People are a company's greatest resource and, at the same time, one of its biggest attack paths. That is why ISO 27001 has a section dedicated to them alone.
When we talk about security, we think of systems. But every system is used by a person, and a person has a journey: they arrive, they work for a while, then they leave or change role. At every step there is a risk, and at every step something can be done.
That is exactly what ISO 27001 does on the human resources side. Annex A, the standard's list of controls, has a group dedicated to people. The basic idea is simple: an employee's security does not start on the first day of work and does not end on the last.
A person's security starts before they walk through the door. Two things matter here.
The longest stage, and the one where the most is won or lost. Three things keep it healthy.
Here is one of the biggest holes in real companies: former employees who still have an active account and access to systems, months after they left.
The good part is that all of it becomes simple if it is prepared in advance: a short checklist, run at every departure, instead of a scramble through systems when it is already too late.
Because the most costly incidents do not come from outside, but from within, often without bad intent. A new, untrained employee who clicks a fake link. An upset colleague who leaves and still has access. A vendor with rights forgotten in the system.
None of these situations is solved with technology. They are solved with care for people, from the first day to after the last. A note: this part is about people as a security element. How you protect employee data under GDPR, the other side of the coin, we covered separately, in the article on employee data protection.
It is the part of the standard that deals with people, because people are both the greatest resource and a security risk. Annex A of ISO 27001 has a group of people controls, organised across three stages: before employment, during employment, and on leaving or changing role. The goal is that everyone knows what they have to protect and that no one is left with access after they no longer need it.
Yes, but in moderation and within the law. ISO 27001 asks for a check that fits the role: the more sensitive the information the job touches, the more thorough the check can be. You verify only what is relevant to the job, ask for consent where needed and respect GDPR. You do not look into a person's private life out of curiosity.
It must be removed immediately. One of the biggest security holes in companies is a former employee who still has an active account and access to systems. On leaving or changing role, access is removed, equipment is returned and the remaining obligations are reminded, first of all confidentiality. This is prepared in advance, not on the day of departure.
No. Certification is useful if customers or a tender require it, but it is not mandatory in order to use the standard. You can take the people controls from Annex A as a common-sense checklist and apply them at your scale, whether you are a small or a large company. The benefit is the same: fewer unpleasant surprises involving people.
We help you take the simple steps, from candidate screening and confidentiality clauses to training and removing access on departure.