This document has
been downloaded
from
[Link]
Document Name HR Security Policy
Classification Internal Use Only
Document Management Information
Document Title: HR Security Policy
Document Number: ORGANISATION-HR-SEC-POL
Document Internal Use Only
Classification:
Document Status: Approved
Issue Details
Release Date DD-MM-YYYY
Revision Details
Version
Revision Date Particulars Approved by
No.
<Provide details of
<Provide name of
1.0 DD-MM-YYYY changes made on policy
Approver here>
here>
Document Contact Details
Role Name Designation
<Provide name of author <Provide designation of author
Author
here> here>
Reviewer/ <Provide name of reviewer <Provide designation of reviewer
Custodian here> here>
<Provide name of owner <Provide designation of owner
Owner
here> here>
Distribution List
Name
Need Based Circulation Only
Document Name HR Security Policy
Classification Internal Use Only
CONTENTS
1. PURPOSE ............................................................................................................................................................... 4
2. SCOPE ...................................................................................................................................................................... 4
3. TERMS AND DEFINITIONS .......................................................................................................................... 5
4. ROLES AND RESPONSIBILITIES ..............................................................................................................6
5. HR SECURITY GOVERNANCE .................................................................................................................... 7
6. PRE-EMPLOYMENT SECURITY CONTROLS .................................................................................... 8
7. DURING EMPLOYMENT SECURITY CONTROLS .......................................................................... 10
8. DISCPLINARY PROCESS ............................................................................................................................. 16
9. ROLE CHANGE & TRANSFER SECURITY CONTROLS .............................................................. 19
10. TERMINATION SECUREITY CONTROLS ......................................................................................... 20
11. EXCEPTIONS ...................................................................................................................................................... 22
12. POLICY REVIEW AND APPROVAL ...................................................................................................... 22
Document Name HR Security Policy
Classification Internal Use Only
1. PURPOSE
The purpose of this HR Security Policy is to establish principles and requirements for
managing personnel-related information security risks throughout the employee
lifecycle, including pre-employment, during employment, role changes, and
termination.
This policy aims to ensure that employees, contractors, and other personnel who have
access to the organization’s information assets understand their information security
responsibilities and comply with established security practices to protect the
confidentiality, integrity, and availability of organizational information and systems.
The policy defines controls and procedures to:
• Ensure appropriate background verification and screening of personnel,
where legally permissible
• Establish security responsibilities and obligations as part of employment or
contractual agreements
• Promote information security awareness and training among personnel
• Enforce confidentiality and acceptable use requirements
• Ensure timely access provisioning, modification, and revocation aligned with
personnel roles
• Address disciplinary actions in case of security policy violations
• Protect organizational information assets during employment transitions and
termination
This policy supports the organization’s commitment to maintaining an effective
Information Security Management System (ISMS) and ensures alignment with
applicable legal, regulatory, contractual, ISO/IEC 27001:2022, and SOC 2 Type II
requirements related to personnel security.
2. SCOPE
This policy applies to all personnel who have access to the organization’s information
assets, systems, networks, or facilities. This includes, but is not limited to:
• Full-time and part-time employees
• Contractual staff and consultants
• Temporary employees and interns
• Third-party personnel or service providers granted access to organizational
systems or information
• Individuals involved in recruitment, onboarding, management, or termination
processes related to personnel with system or information access
Document Name HR Security Policy
Classification Internal Use Only
The policy governs personnel security practices throughout the entire employment
lifecycle, including:
• Pre-employment activities such as recruitment, screening, and background
verification
• Security responsibilities and obligations during employment
• Role changes, transfers, or privilege adjustments within the organization
• Termination or separation from the organization and associated security
measures
This policy applies to all organizational locations, systems, and environments where
personnel interact with or access organizational information assets, including on-
premises, remote working environments, and cloud-based systems.
