ISO/IEC 27000 Confidentiality or Non-Disclosure Agreements, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to confidentiality or non-disclosure agreements.

Assessment Step

1
Confidentiality or Non-Disclosure Agreements (ConfidentialityorNon-DisclosureAgreements)
Has the organization identified and documented confidentiality or non-disclosure agreements reflecting the organization's needs for protecting information, and does it regularly review them, and does it require that they be signed by personnel and relevant interested parties?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Confidentiality or Non-Disclosure Agreements
Confidentiality or non-disclosure agreements reflecting the organization's needs for the protection of information shall be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.
Citations
27001
Annex A, Control 6.6
27002
Section 6.6