ฟ๐ฎ๐ถ๐ป๐ถ๐ป๐ด (e.g., secure coding, phishing, physical security).
ใMaintain a clear and fair ๐ฑ๐ถ๐๐ฐ๐ถ๐ฝ๐น๐ถ๐ป๐ฎ๐ฟ๐ ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐ for policy violations.
Security must become a habit, not a checkbox.
3๏ธโฃ ๐ง๐ฒ๐ฟ๐บ๐ถ๐ป๐ฎ๐๐ถ๐ผ๐ป ๐ผ๐ฟ ๐ฅ๐ผ๐น๐ฒ ๐๐ต๐ฎ๐ป๐ด๐ฒ: ๐ง๐ต๐ฒ ๐๐ผ๐ฟ๐ด๐ผ๐๐๐ฒ๐ป ๐ฅ๐ถ๐๐ธ
One of the weakest links in many organizations.
ใ๐ง๐ถ๐บ๐ฒ๐น๐ ๐ฟ๐ฒ๐๐ผ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ผ๐ณ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ ๐ฟ๐ถ๐ด๐ต๐๐ upon termination.
ใ๐ฃ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ ๐ฐ๐ฟ๐ฒ๐ฒ๐ฝ during internal transfers (e.g., Marketing โ Product) must be reviewed and cleaned up.
ใEnsure all company assets (devices, data, cards, etc.) are returned and securely wiped.
A strong off-boarding process is just as important as onboarding.
๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ถ๐๐ปโ๐ ๐ท๐๐๐ ๐ฎ๐ป ๐๐ง ๐ถ๐๐๐๐ฒ โ ๐ถ๐โ๐ ๐ฎ ๐ฝ๐ฒ๐ผ๐ฝ๐น๐ฒ, ๐ฝ๐ฟ๐ผ๐ฐ๐ฒ๐๐, ๐ฎ๐ป๐ฑ ๐ฐ๐๐น๐๐๐ฟ๐ฒ ๐ถ๐๐๐๐ฒ.
When HR, IT, and leadership arenโt aligned, the entire information security program is at risk.