ISO27001

Disciplinary Process and Remote Working Security: ISO 27001 Controls 6.4–6.7

Disciplinary Process and Remote Working Security: ISO 27001 Controls 6.4–6.7
Loading advertisement...
13

The Friday afternoon that cost Halcyon Freight Brokers $340,000

Derek Voss was fired on a Friday at 4:15 p.m.

He'd been regional sales operations manager at Halcyon Freight Brokers, a 180-person logistics brokerage outside Charlotte, for six years. HR had spent three weeks building a case: falsified customer rebate records that had quietly diverted roughly $60,000 in credits to accounts he controlled through a relative. When the CFO finally confronted him, Derek didn't deny it. He was walked out with a box of desk items and a stern reminder that his signed confidentiality agreement — buried somewhere in his onboarding paperwork from 2020 — was "still in effect." Nobody could tell him exactly what that meant, and frankly, nobody in the room had read it recently either.

HR sent the standard termination notice to IT that afternoon. It sat in a shared inbox that nobody checks after 3 p.m. on Fridays. The offboarding ticket wasn't opened until Monday morning at 9:40 a.m.

In the gap between Friday afternoon and Monday morning, Derek logged into Halcyon's CRM twice from his home laptop and once from a personal iPad that had been enrolled in the company's mail system eighteen months earlier under a "just this once" exception for a business trip — an exception nobody ever revoked, formalized, or reviewed. He exported the full regional customer contract list: 11,400 records, including negotiated pricing terms for Halcyon's twenty largest accounts. He synced the export to a personal Dropbox folder and, investigators later determined, forwarded a subset of it to a competing brokerage where he'd already accepted an offer.

By the time IT disabled his account Monday morning, the data was gone and the account was already logged in from an IP address nowhere near his home.

I was brought in six weeks later, after the second of Halcyon's anchor accounts — worth $1.2 million in annual freight volume between them — quietly moved to the competitor, which had somehow priced a bid within two dollars of Halcyon's actual margin. Between forensic investigation, outside counsel, breach notification to affected customers, and the lost accounts themselves, Halcyon's board put the total cost of that weekend at just north of $340,000, not counting the reputational damage that doesn't show up on an invoice.

Here's the part that made this a genuinely painful engagement rather than a merely expensive one: every individual person at Halcyon had, in isolation, done something defensible. HR followed a termination process. IT eventually disabled the account. Derek had, in fact, signed an NDA. What Halcyon didn't have was the connective tissue between those actions — a disciplinary process that triggered a security response, a defined offboarding timeline with teeth, a confidentiality obligation anyone had actually reinforced, and any governance at all over the personal devices Derek used to do his job remotely. Four separate gaps, each one a distinct ISO 27001 control, each one small enough to seem forgivable on its own and catastrophic in combination.

Controls 6.4 through 6.7 exist precisely for this seam — the point where an employment decision becomes a security event. This article walks through all four: a formal disciplinary process (6.4), the responsibilities that survive termination or a change of role (6.5), confidentiality and non-disclosure agreements (6.6), and the security measures that protect information when people work outside your walls (6.7).

Who this is for

This is written for HR leaders, information security managers, and the ISO 27001 implementers who have to get HR and IT to agree on a joint procedure — usually for the first time. If you're building or auditing your ISMS and your organization has ever fired someone, changed someone's role, had someone sign an NDA, or let anyone work from home, these four controls apply to you; there's no scoping them out. By the end, you'll have a disciplinary procedure tied directly to security policy violations, an offboarding and role-change checklist with named owners, an NDA framework covering who signs what and when it gets refreshed, and a remote and hybrid working security standard built to survive an external audit.

The four controls at a glance

Controls 6.4 through 6.7 sit inside Annex A's People controls theme (6.1–6.8), and they're the back half of the employee lifecycle — the part that runs from "something went wrong" through "this person no longer works here or no longer has this role" through "this person is now working from a kitchen table in another city." I've found organizations that nail 6.1–6.3 (screening, terms of employment, and awareness training — see the People Controls Overview) frequently stumble here, because these four controls require HR, Legal, IT, and line managers to move in lockstep, and most organizations have never built that muscle.

Control

Name

Core question it answers

Primary owners

6.4

Disciplinary process

What happens, fairly and consistently, when someone violates security policy?

HR, Legal, Information Security

6.5

Responsibilities after termination or change of employment

What obligations survive when someone leaves or changes roles, and who enforces them?