Compliance with this policy is mandatory for all personnel within its scope. Failure to
adhere to the requirements defined in this policy may result in disciplinary action,
contractual remedies, or other corrective measures, in accordance with
organizational policies and applicable legal requirements.
3. TERMS AND DEFINITIONS
Term Definition
An individual employed by the organization on a full-time or part-
Employee time basis who performs duties under the terms of an employment
agreement.
An external individual or entity engaged by the organization under
Contractor /
a contractual agreement to perform specific services and who may
Consultant
be granted access to organizational systems or information assets.
Any information, data, systems, applications, infrastructure, or
Information resources that support the organization’s business operations and
Assets require protection to maintain confidentiality, integrity, and
availability.
Information that is sensitive or proprietary in nature and requires
Confidential protection against unauthorized disclosure, access, or misuse. This
Information may include business data, customer information, intellectual
property, and internal operational data.
Elevated system or administrative access granted to authorized
Privileged
personnel to manage systems, applications, or infrastructure
Access
beyond standard user permissions.
Document Name HR Security Policy
Classification Internal Use Only
Term Definition
Access to organizational systems, networks, or information assets
Remote Work /
from locations outside the organization’s controlled physical
Remote Access
premises, including home networks or other remote environments.
Any event that may compromise the confidentiality, integrity, or
Security
availability of information assets, including unauthorized access,
Incident
data leakage, system compromise, or policy violations.
Individuals employed by vendors, service providers, or partner
Third-Party organizations who are granted access to the organization’s
Personnel systems, networks, or information assets to perform authorized
activities.
Permissions granted to personnel that allow them to access
Access Rights systems, applications, data, or facilities in accordance with their job
responsibilities.
4. ROLES AND RESPONSIBILITIES
Role Responsibilities
Provide oversight and support for personnel security practices;
Top Management ensure adequate resources are allocated for implementing HR
security controls; approve and enforce HR security policies.
Ensure security requirements are incorporated into recruitment,
Human onboarding, employment agreements, and exit procedures;
Resources (HR) coordinate background verification where applicable; maintain
personnel records related to employment lifecycle events.
Define personnel security requirements aligned with the
Information Information Security Management System (ISMS); support HR in
Security Team implementing security awareness programs; provide guidance on
security responsibilities and policy compliance.
Provision, modify, and revoke system access based on approved
IT / System
requests; enforce access control policies; support secure
Administrators
onboarding and offboarding processes.
Ensure personnel within their teams understand and comply with
Managers / information security policies; approve access requests and role-
Supervisors based privileges; report personnel-related security issues where
identified.
Document Name HR Security Policy
Classification Internal Use Only
Role Responsibilities
Comply with all information security policies and procedures;
Employees and
protect organizational information assets; report security
Contractors
incidents or suspected policy violations promptly.
Adhere to contractual security requirements and organizational
Third-Party
policies when accessing organizational systems or information
Personnel
assets; maintain confidentiality and protect sensitive information.
5. HR SECURITY GOVERNANCE
The organization shall establish and maintain a governance framework to ensure that
personnel security practices are implemented effectively and consistently across the
organization.
Human Resources, Information Security, and IT functions shall collaborate to ensure
that security requirements are integrated throughout the employee lifecycle, including
recruitment, onboarding, employment, role changes, and termination.
The HR Security Governance framework shall ensure that:
• Personnel security controls are aligned with the organization’s Information
Security Management System (ISMS) and applicable regulatory or contractual
obligations.
• Security responsibilities and expectations are clearly defined and
communicated to employees, contractors, and third-party personnel.
• HR-related security controls, including background verification, employment
agreements, and confidentiality obligations, are implemented and maintained
where applicable.
• Access provisioning, modification, and revocation processes are coordinated
between HR and IT to ensure that system access aligns with personnel roles and
responsibilities.
• Security awareness and training programs are implemented to ensure
personnel understand their responsibilities for protecting organizational
information assets.
