0% found this document useful (0 votes)
2 views24 pages

HR Security Policy

HR Security Policy (1)

Uploaded by

NGUYEN
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views24 pages

HR Security Policy

HR Security Policy (1)

Uploaded by

NGUYEN
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

This document has

been downloaded
from
[Link]
Document Name HR Security Policy
Classification Internal Use Only

Document Management Information

Document Title: HR Security Policy

Document Number: ORGANISATION-HR-SEC-POL

Document Internal Use Only


Classification:

Document Status: Approved

Issue Details
Release Date DD-MM-YYYY

Revision Details
Version
Revision Date Particulars Approved by
No.

<Provide details of
<Provide name of
1.0 DD-MM-YYYY changes made on policy
Approver here>
here>

Document Contact Details


Role Name Designation

<Provide name of author <Provide designation of author


Author
here> here>

Reviewer/ <Provide name of reviewer <Provide designation of reviewer


Custodian here> here>

<Provide name of owner <Provide designation of owner


Owner
here> here>

Distribution List
Name

Need Based Circulation Only


Document Name HR Security Policy
Classification Internal Use Only

CONTENTS

1. PURPOSE ............................................................................................................................................................... 4
2. SCOPE ...................................................................................................................................................................... 4
3. TERMS AND DEFINITIONS .......................................................................................................................... 5
4. ROLES AND RESPONSIBILITIES ..............................................................................................................6
5. HR SECURITY GOVERNANCE .................................................................................................................... 7
6. PRE-EMPLOYMENT SECURITY CONTROLS .................................................................................... 8
7. DURING EMPLOYMENT SECURITY CONTROLS .......................................................................... 10
8. DISCPLINARY PROCESS ............................................................................................................................. 16
9. ROLE CHANGE & TRANSFER SECURITY CONTROLS .............................................................. 19
10. TERMINATION SECUREITY CONTROLS ......................................................................................... 20
11. EXCEPTIONS ...................................................................................................................................................... 22
12. POLICY REVIEW AND APPROVAL ...................................................................................................... 22
Document Name HR Security Policy
Classification Internal Use Only

1. PURPOSE
The purpose of this HR Security Policy is to establish principles and requirements for
managing personnel-related information security risks throughout the employee
lifecycle, including pre-employment, during employment, role changes, and
termination.

This policy aims to ensure that employees, contractors, and other personnel who have
access to the organization’s information assets understand their information security
responsibilities and comply with established security practices to protect the
confidentiality, integrity, and availability of organizational information and systems.

The policy defines controls and procedures to:

• Ensure appropriate background verification and screening of personnel,


where legally permissible

• Establish security responsibilities and obligations as part of employment or


contractual agreements

• Promote information security awareness and training among personnel

• Enforce confidentiality and acceptable use requirements

• Ensure timely access provisioning, modification, and revocation aligned with


personnel roles

• Address disciplinary actions in case of security policy violations

• Protect organizational information assets during employment transitions and


termination

This policy supports the organization’s commitment to maintaining an effective


Information Security Management System (ISMS) and ensures alignment with
applicable legal, regulatory, contractual, ISO/IEC 27001:2022, and SOC 2 Type II
requirements related to personnel security.

2. SCOPE
This policy applies to all personnel who have access to the organization’s information
assets, systems, networks, or facilities. This includes, but is not limited to:

• Full-time and part-time employees

• Contractual staff and consultants

• Temporary employees and interns

• Third-party personnel or service providers granted access to organizational


systems or information

• Individuals involved in recruitment, onboarding, management, or termination


processes related to personnel with system or information access
Document Name HR Security Policy
Classification Internal Use Only

The policy governs personnel security practices throughout the entire employment
lifecycle, including:

• Pre-employment activities such as recruitment, screening, and background


verification

• Security responsibilities and obligations during employment

• Role changes, transfers, or privilege adjustments within the organization

• Termination or separation from the organization and associated security


measures

This policy applies to all organizational locations, systems, and environments where
personnel interact with or access organizational information assets, including on-
premises, remote working environments, and cloud-based systems.