HR, IT Security, Line Manager

6.6

Confidentiality or non-disclosure agreements

What confidentiality commitments are documented, current, and enforceable?

Legal, HR

6.7

Remote working

What protects information when it's accessed, processed, or stored off-premises?

IT Security, Line Manager

Each of these controls has natural touchpoints elsewhere in Annex A. 6.5 leans directly on access rights removal under control 5.18 and on return of assets under control 5.11. 6.7 leans on user endpoint device management, control 8.1, and on the terms established at onboarding under control 6.2, terms and conditions of employment. Keep that web of cross-references in mind as we go — auditors will follow it, and so should you. If you're still building out the terminology behind these cross-references, our ISO 27001 Glossary of Terms is a fast way to get every stakeholder speaking the same language before the disagreements start.

Control 6.4: Disciplinary process, done fairly and consistently

ISO 27002:2022's guidance on control 6.4 is blunt about the goal: personnel and other relevant interested parties who commit an information security policy violation need to face formal, communicated, consistently applied consequences. Not because ISO 27001 wants organizations to be punitive — the standard is explicit that the process should account for factors like the nature and gravity of the violation, its impact, whether it was a first offense or a pattern, whether the person was adequately trained, and applicable legal, statutory, and contractual obligations — but because the absence of a process is what actually creates risk.

I've sat through more employment tribunals and internal investigations than I'd like as an expert witness, and the pattern is depressingly consistent: it's almost never the disciplinary action itself that gets an organization in legal trouble. It's the inconsistency. Two employees commit functionally the same violation — say, both email a spreadsheet of customer data to a personal account — and one gets fired while the other gets a verbal warning, with the difference explained by nothing more defensible than "the manager liked one of them better." That's not a security failure anymore; it's a discrimination claim waiting to happen, and I'll walk through exactly this scenario in the case studies below.

"The auditors don't actually care whether you fired someone or gave them a warning. They care whether you can show me the same violation got the same response six months apart, across two different departments, with two different managers. That consistency is the entire control." — Priya Natarajan, CISO, Bellwether Health Systems

Building a defensible process

A defensible disciplinary process under 6.4 has five components, and I insist on documenting all five as a single procedure rather than scattering them across an HR handbook and a security policy that never reference each other.

Step

Owner

Timeframe

Output

1. Detection and reporting

Any employee, security team, monitoring tooling

Immediate

Incident or violation report logged

2. Triage and severity classification

Information Security + HR jointly

Within 1 business day

Severity tier assigned, investigation scope defined

3. Investigation

HR, Legal, IT Security (evidence collection)

Proportionate to severity, typically 3–15 business days

Documented findings, evidence preserved

4. Decision and action

HR with Legal sign-off; Information Security consulted

Within 5 business days of investigation close

Documented decision with rationale, linked to policy clause violated

5. Communication and record-keeping

HR

At time of decision

Written notice to individual, confidential case file retained

Notice that step 1 deliberately overlaps with your incident management process under controls 5.24–5.28 — a policy violation discovered through log monitoring or a colleague's report often is a security incident before it's a disciplinary matter, and the two processes need a defined handoff point rather than running in parallel and duplicating (or contradicting) each other's findings.

Severity tiers keep the process consistent

The single highest-leverage document I build with clients for 6.4 is a severity matrix. It doesn't replace judgment — genuine edge cases will always need Legal and HR discretion — but it gives everyone a shared reference point before a real case forces the conversation under time pressure.

Tier

Example violations

Typical first response

Typical repeat response

Documentation required

Tier 1 — Minor, unintentional

Leaving a workstation unlocked; misplacing a printed document internally

Verbal coaching, reference to awareness training

Written warning

Manager note in HR file

Tier 2 — Moderate, negligent

Sharing a password with a colleague; ignoring a mandatory patch/update prompt repeatedly

Formal written warning, mandatory retraining

Suspension or final warning

HR case file, security team notified

Tier 3 — Serious, willful

Disabling security controls (e.g., antivirus, MFA) to bypass friction; unauthorized data export

Suspension pending investigation, final written warning

Termination

Full investigation file, Legal review, evidence preserved

Tier 4 — Severe, malicious or criminal

Data theft, fraud, sabotage, unauthorized access for personal gain

Immediate suspension, termination likely, law enforcement referral considered

Termination, referral to authorities

Full forensic evidence package, Legal and possibly regulator involvement

I map every documented information security policy against this matrix during implementation, so that when someone violates the acceptable use provisions in the information security policy, there's no ambiguity about which tier applies before anyone's emotions are running high.