• Security incidents or policy violations involving personnel are reported,
investigated, and addressed in accordance with organizational disciplinary and
incident management procedures.
• Periodic reviews are conducted to evaluate the effectiveness of HR security
practices and ensure alignment with organizational policies and security
objectives.
Document Name HR Security Policy
Classification Internal Use Only
The governance framework shall support continuous improvement of personnel
security controls and ensure that the organization maintains appropriate oversight of
risks associated with human factors in information security.
6. PRE-EMPLOYMENT SECURITY CONTROLS
The organization shall implement appropriate personnel security measures during the
recruitment and hiring process to ensure that individuals who may have access to
organizational information assets are suitable for their roles and understand their
responsibilities related to information security.
Pre-employment security controls are designed to reduce risks associated with
unauthorized access, misuse of systems, data breaches, or other security incidents that
may arise from personnel-related factors. These controls shall be implemented in
accordance with applicable laws, regulatory requirements, and contractual obligations.
Human Resources, in coordination with the Information Security and IT teams where
necessary, shall ensure that security considerations are integrated into the recruitment
and onboarding processes.
6.1 Background Verification
Background verification checks shall be conducted for prospective employees,
contractors, and third-party personnel prior to granting access to organizational
systems, facilities, or information assets, where legally permissible and appropriate to
the role.
Background verification activities may include, but are not limited to:
• Verification of identity and legal eligibility to work
• Validation of previous employment history
• Verification of educational qualifications and certifications
• Reference checks from previous employers or professional references
• Criminal background checks where legally permitted and relevant to the role
• Verification of professional licenses where applicable
The scope and depth of background verification shall be commensurate with the level
of access, responsibilities of the role, and associated information security risks.
Background verification records shall be maintained securely by the Human Resources
department in accordance with the organization’s data protection and record
retention policies.
Document Name HR Security Policy
Classification Internal Use Only
6.2 Role Definition and Security Responsibilities
Job descriptions and role definitions shall clearly identify information security
responsibilities associated with each position.
These responsibilities shall include, where applicable:
• Compliance with organizational information security policies and procedures
• Protection of confidential, sensitive, and proprietary information
• Appropriate use of organizational systems, applications, and information assets
• Responsibility to report suspected information security incidents or policy
violations
• Adherence to access control and data protection requirements
Security responsibilities shall be communicated to personnel during the recruitment
and onboarding process to ensure that individuals understand their obligations prior
to receiving access to organizational resources.
6.3 Employment Agreements and Security Terms
Employment contracts, offer letters, or engagement agreements shall include clauses
that define information security obligations applicable to employees, contractors,
and third-party personnel.
Such contractual terms may include:
• Compliance with the organization’s information security policies and procedures
• Appropriate use of organizational systems, networks, and devices
• Protection of confidential and sensitive information
• Restrictions on unauthorized disclosure, copying, or misuse of organizational
data
• Requirements to report information security incidents or suspected breaches
• Consequences of violating organizational security policies or contractual
obligations
These agreements shall be acknowledged and accepted by personnel prior to the
commencement of employment or engagement.
Document Name HR Security Policy
Classification Internal Use Only
6.4 Confidentiality and Non-Disclosure Agreements
Employees, contractors, and third-party personnel shall sign confidentiality or non-
disclosure agreements (NDAs) where appropriate to acknowledge their responsibility
to protect confidential and sensitive information belonging to the organization, its
customers, and its partners.
Confidentiality agreements shall address, where applicable:
• Protection of proprietary or confidential business information
• Restrictions on sharing or disclosing sensitive information to unauthorized
parties
• Protection of customer, partner, or regulated data
• Proper handling and storage of confidential information
Confidentiality obligations shall remain in effect during the period of employment or
engagement and, where applicable, after termination of employment or
contractual relationship, as defined in applicable agreements.