Compliance with this policy is mandatory for all personnel within its scope. Failure to
adhere to the requirements defined in this policy may result in disciplinary action,
contractual remedies, or other corrective measures, in accordance with
organizational policies and applicable legal requirements.

3. TERMS AND DEFINITIONS


Term Definition

An individual employed by the organization on a full-time or part-


Employee time basis who performs duties under the terms of an employment
agreement.

An external individual or entity engaged by the organization under


Contractor /
a contractual agreement to perform specific services and who may
Consultant
be granted access to organizational systems or information assets.

Any information, data, systems, applications, infrastructure, or


Information resources that support the organization’s business operations and
Assets require protection to maintain confidentiality, integrity, and
availability.

Information that is sensitive or proprietary in nature and requires


Confidential protection against unauthorized disclosure, access, or misuse. This
Information may include business data, customer information, intellectual
property, and internal operational data.

Elevated system or administrative access granted to authorized


Privileged
personnel to manage systems, applications, or infrastructure
Access
beyond standard user permissions.
Document Name HR Security Policy
Classification Internal Use Only

Term Definition

Access to organizational systems, networks, or information assets


Remote Work /
from locations outside the organization’s controlled physical
Remote Access
premises, including home networks or other remote environments.

Any event that may compromise the confidentiality, integrity, or


Security
availability of information assets, including unauthorized access,
Incident
data leakage, system compromise, or policy violations.

Individuals employed by vendors, service providers, or partner


Third-Party organizations who are granted access to the organization’s
Personnel systems, networks, or information assets to perform authorized
activities.

Permissions granted to personnel that allow them to access


Access Rights systems, applications, data, or facilities in accordance with their job
responsibilities.

4. ROLES AND RESPONSIBILITIES


Role Responsibilities

Provide oversight and support for personnel security practices;


Top Management ensure adequate resources are allocated for implementing HR
security controls; approve and enforce HR security policies.

Ensure security requirements are incorporated into recruitment,


Human onboarding, employment agreements, and exit procedures;
Resources (HR) coordinate background verification where applicable; maintain
personnel records related to employment lifecycle events.

Define personnel security requirements aligned with the


Information Information Security Management System (ISMS); support HR in
Security Team implementing security awareness programs; provide guidance on
security responsibilities and policy compliance.

Provision, modify, and revoke system access based on approved


IT / System
requests; enforce access control policies; support secure
Administrators
onboarding and offboarding processes.

Ensure personnel within their teams understand and comply with


Managers / information security policies; approve access requests and role-
Supervisors based privileges; report personnel-related security issues where
identified.
Document Name HR Security Policy
Classification Internal Use Only

Role Responsibilities

Comply with all information security policies and procedures;


Employees and
protect organizational information assets; report security
Contractors
incidents or suspected policy violations promptly.

Adhere to contractual security requirements and organizational


Third-Party
policies when accessing organizational systems or information
Personnel
assets; maintain confidentiality and protect sensitive information.

5. HR SECURITY GOVERNANCE
The organization shall establish and maintain a governance framework to ensure that
personnel security practices are implemented effectively and consistently across the
organization.

Human Resources, Information Security, and IT functions shall collaborate to ensure


that security requirements are integrated throughout the employee lifecycle, including
recruitment, onboarding, employment, role changes, and termination.

The HR Security Governance framework shall ensure that:

• Personnel security controls are aligned with the organization’s Information


Security Management System (ISMS) and applicable regulatory or contractual
obligations.

• Security responsibilities and expectations are clearly defined and


communicated to employees, contractors, and third-party personnel.

• HR-related security controls, including background verification, employment


agreements, and confidentiality obligations, are implemented and maintained
where applicable.

• Access provisioning, modification, and revocation processes are coordinated


between HR and IT to ensure that system access aligns with personnel roles and
responsibilities.