What auditors actually check

Certification auditors sampling control 6.4 rarely ask to see a specific termination case (though they may, with appropriate anonymization). More often they'll ask three things: does a documented disciplinary procedure exist and is it referenced in your information security policy suite; can you produce evidence that it's been communicated to personnel (typically through the same channel as your security awareness and training program under control 6.3); and can you show at least one real (or realistic, in a young ISMS) example of the process being followed end to end. If your organization genuinely hasn't had a policy violation since certification scope was defined, I still recommend a tabletop walkthrough documented as evidence — auditors respect a rehearsed process almost as much as a proven one.

Control 6.5: Responsibilities after termination or change of employment

Control 6.5 gets summarized in most training materials as "offboarding," and that's not wrong, but it undersells the scope. The control explicitly covers two distinct events: termination (voluntary resignation, involuntary termination, contract expiry, retirement) and change of employment (promotion, demotion, transfer, a contractor converting to employee, a change in job function that alters what systems and data someone needs). Most organizations have a reasonably mature process for the first and almost nothing for the second — and role changes are, in my experience, the more common source of access creep I find during gap assessments.

"Everybody remembers to offboard the person who quits. Almost nobody remembers to offboard the old role of the person who got promoted. Six months later they've still got warehouse-floor access from before they moved into finance, and nobody can tell me why." — Marcus Feld, HR Director, Kestrel Manufacturing

Termination vs. role change: different triggers, same discipline

Scenario

What must happen

Typical failure mode

Involuntary termination (for cause)

Immediate access revocation, often same-day or same-hour; asset recovery scheduled before departure if possible

Delay between HR decision and IT notification (exactly the Halcyon gap)

Involuntary termination (redundancy/layoff)

Access revocation timed with formal notice; asset recovery logistics (shipping labels, drop-off)

Bulk layoffs overwhelming IT's manual deprovisioning capacity

Voluntary resignation

Access revocation effective last working day; NDA and post-employment obligations reiterated in exit interview

Long notice periods leaving access live for weeks with no re-review

Contract/fixed-term expiry

Access set to expire automatically at contract end date

Manual processes forgetting contractors who were never in the automated HR feed

Role change (promotion/transfer)

Old access removed, new access provisioned — not just added on top of the old

"Access accretion": new rights granted, old rights never removed

Extended leave (parental, medical, sabbatical)

Access suspended or restricted for duration; reinstated on return with a fresh review

Access left fully active and unmonitored for months

The offboarding and role-change checklist

This is the table I hand to clients and tell them to laminate. It exists to make sure the actions required by 6.5 are actually distributed across the controls that execute them — 6.5 defines the obligation, but 5.18 access rights and 5.11 return of assets do the operational work.

Task

Related control

Owner

Timing

Evidence retained

HR notifies IT Security and line manager of departure/change

6.5

HR

Same day decision is finalized

Notification timestamp in HR/ITSM system

Full inventory of systems, applications, and data the individual can access

5.18

IT Security

Prior to or on last day

Access review report

Revoke or modify access rights (accounts, VPN, shared drives, SaaS apps, physical badges)

5.18

IT Security

Same day for involuntary termination; last working day otherwise

Deprovisioning ticket with timestamps

Recall company-issued endpoint devices (laptop, phone, tokens)

5.11 / 8.1

Line manager / IT

Last working day, or scheduled courier for remote staff

Signed asset return form

Remove or wipe corporate data from any personal (BYOD) devices

6.7 / 8.1

IT Security

Same day as access revocation

MDM wipe confirmation

Retrieve or invalidate physical assets: keys, access cards, uniforms, ID badges

5.11

Facilities / Line manager

Last working day

Signed asset return form

Reiterate surviving confidentiality and NDA obligations in exit interview

6.5 / 6.6

HR

Exit interview

Signed acknowledgment

Redirect or archive email and reassign ownership of shared files/accounts

5.18

IT Security

Within 1–3 business days

Ownership transfer log

Update org chart, access registers, and asset registers

5.9 / 5.18

IT Security / HR

Within 5 business days

Updated register with version date

Notify third parties/vendors who granted the individual direct access

5.19

IT Security

Within 3 business days

Vendor notification record

Close out with confirmation to HR that all steps completed

6.5

IT Security

Within 5 business days

Signed-off offboarding checklist

That last row matters more than it looks. Every audit finding I've written against control 6.5 traces back to the same root cause: no single person confirmed the checklist was complete. Individual steps got done in isolation, nobody closed the loop, and three months later a departed contractor's VPN credential was still technically live.