6.5 Pre-Employment Access Restrictions
Access to organizational systems, networks, applications, or facilities shall not be
granted to new personnel until required onboarding and verification steps are
completed, including:
• Completion of background verification where required
• Acceptance of employment agreements and security obligations
• Completion of initial onboarding requirements
Access provisioning shall follow the organization’s access control and identity
management procedures, ensuring that access is granted based on the principle of
least privilege and the individual’s approved job responsibilities.
7. DURING EMPLOYMENT SECURITY CONTROLS
The organization shall ensure that employees, contractors, and relevant third-party
personnel maintain appropriate information security practices throughout the course
of their employment or contractual engagement. Personnel who have access to
organizational information assets, systems, networks, applications, or facilities shall
comply with established security policies, procedures, standards, and acceptable use
requirements.
Human Resources, Information Security, and IT teams shall work together to ensure
that personnel are informed of their information security responsibilities, receive
appropriate training and awareness, use organizational assets securely, and promptly
report security incidents or concerns.
Document Name HR Security Policy
Classification Internal Use Only
7.1 Information Security Awareness and Training
The organization shall establish and maintain an information security awareness and
training program to ensure that personnel understand their responsibilities for
protecting organizational information assets and complying with applicable security
policies and procedures.
The awareness and training program shall be designed to:
• promote secure behavior by personnel
• reduce risks arising from human error, negligence, or malicious actions
• reinforce compliance with information security, privacy, and acceptable use
requirements
• ensure personnel remain aware of evolving security threats and organizational
expectations
7.1.1 Onboarding Security Awareness Training
All newly hired employees, contractors, interns, and relevant third-party personnel shall
complete information security awareness training as part of the onboarding process,
before or shortly after being granted access to organizational systems or information
assets.
Onboarding security awareness training shall include, as applicable:
• overview of the organization’s information security policies, procedures, and
expectations
• roles and responsibilities relating to information security
• classification, handling, storage, and protection of confidential or sensitive
information
• acceptable use of organizational systems, devices, email, internet, and
communication tools
• password hygiene, credential protection, and authentication requirements
• secure use of collaboration tools, remote access methods, and cloud-based
systems
• recognition of phishing, social engineering, malware, and other common threats
• process for reporting information security incidents, weaknesses, or suspicious
activity
• consequences of non-compliance with organizational security requirements
Completion of onboarding training shall be recorded and retained as evidence.
Document Name HR Security Policy
Classification Internal Use Only
7.1.2 Refresher Security Awareness Training
All personnel within the scope of this policy shall complete refresher information
security awareness training at least once every six (6) months.
Refresher training shall be designed to reinforce security responsibilities and address
relevant topics such as:
• emerging cyber threats and attack techniques
• recent internal or external security incidents and lessons learned
• updates to organizational security policies, procedures, or controls
• secure handling of customer, business, regulated, or confidential information
• remote working risks and secure working practices
• data protection and privacy requirements, where applicable
Participation in refresher training shall be monitored and documented.
7.1.3 Training Assessment and Effectiveness Evaluation
The organization shall assess the effectiveness of security awareness training through
appropriate evaluation mechanisms following onboarding and refresher training
sessions.
Assessment methods may include:
• quizzes or knowledge checks
• online assessments
• scenario-based questions
• interactive exercises
• periodic review of personnel understanding and behavior
Assessment results may be used to:
• determine whether the training objectives were met
• identify personnel or teams requiring additional awareness support
• improve future training content and delivery
• address recurring areas of misunderstanding or weakness
Where personnel do not satisfactorily complete awareness assessments, additional
guidance, retraining, or corrective action may be required.
7.1.4 Phishing Awareness and Simulation Exercises
The organization may conduct periodic phishing awareness activities and phishing
simulation exercises to evaluate personnel awareness of phishing and social
engineering threats.