• Security awareness and training programs are implemented to ensure


personnel understand their responsibilities for protecting organizational
information assets.

• Security incidents or policy violations involving personnel are reported,


investigated, and addressed in accordance with organizational disciplinary and
incident management procedures.

• Periodic reviews are conducted to evaluate the effectiveness of HR security


practices and ensure alignment with organizational policies and security
objectives.
Document Name HR Security Policy
Classification Internal Use Only

The governance framework shall support continuous improvement of personnel


security controls and ensure that the organization maintains appropriate oversight of
risks associated with human factors in information security.

6. PRE-EMPLOYMENT SECURITY CONTROLS


The organization shall implement appropriate personnel security measures during the
recruitment and hiring process to ensure that individuals who may have access to
organizational information assets are suitable for their roles and understand their
responsibilities related to information security.

Pre-employment security controls are designed to reduce risks associated with


unauthorized access, misuse of systems, data breaches, or other security incidents that
may arise from personnel-related factors. These controls shall be implemented in
accordance with applicable laws, regulatory requirements, and contractual obligations.

Human Resources, in coordination with the Information Security and IT teams where
necessary, shall ensure that security considerations are integrated into the recruitment
and onboarding processes.

6.1 Background Verification

Background verification checks shall be conducted for prospective employees,


contractors, and third-party personnel prior to granting access to organizational
systems, facilities, or information assets, where legally permissible and appropriate to
the role.

Background verification activities may include, but are not limited to:

• Verification of identity and legal eligibility to work

• Validation of previous employment history

• Verification of educational qualifications and certifications

• Reference checks from previous employers or professional references

• Criminal background checks where legally permitted and relevant to the role

• Verification of professional licenses where applicable

The scope and depth of background verification shall be commensurate with the level
of access, responsibilities of the role, and associated information security risks.

Background verification records shall be maintained securely by the Human Resources


department in accordance with the organization’s data protection and record
retention policies.
Document Name HR Security Policy
Classification Internal Use Only

6.2 Role Definition and Security Responsibilities

Job descriptions and role definitions shall clearly identify information security
responsibilities associated with each position.

These responsibilities shall include, where applicable:

• Compliance with organizational information security policies and procedures

• Protection of confidential, sensitive, and proprietary information

• Appropriate use of organizational systems, applications, and information assets

• Responsibility to report suspected information security incidents or policy


violations

• Adherence to access control and data protection requirements

Security responsibilities shall be communicated to personnel during the recruitment


and onboarding process to ensure that individuals understand their obligations prior
to receiving access to organizational resources.

6.3 Employment Agreements and Security Terms

Employment contracts, offer letters, or engagement agreements shall include clauses


that define information security obligations applicable to employees, contractors,
and third-party personnel.

Such contractual terms may include:

• Compliance with the organization’s information security policies and procedures

• Appropriate use of organizational systems, networks, and devices

• Protection of confidential and sensitive information

• Restrictions on unauthorized disclosure, copying, or misuse of organizational


data

• Requirements to report information security incidents or suspected breaches

• Consequences of violating organizational security policies or contractual


obligations

These agreements shall be acknowledged and accepted by personnel prior to the


commencement of employment or engagement.
Document Name HR Security Policy
Classification Internal Use Only

6.4 Confidentiality and Non-Disclosure Agreements

Employees, contractors, and third-party personnel shall sign confidentiality or non-


disclosure agreements (NDAs) where appropriate to acknowledge their responsibility
to protect confidential and sensitive information belonging to the organization, its
customers, and its partners.

Confidentiality agreements shall address, where applicable:

• Protection of proprietary or confidential business information

• Restrictions on sharing or disclosing sensitive information to unauthorized


parties

• Protection of customer, partner, or regulated data

• Proper handling and storage of confidential information

Confidentiality obligations shall remain in effect during the period of employment or


engagement and, where applicable, after termination of employment or
contractual relationship, as defined in applicable agreements.