Offboarding flow across 6.5, 5.11, and 5.18

Timing is the control

If I had to reduce control 6.5 to one design principle, it's this: the gap between the decision and the action is where all the risk lives. Halcyon's entire $340,000 loss happened inside a 64-hour gap between a Friday termination decision and a Monday IT ticket. I push every client toward a same-business-day SLA for involuntary terminations specifically, with access suspension (not necessarily full deprovisioning, which can wait for asset recovery) happening before the employee leaves the building, not after. For voluntary resignations with notice periods, I recommend a mid-notice access review — trimming access to only what's needed for a productive handover, rather than leaving full privileges live until the final day.

Control 6.6: Confidentiality and non-disclosure agreements

Control 6.6 requires organizations to identify, document, regularly review, and get personnel and relevant external parties to sign confidentiality or non-disclosure agreements that reflect the organization's actual protection needs. The phrase that trips people up is "reflect the organization's needs" — ISO 27001 isn't satisfied by a generic template pulled off the internet and signed once at onboarding. It wants an NDA framework that's deliberately scoped, reviewed, and current.

"I've reviewed hundreds of NDAs in litigation. The ones that hold up in court are never the longest ones — they're the ones that actually define what 'confidential' means for that specific business, instead of copying boilerplate from a template nobody customized." — Sana Okafor, Legal Counsel, Bramwell & Voss LLP

NDA types you actually need

Most organizations need more than one NDA template, and I typically build a small family of them rather than one document trying to cover every relationship.

NDA type

When used

Key parties

Typical duration

Employee confidentiality agreement

Signed at onboarding, part of the employment contract or as a standalone document

Employer and employee

Duration of employment plus a defined survival period (often 3–5 years, sometimes indefinite for trade secrets)

Contractor/consultant NDA

Signed before engagement begins, before any access is granted

Organization and contractor/consultant

Duration of engagement plus survival period, aligned to contract terms

Mutual NDA

Used when both parties will exchange confidential information (e.g., due diligence, joint ventures, partnerships)

Two organizations

Fixed term of negotiation/relationship plus survival period

Unilateral (one-way) NDA

Used when only the organization is disclosing (e.g., to a prospective vendor evaluating a solution)

Organization (discloser) and third party (recipient)

Fixed term, often 1–3 years

Executive/board-level NDA

Signed by directors, executives, or advisors with access to strategic, financial, or M&A information

Organization and executive/board member

Duration of role plus extended survival period given sensitivity

What a defensible NDA actually contains

I keep a standing checklist of the clauses an NDA needs to be enforceable and useful, not just present. This isn't legal advice — every NDA should be reviewed by qualified counsel in the relevant jurisdiction — but it's the practical content list I bring to that legal review.

Clause

Why it matters

Clear definition of "confidential information"

Vague definitions are the single most common reason NDAs fail to hold up; tie the definition to your information classification scheme under control 5.12

Explicit exclusions (publicly available info, independently developed info)

Protects enforceability and shows the agreement is reasonable, not overbroad

Obligations of the receiving party

What they must and must not do with the information

Duration of confidentiality obligation, including post-relationship survival

Confidentiality that expires the day someone leaves is functionally worthless

Permitted disclosures (e.g., legally compelled disclosure, disclosure to auditors)

Prevents the agreement from being technically breached by legitimate activity

Return or destruction of information on termination

Ties directly to control 5.11, return of assets

Remedies and governing law

Establishes what happens on breach and where disputes are resolved

Signature, date, and version reference

Enables the review cadence below — an unversioned NDA can't be tracked

Review cadence: NDAs are not sign-once documents

The "regularly review" language in control 6.6 is often the part organizations skip entirely, because it's easy to treat a signed NDA as a permanent artifact. I build the review cadence around defined triggers rather than a blanket annual review of every signed document, which doesn't scale past a few hundred people.

Trigger

Review action

Owner

New hire onboarding

Sign current version of employee confidentiality agreement

HR

Role change granting access to new sensitivity tiers

Sign supplemental confidentiality acknowledgment scoped to new data

HR / Line manager

New contractor/vendor engagement

Sign contractor NDA before any system or data access is granted

Procurement / Legal

Annual policy review cycle

Legal reviews NDA templates against current legal, regulatory, and business context

Legal

Material change in law or jurisdiction

Ad hoc review and re-issuance where required

Legal

Termination or offboarding

Reaffirm ongoing obligations in exit interview, provide copy of surviving terms

HR (as part of the 6.5 checklist above)

Organizations building a full ISMS documentation set often want to go deeper into NDA drafting than a single section here can cover — templates for each relationship type, jurisdictional variations, and specific trade secret language are worth their own reference, which is exactly what our dedicated Control 6.6: Confidentiality and NDAs guide covers.