Document Name HR Security Policy
Classification Internal Use Only
These activities may include:
• simulated phishing emails
• guidance on identifying suspicious messages, malicious links, and fraudulent
requests
• targeted re-training for personnel who fail phishing simulations
• analysis of trends and common weaknesses identified through simulation
campaigns
Results of phishing simulations may be reviewed by Information Security and
management, where appropriate, to support continual improvement of awareness
activities and reduce the likelihood of successful phishing attacks.
7.2 Communication of Information Security Policies
The organization shall communicate relevant information security policies, procedures,
standards, and guidelines to employees, contractors, and relevant third-party
personnel to ensure that they are aware of their security obligations.
Communication of policies may take place through:
• onboarding activities
• internal document repositories or policy portals
• awareness and training sessions
• management communications
• email notifications or internal collaboration platforms
Where policies or requirements are updated, affected personnel shall be informed
within a reasonable timeframe to ensure continued awareness and compliance.
7.3 Policy Acknowledgement
Employees, contractors, and relevant third-party personnel shall formally acknowledge
that they have received, read, understood, and agree to comply with applicable
information security policies and related requirements.
Acknowledgement may be obtained through:
• signed policy acknowledgement forms
• electronic acknowledgement through HR, GRC, or policy management systems
• onboarding checklists or controlled workflow tools
Records of policy acknowledgement shall be retained as evidence of communication
and acceptance of security responsibilities.
Document Name HR Security Policy
Classification Internal Use Only
7.4 Acceptable Use of Organizational Assets
Personnel shall use organizational systems, applications, devices, networks, and
information assets only for authorized business purposes and in accordance with the
organization’s Acceptable Use Policy and related security requirements.
Personnel shall:
• protect organizational assets from unauthorized access, misuse, damage, theft,
or loss
• use only approved software, tools, and services for organizational work
• avoid installing or using unauthorized applications or external storage devices
• ensure that organizational data is processed, stored, and shared only in
authorized locations and through approved methods
• avoid any activity that could adversely impact the confidentiality, integrity, or
availability of organizational systems or information
Use of organizational assets may be monitored in accordance with applicable legal,
regulatory, contractual, and organizational requirements.
7.5 Access Control Responsibilities
Access to organizational systems, applications, data, and facilities shall be granted
based on business need, approved job responsibilities, and the principle of least
privilege.
Personnel shall:
• use only the access rights assigned to them
• protect passwords, authentication tokens, keys, and other credentials from
unauthorized disclosure or misuse
• refrain from sharing user IDs, passwords, or other authentication mechanisms
• use privileged access only where authorized and strictly for approved activities
• notify the appropriate team if access is no longer required or appears excessive
• report suspected unauthorized use, compromise, or misuse of accounts or
credentials immediately
Managers, Human Resources, Information Security, and IT personnel shall coordinate
to ensure access remains appropriate throughout employment and is reviewed
periodically where required.
Document Name HR Security Policy
Classification Internal Use Only
7.6 Secure Remote Working
Personnel who work remotely or access organizational systems from locations outside
the organization’s controlled premises shall do so in accordance with the organization’s
remote working and information security requirements.
Remote working personnel shall, where applicable:
• use approved and adequately secured devices and communication channels
• connect to organizational resources only through authorized remote access
methods
• use multi-factor authentication where required
• protect devices from unauthorized access, loss, theft, or damage
• avoid exposing confidential information in public or insecure environments
• ensure that family members, visitors, or other unauthorized individuals do not
access organizational devices or information
• follow secure practices for storage, printing, discussion, and disposal of work-
related information outside organizational premises
Personnel shall maintain the same level of care and protection for organizational
information assets while working remotely as they would within office or controlled
environments.
7.7 Reporting Information Security Events
All personnel shall promptly report actual or suspected information security incidents,
vulnerabilities, weaknesses, policy violations, or unusual events through the
organization’s defined reporting channels.