6.5 Pre-Employment Access Restrictions

Access to organizational systems, networks, applications, or facilities shall not be


granted to new personnel until required onboarding and verification steps are
completed, including:

• Completion of background verification where required

• Acceptance of employment agreements and security obligations

• Completion of initial onboarding requirements

Access provisioning shall follow the organization’s access control and identity
management procedures, ensuring that access is granted based on the principle of
least privilege and the individual’s approved job responsibilities.

7. DURING EMPLOYMENT SECURITY CONTROLS


The organization shall ensure that employees, contractors, and relevant third-party
personnel maintain appropriate information security practices throughout the course
of their employment or contractual engagement. Personnel who have access to
organizational information assets, systems, networks, applications, or facilities shall
comply with established security policies, procedures, standards, and acceptable use
requirements.

Human Resources, Information Security, and IT teams shall work together to ensure
that personnel are informed of their information security responsibilities, receive
appropriate training and awareness, use organizational assets securely, and promptly
report security incidents or concerns.
Document Name HR Security Policy
Classification Internal Use Only

7.1 Information Security Awareness and Training

The organization shall establish and maintain an information security awareness and
training program to ensure that personnel understand their responsibilities for
protecting organizational information assets and complying with applicable security
policies and procedures.

The awareness and training program shall be designed to:

• promote secure behavior by personnel

• reduce risks arising from human error, negligence, or malicious actions

• reinforce compliance with information security, privacy, and acceptable use


requirements

• ensure personnel remain aware of evolving security threats and organizational


expectations

7.1.1 Onboarding Security Awareness Training

All newly hired employees, contractors, interns, and relevant third-party personnel shall
complete information security awareness training as part of the onboarding process,
before or shortly after being granted access to organizational systems or information
assets.

Onboarding security awareness training shall include, as applicable:

• overview of the organization’s information security policies, procedures, and


expectations

• roles and responsibilities relating to information security

• classification, handling, storage, and protection of confidential or sensitive


information

• acceptable use of organizational systems, devices, email, internet, and


communication tools

• password hygiene, credential protection, and authentication requirements

• secure use of collaboration tools, remote access methods, and cloud-based


systems

• recognition of phishing, social engineering, malware, and other common threats

• process for reporting information security incidents, weaknesses, or suspicious


activity

• consequences of non-compliance with organizational security requirements

Completion of onboarding training shall be recorded and retained as evidence.


Document Name HR Security Policy
Classification Internal Use Only

7.1.2 Refresher Security Awareness Training

All personnel within the scope of this policy shall complete refresher information
security awareness training at least once every six (6) months.

Refresher training shall be designed to reinforce security responsibilities and address


relevant topics such as:

• emerging cyber threats and attack techniques

• recent internal or external security incidents and lessons learned

• updates to organizational security policies, procedures, or controls

• secure handling of customer, business, regulated, or confidential information

• remote working risks and secure working practices

• data protection and privacy requirements, where applicable

Participation in refresher training shall be monitored and documented.

7.1.3 Training Assessment and Effectiveness Evaluation

The organization shall assess the effectiveness of security awareness training through
appropriate evaluation mechanisms following onboarding and refresher training
sessions.

Assessment methods may include:

• quizzes or knowledge checks

• online assessments

• scenario-based questions

• interactive exercises

• periodic review of personnel understanding and behavior

Assessment results may be used to:

• determine whether the training objectives were met

• identify personnel or teams requiring additional awareness support

• improve future training content and delivery

• address recurring areas of misunderstanding or weakness

Where personnel do not satisfactorily complete awareness assessments, additional


guidance, retraining, or corrective action may be required.

