ISO/IEC 27000 Responsibilities After Termination or Change of Employment, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to responsibilities after termination or change of employment.
Assessment Step
1
Responsibilities After Termination or Change of Employment (ResponsibilitiesAfterTerminationorChangeofEmployment)
Has the organization defined information security responsibilities and duties that remain valid after termination or change of employment, and does it enforce them and communicate them to relevant personnel and other interested parties?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Responsibilities After Termination or Change of Employment
Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties.
Citations
27001
Annex A, Control 6.5
27002
Section 6.5
|