Reportable events may include, but are not limited to:
• phishing emails or suspicious communications
• unauthorized access or attempted access to systems or data
• loss or theft of laptops, mobile devices, access cards, or storage media
• accidental disclosure or mishandling of confidential information
• malware infection, unusual system behavior, or suspected compromise
• inappropriate use of systems, data, or user accounts
• any observed weakness that may increase security risk
Personnel shall cooperate with incident response, investigation, containment, and
remediation activities as required.
Document Name HR Security Policy
Classification Internal Use Only
7.8 Compliance with Information Security Policies
All employees, contractors, and relevant third-party personnel shall comply with
applicable information security policies, procedures, standards, and control
requirements established by the organization.
Non-compliance with information security requirements may result in:
• disciplinary action
• revocation or restriction of access rights
• additional training or corrective action
• contractual remedies
• other actions as appropriate under organizational policies and applicable legal
or regulatory requirements
The organization shall take reasonable steps to monitor adherence to security
requirements and address deviations in a timely manner.
8. DISCPLINARY PROCESS
The organization shall establish and maintain a formal disciplinary process to address
violations of information security policies, procedures, standards, or other security-
related obligations.
The purpose of the disciplinary process is to ensure that personnel understand the
consequences of non-compliance with information security requirements and to
promote responsible behavior in protecting organizational information assets.
Employees, contractors, and relevant third-party personnel who violate information
security policies or fail to comply with established security practices may be subject to
disciplinary action in accordance with organizational policies, contractual agreements,
and applicable legal or regulatory requirements.
8.1 Applicability
The disciplinary process applies to all personnel within the scope of this policy,
including:
• Employees
• Contractors and consultants
• Temporary staff and interns
• Third-party personnel who have access to organizational systems, facilities, or
information assets
8.2 Security Policy Violations
Disciplinary actions may be initiated in response to violations such as, but not limited
to:
Document Name HR Security Policy
Classification Internal Use Only
• Unauthorized access to systems, data, or facilities
• Sharing or misuse of authentication credentials
• Unauthorized disclosure or mishandling of confidential or sensitive information
• Installation or use of unauthorized software or tools
• Failure to comply with acceptable use requirements
• Failure to report security incidents or suspicious activities
• Circumvention of security controls or safeguards
• Repeated negligence in following security procedures
8.3 Investigation of Violations
Reported or suspected violations shall be reviewed and investigated by the appropriate
functions, which may include Human Resources, Information Security, Legal, and
relevant management personnel.
Investigations shall be conducted in a fair, consistent, and confidential manner, taking
into consideration:
• the nature and severity of the violation
• whether the action was intentional, negligent, or accidental
• potential impact on organizational systems, data, customers, or partners
• previous violations or patterns of non-compliance
8.4 Disciplinary Actions
Disciplinary actions shall be proportionate to the severity and impact of the violation
and may include:
• security awareness retraining or corrective guidance
• formal warnings or reprimands
• temporary suspension of system access
• restriction or revocation of privileges
• termination of employment or contractual engagement
• legal or contractual actions where applicable
Disciplinary measures shall be applied consistently in accordance with the
organization’s HR policies, employment agreements, and applicable legal
requirements.
Disciplinary actions for violations of information security policies shall follow a
progressive approach, taking into account the nature, severity, and impact of the
Document Name HR Security Policy
Classification Internal Use Only
violation. The organization reserves the right to apply stronger actions immediately in
cases of serious misconduct or intentional security breaches.
Violation Disciplinary
Description
Occurrence Action
The employee is formally informed of the violation
Verbal Warning /
and reminded of applicable security policies.
First Violation Security Awareness
Additional awareness training or guidance may
Reinforcement
be provided.
A formal written warning is issued and
Second documented in the employee’s personnel file.
Written Warning
Violation The employee may be required to complete
mandatory security retraining.
A final written warning is issued. Access privileges
Third Final Warning and or responsibilities may be reviewed, restricted, or
Violation Privilege Review temporarily suspended depending on the nature
of the violation.