7.1.4 Phishing Awareness and Simulation Exercises

The organization may conduct periodic phishing awareness activities and phishing
simulation exercises to evaluate personnel awareness of phishing and social
engineering threats.
Document Name HR Security Policy
Classification Internal Use Only

These activities may include:

• simulated phishing emails

• guidance on identifying suspicious messages, malicious links, and fraudulent


requests

• targeted re-training for personnel who fail phishing simulations

• analysis of trends and common weaknesses identified through simulation


campaigns

Results of phishing simulations may be reviewed by Information Security and


management, where appropriate, to support continual improvement of awareness
activities and reduce the likelihood of successful phishing attacks.

7.2 Communication of Information Security Policies

The organization shall communicate relevant information security policies, procedures,


standards, and guidelines to employees, contractors, and relevant third-party
personnel to ensure that they are aware of their security obligations.

Communication of policies may take place through:

• onboarding activities

• internal document repositories or policy portals

• awareness and training sessions

• management communications

• email notifications or internal collaboration platforms

Where policies or requirements are updated, affected personnel shall be informed


within a reasonable timeframe to ensure continued awareness and compliance.

7.3 Policy Acknowledgement

Employees, contractors, and relevant third-party personnel shall formally acknowledge


that they have received, read, understood, and agree to comply with applicable
information security policies and related requirements.

Acknowledgement may be obtained through:

• signed policy acknowledgement forms

• electronic acknowledgement through HR, GRC, or policy management systems

• onboarding checklists or controlled workflow tools

Records of policy acknowledgement shall be retained as evidence of communication


and acceptance of security responsibilities.
Document Name HR Security Policy
Classification Internal Use Only

7.4 Acceptable Use of Organizational Assets

Personnel shall use organizational systems, applications, devices, networks, and


information assets only for authorized business purposes and in accordance with the
organization’s Acceptable Use Policy and related security requirements.

Personnel shall:

• protect organizational assets from unauthorized access, misuse, damage, theft,


or loss

• use only approved software, tools, and services for organizational work

• avoid installing or using unauthorized applications or external storage devices

• ensure that organizational data is processed, stored, and shared only in


authorized locations and through approved methods

• avoid any activity that could adversely impact the confidentiality, integrity, or
availability of organizational systems or information

Use of organizational assets may be monitored in accordance with applicable legal,


regulatory, contractual, and organizational requirements.

7.5 Access Control Responsibilities

Access to organizational systems, applications, data, and facilities shall be granted


based on business need, approved job responsibilities, and the principle of least
privilege.

Personnel shall:

• use only the access rights assigned to them

• protect passwords, authentication tokens, keys, and other credentials from


unauthorized disclosure or misuse

• refrain from sharing user IDs, passwords, or other authentication mechanisms

• use privileged access only where authorized and strictly for approved activities

• notify the appropriate team if access is no longer required or appears excessive

• report suspected unauthorized use, compromise, or misuse of accounts or


credentials immediately

Managers, Human Resources, Information Security, and IT personnel shall coordinate


to ensure access remains appropriate throughout employment and is reviewed
periodically where required.
Document Name HR Security Policy
Classification Internal Use Only

7.6 Secure Remote Working

Personnel who work remotely or access organizational systems from locations outside
the organization’s controlled premises shall do so in accordance with the organization’s
remote working and information security requirements.

Remote working personnel shall, where applicable:

• use approved and adequately secured devices and communication channels

• connect to organizational resources only through authorized remote access


methods

• use multi-factor authentication where required

• protect devices from unauthorized access, loss, theft, or damage

• avoid exposing confidential information in public or insecure environments

• ensure that family members, visitors, or other unauthorized individuals do not


access organizational devices or information

• follow secure practices for storage, printing, discussion, and disposal of work-
related information outside organizational premises

Personnel shall maintain the same level of care and protection for organizational
information assets while working remotely as they would within office or controlled
environments.

7.7 Reporting Information Security Events

All personnel shall promptly report actual or suspected information security incidents,
vulnerabilities, weaknesses, policy violations, or unusual events through the
organization’s defined reporting channels.