Control 6.7: Remote working

Control 6.7 requires security measures whenever personnel work remotely, to protect information that's accessed, processed, or stored outside organizational premises. Since 2020, this control has gone from a niche requirement mostly relevant to field sales and traveling executives to one of the highest-risk controls in the entire framework for most organizations, because "remote" now describes a meaningful fraction of the workforce, not an edge case.

"Remote working used to mean a VP checking email from a hotel lobby twice a year. Now it means forty percent of my workforce processing customer data from home networks I have zero visibility into. The risk didn't get smaller when it became normal — it got bigger and quieter." — Tom Reyes, IT Security Manager, Duvalier Logistics

The risk landscape remote work actually creates

Home and hybrid work introduce risks that simply don't exist inside a controlled office: unmanaged home networks (a router that hasn't been patched in three years, sitting on the same network as a smart TV with known vulnerabilities), shared living spaces where screens are visible to family members or roommates, public Wi-Fi at cafés and airports, devices left in vehicles or hotel rooms, and — as with Derek Voss's iPad — informal exceptions to device policy that never get formalized or reviewed. None of these are exotic; they're the ordinary conditions of working from somewhere that isn't the office, and control 6.7 exists to make sure "ordinary" doesn't mean "unmanaged."

The remote working control stack

I organize remote working controls into four layers, because trying to solve "remote work security" as one undifferentiated problem produces vague policies nobody can actually implement. Each layer has a distinct owner and distinct tooling.

Layer

Control objective

Implementation examples

Related Annex A control

Device

Only managed, secured endpoints process organizational data remotely

Full-disk encryption, mandatory OS and patch updates, endpoint detection and response, screen-lock timeout, remote wipe capability

8.1 User endpoint devices

Network

Connections to organizational systems are authenticated and encrypted

Mandatory VPN or zero-trust network access, MFA on all remote logins, prohibition or restriction of public Wi-Fi for sensitive work, secured home router baseline guidance

8.20 Networks security, 8.5 Secure authentication

Physical

Information isn't exposed through the physical environment the person works in

Privacy screens, clean desk practice at home, locking devices when unattended, guidance on confidential calls in shared spaces

Aligned with physical controls theme (7.x) applied to a non-organizational location

Data

Information itself remains protected regardless of where it's processed

Restriction on local storage of sensitive data (cloud-only processing where feasible), data loss prevention tooling, classification-aware access restrictions

8.12 Data leakage prevention, 5.12 Classification of information

Control 8.1 (user endpoint devices) doesn't yet have a standalone deep-dive in this series, so treat the device-layer guidance above as the working baseline until that technological controls coverage is published.

Home, hybrid, and travel: not the same risk profile

Not every remote scenario deserves the same controls. I've seen organizations write a single "remote work policy" that's simultaneously too strict for someone working from a spare bedroom and too loose for someone working from an airport lounge.

Scenario

Primary risks

Baseline controls

Fixed home office

Household network security, shared device access, family/visitor exposure

Managed router baseline guidance, screen lock policy, dedicated work device

Hybrid (office + home, irregular)

Devices moving between environments, inconsistent connectivity, physical loss in transit

Full-disk encryption, cable locks or secure transport bags, VPN required outside office network

Business travel (domestic)

Public Wi-Fi, shoulder-surfing in transit, device left unattended in hotels

Mandatory VPN, privacy screen, hotel safe usage guidance, no sensitive calls in open areas

International travel

All of the above, plus border search risk, foreign surveillance risk, data residency/export concerns

Loaner/burner devices for high-risk destinations, minimal data at rest, legal review of destination-specific risk

Field/customer-site work

Access from client networks, physical document handling on someone else's premises

VPN mandatory before any access, no use of client-provided Wi-Fi for internal systems, document handling procedure

A note on BYOD

Bring-your-own-device arrangements sit at the collision point of controls 6.7 and 8.1, and they're where I find the most policy-reality gaps. Organizations frequently have a written policy prohibiting or tightly restricting BYOD, and a parallel informal reality — exactly like Derek Voss's iPad — where individual exceptions get granted verbally, never documented, and never revisited. If you're going to allow BYOD at all, do it deliberately.

