HRS-08: Are provisions and/or terms for adherence to established information governance
and security policies included within employment agreements?
The agreement between the employee and organization should include—but is not limited to—a confidentiality or non-disclosure agreement if the employee will have access to confidential data.
Policy statements relevant to the employee/contractor should be communicated through training.
Employee legal responsibilities regarding their rights as an employee of the organization (i.e., whistleblower, data protection regulations, etc.) should include guidance on how to handle both physical and digital assets.
The organization should take appropriate and proportionate action if an employee is in breach of an agreement
Control implemented
Control ownership
Description
The organization includes within the employment agreements provisions
and/or terms for adherence to established information governance and security
policies.