Reportable events may include, but are not limited to:

• phishing emails or suspicious communications

• unauthorized access or attempted access to systems or data

• loss or theft of laptops, mobile devices, access cards, or storage media

• accidental disclosure or mishandling of confidential information

• malware infection, unusual system behavior, or suspected compromise

• inappropriate use of systems, data, or user accounts

• any observed weakness that may increase security risk

Personnel shall cooperate with incident response, investigation, containment, and


remediation activities as required.
Document Name HR Security Policy
Classification Internal Use Only

7.8 Compliance with Information Security Policies

All employees, contractors, and relevant third-party personnel shall comply with
applicable information security policies, procedures, standards, and control
requirements established by the organization.

Non-compliance with information security requirements may result in:

• disciplinary action

• revocation or restriction of access rights

• additional training or corrective action

• contractual remedies

• other actions as appropriate under organizational policies and applicable legal


or regulatory requirements

The organization shall take reasonable steps to monitor adherence to security


requirements and address deviations in a timely manner.

8. DISCPLINARY PROCESS
The organization shall establish and maintain a formal disciplinary process to address
violations of information security policies, procedures, standards, or other security-
related obligations.

The purpose of the disciplinary process is to ensure that personnel understand the
consequences of non-compliance with information security requirements and to
promote responsible behavior in protecting organizational information assets.

Employees, contractors, and relevant third-party personnel who violate information


security policies or fail to comply with established security practices may be subject to
disciplinary action in accordance with organizational policies, contractual agreements,
and applicable legal or regulatory requirements.

8.1 Applicability

The disciplinary process applies to all personnel within the scope of this policy,
including:

• Employees

• Contractors and consultants

• Temporary staff and interns

• Third-party personnel who have access to organizational systems, facilities, or


information assets

8.2 Security Policy Violations

Disciplinary actions may be initiated in response to violations such as, but not limited
to:
Document Name HR Security Policy
Classification Internal Use Only

• Unauthorized access to systems, data, or facilities

• Sharing or misuse of authentication credentials

• Unauthorized disclosure or mishandling of confidential or sensitive information

• Installation or use of unauthorized software or tools

• Failure to comply with acceptable use requirements

• Failure to report security incidents or suspicious activities

• Circumvention of security controls or safeguards

• Repeated negligence in following security procedures

8.3 Investigation of Violations

Reported or suspected violations shall be reviewed and investigated by the appropriate


functions, which may include Human Resources, Information Security, Legal, and
relevant management personnel.

Investigations shall be conducted in a fair, consistent, and confidential manner, taking


into consideration:

• the nature and severity of the violation

• whether the action was intentional, negligent, or accidental

• potential impact on organizational systems, data, customers, or partners

• previous violations or patterns of non-compliance

8.4 Disciplinary Actions

Disciplinary actions shall be proportionate to the severity and impact of the violation
and may include:

• security awareness retraining or corrective guidance

• formal warnings or reprimands

• temporary suspension of system access

• restriction or revocation of privileges

• termination of employment or contractual engagement

• legal or contractual actions where applicable

Disciplinary measures shall be applied consistently in accordance with the


organization’s HR policies, employment agreements, and applicable legal
requirements.

Disciplinary actions for violations of information security policies shall follow a


progressive approach, taking into account the nature, severity, and impact of the
Document Name HR Security Policy
Classification Internal Use Only

violation. The organization reserves the right to apply stronger actions immediately in
cases of serious misconduct or intentional security breaches.

Violation Disciplinary
Description
Occurrence Action

The employee is formally informed of the violation


Verbal Warning /
and reminded of applicable security policies.
First Violation Security Awareness
Additional awareness training or guidance may
Reinforcement
be provided.

A formal written warning is issued and


Second documented in the employee’s personnel file.
Written Warning
Violation The employee may be required to complete
mandatory security retraining.

A final written warning is issued. Access privileges


Third Final Warning and or responsibilities may be reviewed, restricted, or
Violation Privilege Review temporarily suspended depending on the nature
of the violation.