The matter may be escalated to management
Fourth Suspension or and HR for disciplinary review. Temporary
Violation Disciplinary Review suspension, restriction of access, or other
corrective actions may be applied.
In cases of repeated violations or serious
misconduct (such as intentional misuse of
Repeated or Termination of systems, unauthorized disclosure of confidential
Severe Employment or information, or deliberate bypassing of security
Violations Contract controls), employment or contractual
engagement may be terminated, and legal
action may be pursued where applicable.
NOTE: The organization reserves the right to bypass progressive disciplinary steps and
apply stronger disciplinary measures immediately in cases involving serious security
violations, intentional misconduct, data breaches, fraud, or activities that may
significantly impact the organization, its customers, or partners.
8.5 Documentation and Recordkeeping
All disciplinary actions related to information security violations shall be documented
and maintained by Human Resources or the appropriate governance function.
Records shall be retained in accordance with organizational record retention policies
and applicable legal or regulatory requirements.
Document Name HR Security Policy
Classification Internal Use Only
9. ROLE CHANGE & TRANSFER SECURITY CONTROLS
The organization shall ensure that appropriate security measures are implemented
when employees, contractors, or relevant third-party personnel change roles,
responsibilities, or departments within the organization.
Role changes, internal transfers, or promotions may result in changes to system access,
privileges, responsibilities, or exposure to sensitive information. Therefore, access rights
and security responsibilities must be reviewed and adjusted to ensure that personnel
only retain the access required to perform their new job functions.
Human Resources, Information Security, IT administrators, and relevant managers shall
coordinate to ensure that access rights are modified promptly and in accordance
with the principle of least privilege.
9.1 Access Modification and Privilege Adjustment
When a role change occurs, the organization shall ensure that system access rights are
reviewed and updated to reflect the new responsibilities of the individual.
This process may include:
• Granting access to systems, applications, or data required for the new role
• Removing access privileges that are no longer required
• Adjusting levels of access where responsibilities change
• Updating group memberships, permissions, or system roles
• Reviewing and approving privileged or administrative access where applicable
All access modifications shall follow the organization’s access management and
authorization procedures.
9.2 Access Review During Internal Transfers
When employees move between teams, departments, or projects, the organization
shall ensure that access rights associated with their previous role are reviewed and
removed where no longer required.
Managers and system owners shall verify that personnel retain only the minimum
level of access necessary to perform their duties.
Periodic access reviews may also be conducted to confirm that access rights remain
appropriate following role changes.
9.3 Authorization and Approval
All access changes resulting from role changes or internal transfers shall be formally
requested and approved by the appropriate authority, which may include:
• the employee’s new manager or supervisor
• system or application owners
Document Name HR Security Policy
Classification Internal Use Only
• Information Security or IT administrators, where required
Approvals shall be documented and maintained as part of the organization’s access
management records.
9.4 Communication of Updated Responsibilities
Personnel undergoing role changes or transfers shall be informed of any new
information security responsibilities associated with their updated role.
Where applicable, personnel may be required to:
• complete additional security awareness training relevant to their new
responsibilities
• acknowledge updated policies or procedures
• comply with revised access or data handling requirements
10. TERMINATION SECUREITY CONTROLS
The organization shall ensure that appropriate security measures are implemented
when employees, contractors, or third-party personnel leave the organization or when
their engagement with the organization is terminated.
Termination or separation processes must ensure that access to organizational
systems, facilities, and information assets is promptly revoked, and that organizational
assets and confidential information are protected.
Human Resources, Information Security, IT administrators, and relevant managers shall
coordinate to ensure that termination procedures are carried out in a timely and
controlled manner to prevent unauthorized access or misuse of organizational
resources.
10.1 Access Revocation
Access to organizational systems, networks, applications, databases, and other
information assets shall be revoked promptly upon termination or completion of
engagement.
