Annex A — People Controls (6.1-6.8)

Cover all 8 People controls, from pre-hire screening through post-termination responsibilities, and learn when it's legitimate to mark a control 'not applicable' in a small organization's SoA.

Easy 40m 2 tasks

Learning Objectives

  • List all 8 People controls and what each requires in one sentence
  • Explain what must happen at the moment of termination, specifically
  • Distinguish 'awareness' training (6.3) from onboarding terms (6.2)
  • Write a defensible SoA justification for excluding a People control in a sole-practitioner organization

At only 8 controls, this is the smallest Annex A theme — small enough to cover individually rather than in clusters. It follows the natural lifecycle of a person's relationship with an organization: before hiring, during employment, and after they leave.

The 8 controls, in lifecycle order

# Control What it requires
6.1 Screening Background verification checks before employment, proportional to the role's risk and any applicable law
6.2 Terms and conditions of employment Employment contracts state security responsibilities clearly, agreed to before access is granted
6.3 Security awareness, education and training Ongoing (not one-time) training appropriate to each person's role
6.4 Disciplinary process A formal, communicated process for handling confirmed security policy violations
6.5 Responsibilities after termination or change of employment What continues to apply (e.g. confidentiality) and what must happen immediately (e.g. access revocation)
6.6 Confidentiality or non-disclosure agreements Identified, documented, and regularly reviewed NDAs reflecting actual protection needs
6.7 Remote working Protecting information accessed, processed, or stored outside traditional office premises
6.8 Information security event reporting A clear, known channel for any person to report a suspected security event

The moment that matters most: 6.5

Control 6.5 is the one most often tied to real audit findings — including, notably, the exact kind of finding VigilForge's own gap analysis surfaced about itself (a lesson coming up will use that gap analysis as a full case study). The requirement has two parts that are easy to blur together:

  • Access revocation should be immediate — ideally on the person's last working day, sometimes triggered automatically by an HR system event rather than relying on a manual step someone might forget.
  • Ongoing obligations (like confidentiality of information learned during employment) don't end just because employment does — this is why 6.6 (NDAs) often extends beyond the termination date explicitly.

A gap here is rarely about bad intentions — it's almost always a process gap: no automated trigger, no checklist, no single owner confirming completion. This connects directly back to lesson 6's correction-vs-corrective-action distinction: disabling one late account is a correction; fixing the process so it never happens again is the corrective action clause 10.2 actually requires.

Awareness (6.3) is not the same as onboarding terms (6.2)

6.2 is a one-time, contractual event: you agree to your security responsibilities as a condition of employment, typically on day one. 6.3 is ongoing and role-appropriate: a developer's security training content should differ from a finance team member's, and neither should be a single session delivered once and never repeated. Confusing the two is a common Foundation-level mistake — 6.2 sets the initial expectation; 6.3 keeps it current and relevant over time.

When "not applicable" is a legitimate answer

Several People controls (6.1, 6.2, 6.4 in particular) can be genuinely not applicable for a sole practitioner or very small team with no employees or contractors — there's no one to screen, no disciplinary process needed for a team of one. This is not cheating the standard; it's an honest reflection of organizational reality. But — as covered in the SoA lesson coming up — an exclusion still needs a written justification in the SoA (e.g., "Not applicable — sole practitioner, no employees or contractors as of [date]; to be reassessed upon first hire"), not just silent omission. An auditor reviewing an unjustified blank is a legitimate finding; an auditor reviewing a properly justified N/A is not.

A new employee is hired at a mid-sized company. Place these events in the correct order and match each to its control: (a) background check completed, (b) employment contract signed including security clauses, (c) first security awareness training session, (d) employee resigns and access is revoked same day.

✦ Answer the questions to complete this task

Which control corresponds to the background check happening before the employee starts?

Which control corresponds to same-day access revocation upon resignation?

You are a sole practitioner running a small online business with no employees or contractors. Draft a one-sentence SoA justification for excluding control 6.4 (disciplinary process), following the pattern given in the lesson.

✦ Answer the questions to complete this task

Why is a silent omission of control 6.4 (no mention at all in the SoA) a worse audit outcome than a documented 'not applicable' with justification?

💪 Exercises & Challenges

📝 MCQ Easy +20 XP

Annex A People Controls — MCQ

Annex A People Controls — MCQ

Start →
⚙️ Practical Easy +30 XP

Draft an Offboarding Checklist

Draft an Offboarding Checklist

Start →
🚩 Challenge Medium +40 XP

Screening or Awareness?

Screening or Awareness?

Start →