The matter may be escalated to management


Fourth Suspension or and HR for disciplinary review. Temporary
Violation Disciplinary Review suspension, restriction of access, or other
corrective actions may be applied.

In cases of repeated violations or serious


misconduct (such as intentional misuse of
Repeated or Termination of systems, unauthorized disclosure of confidential
Severe Employment or information, or deliberate bypassing of security
Violations Contract controls), employment or contractual
engagement may be terminated, and legal
action may be pursued where applicable.

NOTE: The organization reserves the right to bypass progressive disciplinary steps and
apply stronger disciplinary measures immediately in cases involving serious security
violations, intentional misconduct, data breaches, fraud, or activities that may
significantly impact the organization, its customers, or partners.

8.5 Documentation and Recordkeeping

All disciplinary actions related to information security violations shall be documented


and maintained by Human Resources or the appropriate governance function.

Records shall be retained in accordance with organizational record retention policies


and applicable legal or regulatory requirements.
Document Name HR Security Policy
Classification Internal Use Only

9. ROLE CHANGE & TRANSFER SECURITY CONTROLS


The organization shall ensure that appropriate security measures are implemented
when employees, contractors, or relevant third-party personnel change roles,
responsibilities, or departments within the organization.

Role changes, internal transfers, or promotions may result in changes to system access,
privileges, responsibilities, or exposure to sensitive information. Therefore, access rights
and security responsibilities must be reviewed and adjusted to ensure that personnel
only retain the access required to perform their new job functions.

Human Resources, Information Security, IT administrators, and relevant managers shall


coordinate to ensure that access rights are modified promptly and in accordance
with the principle of least privilege.

9.1 Access Modification and Privilege Adjustment

When a role change occurs, the organization shall ensure that system access rights are
reviewed and updated to reflect the new responsibilities of the individual.

This process may include:

• Granting access to systems, applications, or data required for the new role

• Removing access privileges that are no longer required

• Adjusting levels of access where responsibilities change

• Updating group memberships, permissions, or system roles

• Reviewing and approving privileged or administrative access where applicable

All access modifications shall follow the organization’s access management and
authorization procedures.

9.2 Access Review During Internal Transfers

When employees move between teams, departments, or projects, the organization


shall ensure that access rights associated with their previous role are reviewed and
removed where no longer required.

Managers and system owners shall verify that personnel retain only the minimum
level of access necessary to perform their duties.

Periodic access reviews may also be conducted to confirm that access rights remain
appropriate following role changes.

9.3 Authorization and Approval

All access changes resulting from role changes or internal transfers shall be formally
requested and approved by the appropriate authority, which may include:

• the employee’s new manager or supervisor

• system or application owners


Document Name HR Security Policy
Classification Internal Use Only

• Information Security or IT administrators, where required

Approvals shall be documented and maintained as part of the organization’s access


management records.

9.4 Communication of Updated Responsibilities

Personnel undergoing role changes or transfers shall be informed of any new


information security responsibilities associated with their updated role.

Where applicable, personnel may be required to:

• complete additional security awareness training relevant to their new


responsibilities

• acknowledge updated policies or procedures

• comply with revised access or data handling requirements

10. TERMINATION SECUREITY CONTROLS


The organization shall ensure that appropriate security measures are implemented
when employees, contractors, or third-party personnel leave the organization or when
their engagement with the organization is terminated.

Termination or separation processes must ensure that access to organizational


systems, facilities, and information assets is promptly revoked, and that organizational
assets and confidential information are protected.

Human Resources, Information Security, IT administrators, and relevant managers shall


coordinate to ensure that termination procedures are carried out in a timely and
controlled manner to prevent unauthorized access or misuse of organizational
resources.

10.1 Access Revocation

Access to organizational systems, networks, applications, databases, and other


information assets shall be revoked promptly upon termination or completion of
engagement.