The organization shall ensure that:
• User accounts are disabled or removed in a timely manner
• Access to internal systems, applications, and cloud platforms is revoked
• Privileged or administrative access rights are immediately terminated
• Remote access mechanisms such as VPN or secure gateways are disabled
• Physical access credentials such as ID cards or access badges are deactivated
where applicable
For planned terminations, access revocation shall be coordinated to occur at or before
the effective time of termination.
Document Name HR Security Policy
Classification Internal Use Only
10.2 Return of Organizational Assets
Upon termination or completion of engagement, personnel shall return all
organizational assets issued to them.
Assets may include, but are not limited to:
• Laptops, desktops, mobile devices, or tablets
• Access cards, identification badges, or security tokens
• Storage devices, removable media, or backup devices
• Documents, records, or printed materials containing organizational information
• Keys or other physical access items
Managers and the Human Resources department shall ensure that asset return is
verified and documented during the exit process.
10.3 Protection of Organizational Information
Personnel leaving the organization shall not retain copies of organizational data,
confidential information, intellectual property, or proprietary materials.
Where applicable, IT administrators may perform necessary checks to ensure that
organizational data stored on assigned devices, accounts, or cloud services has been
secured, transferred, or removed in accordance with organizational procedures.
10.4 Exit Procedures and Obligations
As part of the termination or separation process, personnel may be reminded of their
ongoing obligations related to:
• Protection of confidential or proprietary information
• Non-disclosure commitments
• Intellectual property protection
• Compliance with applicable contractual or legal obligations
Exit procedures may include exit interviews, acknowledgement of continuing
confidentiality obligations, or other steps required by the organization.
10.5 Documentation of Termination Activities
All termination-related security activities shall be documented and retained as
evidence that appropriate security controls were implemented.
Such documentation may include:
• confirmation of access revocation
• records of asset return
• exit checklist completion
Document Name HR Security Policy
Classification Internal Use Only
• acknowledgement of post-employment confidentiality obligations
These records shall be maintained in accordance with the organization’s record
retention and security policies.
11. EXCEPTIONS
Any exception to the requirements defined in this HR Security Policy must be formally
reviewed, approved, and documented.
Personnel or departments seeking an exception to any requirement in this policy shall
submit a request to the appropriate authority, typically involving Human Resources,
Information Security, and relevant management personnel.
Exception requests shall include:
• justification for the exception
• scope and duration of the exception
• potential risks associated with the exception
• proposed compensating controls or mitigating measures, where applicable
All exceptions shall be formally evaluated and approved prior to implementation.
Approved exceptions shall be documented and periodically reviewed to ensure that
they remain valid and that associated risks are appropriately managed.
Temporary exceptions shall be granted only for a defined period and shall be re-
evaluated upon expiration.
12. POLICY REVIEW AND APPROVAL
This HR Security Policy shall be reviewed periodically to ensure its continued suitability,
adequacy, and effectiveness in supporting the organization’s information security
objectives.
12.1 Policy Review
This policy shall be reviewed at least annually, or earlier if there are:
• significant changes to organizational structure, personnel practices, or systems
• changes in legal, regulatory, or contractual requirements
• updates to ISO/IEC 27001, SOC 2, or other applicable standards
• significant information security incidents involving personnel-related risks
• recommendations from internal or external audits
Updates to the policy shall be documented and communicated to relevant personnel.
12.2 Policy Approval
Document Name HR Security Policy
Classification Internal Use Only
This policy shall be approved by Top Management or the designated governing
authority responsible for information security governance.
Approved versions of the policy shall be maintained as controlled documents within
the organization’s document management system.
12.3 Document Control
The organization shall maintain appropriate document control practices to ensure that:
• the current approved version of the policy is accessible to relevant personnel
• obsolete or superseded versions are appropriately archived
• policy updates are tracked through version control and revision history
Document Name HR Security Policy
Classification Internal Use Only