BYOD approach

What it requires

Risk if ungoverned

Prohibited entirely

Technical enforcement (conditional access blocking unmanaged devices), clear policy communication

Shadow IT: employees route around the prohibition using personal devices anyway

Allowed with MDM enrollment

Mobile device management agent, minimum OS version, remote wipe capability, containerized corporate data

Employees resist enrollment due to privacy concerns over personal device

Allowed for email/calendar only, no document access

Conditional access policies scoped narrowly, app-level protection

Scope creep — "email only" quietly expands to file access over time

Fully unmanaged (not recommended)

None — by definition ungoverned

Exactly the Halcyon Freight Brokers scenario: an unmanaged personal device with live access and no offboarding hook

If BYOD is allowed under any model, it needs to appear explicitly in your terms and conditions of employment under control 6.2 and in the offboarding checklist above — a personal device enrolled for corporate access is an asset that has to be un-enrolled at termination just as reliably as a company laptop has to be returned.

Common mistakes across 6.4–6.7

I see the same handful of failure patterns across nearly every organization I assess, regardless of industry or size.

Mistake

Why it happens

Fix

Disciplinary action taken with no reference to a documented policy clause

HR and Legal handle discipline as an employment-law matter disconnected from the ISMS

Every disciplinary decision cites the specific security policy clause violated

Offboarding treated as an IT ticket instead of a cross-functional checklist

No single owner accountable for confirming full completion

Assign an offboarding checklist owner (see the table above) who signs off completion

NDAs signed once at onboarding and never revisited

"Set and forget" mentality treats signature as a one-time compliance box

Trigger-based review cadence (new role, new engagement, annual legal review)

Remote work policy exists but BYOD exceptions are granted informally outside it

Managers want to be helpful and grant one-off access without going through IT

Formal exception process with expiry date and mandatory review

Role changes update systems access but never revoke the old role's access

Provisioning teams add new access on request; nobody proactively removes old access

Treat every role change as a mini-offboarding: remove first, then provision

Remote working policy assumes a home office and doesn't address travel or field work

Policy written before hybrid/travel became common, never updated

Segment the policy by scenario, as in the home/hybrid/travel table above

Disciplinary severity varies by manager rather than by violation

No shared reference point exists before a real case forces the decision

Adopt and train on a severity matrix (see the Tier 1–4 table above)

Case studies

Halcyon Freight Brokers: closing the offboarding gap

I've already walked through what went wrong at Halcyon. What matters for this article is what changed afterward. Working with their HR and IT leadership, we rebuilt the termination-to-deprovisioning path as a same-business-day SLA: HR's termination decision now triggers an automated, time-stamped ticket to IT Security the moment it's finalized in the HR system, not a manually forwarded email. Access suspension for involuntary terminations happens before the employee is informed, not after. Every device — company-issued or the handful of formally approved BYOD exceptions — is now tracked in an asset register with an explicit revocation step tied to the offboarding checklist. Eighteen months after implementation, Halcyon has processed eleven involuntary terminations and thirty-four voluntary departures with zero repeat incidents, and their cyber insurance renewal premium dropped 12% after the insurer's underwriter reviewed the new offboarding evidence during renewal.

Solenne Cosmetics: a laptop, a café, and a delayed launch

A mid-market cosmetics brand I'll call Solenne Cosmetics had a marketing manager working from a café ahead of a major product launch. She stepped away from her table for roughly four minutes to collect an order; her laptop, unlocked and displaying the unreleased Q3 product roadmap, was gone when she returned. The laptop wasn't encrypted at the disk level — a gap that predated any formal remote work policy — and while the company couldn't confirm the data was actually exfiltrated rather than the device simply being resold for hardware value, they had no way to prove it hadn't been, which under their disclosure obligations meant treating it as a confirmed exposure. Incident response, forensic device-history review, and legal consultation cost roughly $85,000, and the product team elected to shift the launch timeline by seven weeks out of caution about competitive positioning — a delay Solenne's own finance team estimated cost approximately $400,000 in lost first-mover advantage. The fix was almost embarrassingly basic: mandatory full-disk encryption enforced through device management before any laptop could connect to corporate systems, a screen-lock timeout reduced to two minutes, and a remote working policy that explicitly required devices to be secured (locked, out of sight, or on the person) whenever unattended in a public space. Solenne's next annual audit cited this as a positive corrective action closure rather than a finding.