The organization shall ensure that:

• User accounts are disabled or removed in a timely manner

• Access to internal systems, applications, and cloud platforms is revoked

• Privileged or administrative access rights are immediately terminated

• Remote access mechanisms such as VPN or secure gateways are disabled

• Physical access credentials such as ID cards or access badges are deactivated


where applicable

For planned terminations, access revocation shall be coordinated to occur at or before


the effective time of termination.
Document Name HR Security Policy
Classification Internal Use Only

10.2 Return of Organizational Assets

Upon termination or completion of engagement, personnel shall return all


organizational assets issued to them.

Assets may include, but are not limited to:

• Laptops, desktops, mobile devices, or tablets

• Access cards, identification badges, or security tokens

• Storage devices, removable media, or backup devices

• Documents, records, or printed materials containing organizational information

• Keys or other physical access items

Managers and the Human Resources department shall ensure that asset return is
verified and documented during the exit process.

10.3 Protection of Organizational Information

Personnel leaving the organization shall not retain copies of organizational data,
confidential information, intellectual property, or proprietary materials.

Where applicable, IT administrators may perform necessary checks to ensure that


organizational data stored on assigned devices, accounts, or cloud services has been
secured, transferred, or removed in accordance with organizational procedures.

10.4 Exit Procedures and Obligations

As part of the termination or separation process, personnel may be reminded of their


ongoing obligations related to:

• Protection of confidential or proprietary information

• Non-disclosure commitments

• Intellectual property protection

• Compliance with applicable contractual or legal obligations

Exit procedures may include exit interviews, acknowledgement of continuing


confidentiality obligations, or other steps required by the organization.

10.5 Documentation of Termination Activities

All termination-related security activities shall be documented and retained as


evidence that appropriate security controls were implemented.

Such documentation may include:

• confirmation of access revocation

• records of asset return

• exit checklist completion


Document Name HR Security Policy
Classification Internal Use Only

• acknowledgement of post-employment confidentiality obligations

These records shall be maintained in accordance with the organization’s record


retention and security policies.

11. EXCEPTIONS
Any exception to the requirements defined in this HR Security Policy must be formally
reviewed, approved, and documented.

Personnel or departments seeking an exception to any requirement in this policy shall


submit a request to the appropriate authority, typically involving Human Resources,
Information Security, and relevant management personnel.

Exception requests shall include:

• justification for the exception

• scope and duration of the exception

• potential risks associated with the exception

• proposed compensating controls or mitigating measures, where applicable

All exceptions shall be formally evaluated and approved prior to implementation.


Approved exceptions shall be documented and periodically reviewed to ensure that
they remain valid and that associated risks are appropriately managed.

Temporary exceptions shall be granted only for a defined period and shall be re-
evaluated upon expiration.

12. POLICY REVIEW AND APPROVAL


This HR Security Policy shall be reviewed periodically to ensure its continued suitability,
adequacy, and effectiveness in supporting the organization’s information security
objectives.

12.1 Policy Review

This policy shall be reviewed at least annually, or earlier if there are:

• significant changes to organizational structure, personnel practices, or systems

• changes in legal, regulatory, or contractual requirements

• updates to ISO/IEC 27001, SOC 2, or other applicable standards

• significant information security incidents involving personnel-related risks

• recommendations from internal or external audits

Updates to the policy shall be documented and communicated to relevant personnel.

12.2 Policy Approval


Document Name HR Security Policy
Classification Internal Use Only

This policy shall be approved by Top Management or the designated governing


authority responsible for information security governance.

Approved versions of the policy shall be maintained as controlled documents within


the organization’s document management system.

12.3 Document Control

The organization shall maintain appropriate document control practices to ensure that:

• the current approved version of the policy is accessible to relevant personnel

• obsolete or superseded versions are appropriately archived

• policy updates are tracked through version control and revision history
Document Name HR Security Policy
Classification Internal Use Only

You might also like