Prairie Grain Cooperative: the inconsistency that became a lawsuit

Prairie Grain Cooperative, an agricultural cooperative with about 400 employees across several regional offices, had two employees in different offices independently email spreadsheets containing member financial data to their personal accounts — both, they later stated, intending to "work on it over the weekend," a rationalization neither of us found persuasive but which mattered less than what happened next. One employee, in an office where the branch manager was risk-averse and had recently read about a data breach in the trade press, was terminated the same week. The other, in a different office under a different manager, received a verbal warning and no documentation at all. Eleven months later, the terminated employee filed a discrimination claim, correctly pointing out that the disparate treatment for materially identical conduct had no documented rationale — because none existed. Prairie Grain settled for $210,000 rather than litigate a case they knew they'd struggle to defend, given they had no severity matrix, no documented process, and no record of the second employee's incident at all. Post-settlement, we built exactly the kind of tiered severity matrix described earlier in this article, trained every manager and HR partner on it, and made joint IT Security and HR sign-off mandatory for any Tier 3 or Tier 4 decision — removing individual managers' discretion on the cases where discretion had proven most dangerous.

Roles and responsibilities across the four controls

Because these controls cut across HR, Legal, IT Security, and line management, I always document an explicit responsibility matrix rather than assuming it's obvious who owns what.

Activity

HR

IT Security

Line Manager

Legal

DPO/Privacy

Classify severity of a policy violation

Consulted

Accountable (jointly with HR)

Informed

Consulted

Informed if personal data involved

Investigate a disciplinary matter

Accountable

Supports (evidence/logs)

Consulted

Consulted

Consulted if personal data involved

Revoke access on termination

Informs

Accountable

Informed

—

—

Recover physical/technical assets

Informed

Supports

Accountable

—

—

Draft and maintain NDA templates

Consulted

Consulted

—

Accountable

Consulted

Trigger NDA re-signature on role change

Accountable

Informed

Consulted

Consulted

—

Approve BYOD exceptions

Informed

Accountable

Requests

—

Consulted

Maintain remote working policy

Consulted

Accountable

Informed

Consulted

Consulted

Evidence auditors expect to see

When a certification body auditor samples these four controls, I brief clients to have a specific evidence packet ready rather than scrambling to assemble it during the audit itself.

Control

Documentary evidence

Operational evidence

6.4

Documented disciplinary procedure; reference in information security policy; training records

At least one worked example (real or tabletop) of the process end to end

6.5

Offboarding/role-change procedure; termination checklist template

Sample of completed offboarding checklists with timestamps; access review logs

6.6

NDA templates by relationship type; review cadence policy

Signed NDA register; evidence of re-signature on role change or new engagement

6.7

Remote working policy; BYOD policy (if applicable)

MDM enrollment records; VPN/MFA enforcement configuration; device encryption compliance report

Most of this evidence should already exist as a natural byproduct of your Statement of Applicability documentation and your broader mandatory documents set — if you're still assembling that baseline, our Mandatory Documents Checklist walks through exactly what a certification body expects to find, control by control. Before your next surveillance audit, it's also worth running this evidence packet against our Internal Audit Checklist, which includes a dedicated section for People controls sampling.

Turning the back half of the employee lifecycle into a business advantage

It's tempting to treat controls 6.4 through 6.7 as pure compliance overhead — the unglamorous paperwork of firing people, taking back laptops, and telling remote workers to lock their screens. I'd push back on that framing. Every one of the case studies above is really a story about operational maturity, not just security: Halcyon's insurer rewarded their rebuilt offboarding process with a lower premium; Prairie Grain's disciplinary consistency directly reduces their employment litigation exposure going forward, independent of any security benefit; and Solenne's encryption mandate protects intellectual property regardless of whether the threat is a stolen laptop or a lost one. These controls, done well, make an organization more defensible in front of a regulator, more attractive to enterprise customers running vendor security questionnaires, and measurably less exposed to the kind of six-figure incident that tends to follow a Friday-afternoon termination or an unlocked laptop in a café.

These four controls also sit at the intersection of ISO 27001 with other frameworks your organization may already be answerable to. A SOC 2 Type II audit will scrutinize your HR-and-offboarding evidence trail almost identically to how an ISO 27001 auditor does — a well-run SOC 2 offboarding and termination control satisfies much of the same evidence expectation. And if your remote workforce processes personal data of EU residents, your remote working controls under 6.7 directly support your GDPR obligations around technical and organizational security measures, since a lost unencrypted laptop containing personal data is a notifiable breach under GDPR regardless of what ISO 27001 says about it.

If you're building out this part of your ISMS from scratch, don't try to solve all four controls simultaneously with a single sprawling policy document. Start with the disciplinary severity matrix and the offboarding checklist — they're the two most likely to surface a real gap immediately, exactly as they did at Halcyon and Prairie Grain — then layer in the NDA review cadence and the remote working control stack once the personnel foundation is solid. Our Information Security Policy Template includes starting language for all four of these controls that you can adapt to your organization's actual risk profile rather than writing from a blank page, and PentesterWorld's Complete ISO 27001 Implementation Guide walks through sequencing these People controls against the rest of your Annex A rollout.

"The organizations that pass their audit on these controls without a finding are never the ones with the fanciest policy document. They're the ones where I ask an HR generalist and an IT admin the same question about a hypothetical termination and get the same answer from both of them." — Elena Castillo, Internal Auditor, Northgate Assurance

"We rebuilt our BYOD program after a near-miss that never made it into a case study anywhere, thankfully. The lesson that stuck with my team wasn't 'ban personal devices.' It was 'nothing informal survives contact with an offboarding.' If it's not in the register, it's not going to get revoked." — Diego Marsh, Head of People Ops, Fenwick Digital

If your organization is still mapping how these four controls fit into your broader Statement of Applicability, or you want a second set of eyes on whether your disciplinary and offboarding evidence would hold up under a certification body's scrutiny, PentesterWorld's ISO 27001 advisory team runs exactly this kind of gap assessment — reach out and we'll walk your HR and IT Security leads through a joint readiness review before your auditor does.

Frequently asked questions

Does ISO 27001 require us to fire someone for a security policy violation?

No. Control 6.4 requires a process for responding proportionately and consistently — it doesn't mandate termination as the default or only outcome. ISO 27002 guidance explicitly calls for weighing the nature, gravity, and impact of the violation, along with factors like training adequacy and whether it's a first offense, before deciding on a response.

How is control 6.5 different from control 5.11, return of assets?

6.5 is the broader obligation: it covers all responsibilities that survive termination or a role change, including confidentiality, non-compete or non-solicitation terms where applicable, and continued compliance with data protection duties — not just physical and technical asset return. 5.11 is one operational component that executes part of what 6.5 requires; access revocation under 5.18 is another.

Do NDAs need to be separate documents from the employment contract?

Not necessarily. Confidentiality obligations can be embedded within the employment contract itself (often as part of the terms and conditions of employment under control 6.2), or issued as standalone agreements. What matters for control 6.6 is that the obligation exists, is documented, is scoped to your actual protection needs, and is reviewed — not the specific document structure.

Is remote working mandatory to allow under ISO 27001?

No. ISO 27001 doesn't require an organization to permit remote working at all. Control 6.7 only applies to the extent that remote working does happen — if your organization prohibits it entirely and enforces that prohibition, the control is satisfied by the prohibition itself, documented and communicated.

How long do post-employment confidentiality obligations last?

This is a legal question that varies by jurisdiction and the nature of the information, which is exactly why control 6.6 requires regular review rather than a one-time answer. Trade secret protections may extend indefinitely; other confidential business information might have a defined survival period (commonly three to five years) specified in the NDA itself. Have counsel set this per NDA type rather than assuming a single default across your organization.

Do contractors and third parties need the same disciplinary process as employees?

The disciplinary process itself typically applies formally to direct employees, since it's grounded in the employment relationship. For contractors and third parties, the equivalent mechanism is usually contractual — a breach clause tied to the confidentiality agreement or supplier contract that allows termination of the engagement and, where warranted, legal action. Control 6.4's language deliberately includes "other relevant interested parties," so your process should at minimum define how violations by non-employees get escalated and actioned.

What evidence do auditors want to see for 6.4–6.7?

See the evidence table above — in short, documented procedures for each control, plus operational proof they're actually followed: worked disciplinary examples, completed offboarding checklists, a signed NDA register with review history, and technical configuration evidence (MDM, VPN, encryption enforcement) for remote working.

Does allowing BYOD automatically violate control 6.7?

No. BYOD is compatible with control 6.7 as long as it's governed deliberately — enrolled in mobile device management, scoped to defined data access levels, and included in your offboarding process so access can be revoked and corporate data wiped on departure. What violates the control isn't BYOD itself; it's ungoverned BYOD, like the informal exception that helped sink Halcyon Freight Brokers.

13

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!