Information Security Management
ISO 27001 People Controls Explored
The “people” controls of ISO 27001 form a small, but important part of Annex A.
They address the human side of information security — from screening and awareness to managing access and disciplinary processes, ensuring that everyone with access to information understands their responsibilities and behaves securely.
Jump to the full list of Annex A controls →
Looking for the broader Annex A context? Start here →
Annex A People Control List (6.1 – 6.8)
Below is a complete list of the People controls, each linking to its own detailed explanation and examples.
6.1 Screening – Background checks on candidates for roles where the level of access or responsibility justifies verifying who they are and what they’ve done.
6.2 Terms and conditions of employment – Building information security responsibilities into employment contracts so that staff obligations around confidentiality and acceptable behaviour are formally established.
6.3 Information security awareness, education and training – Ongoing training that ensures staff understand the security risks they face, the policies they need to follow, and what’s expected of them in their role.
6.4 Disciplinary process – A formal process for handling staff who breach information security policies, with consequences proportionate to the breach.
6.5 Responsibilities after termination or change of employment – Making clear which security obligations continue to apply after someone leaves or changes role, particularly around confidentiality.
6.6 Confidentiality or non-disclosure agreements – Formal NDAs covering the protection of information shared with staff, contractors, and other parties.
6.7 Remote working – Rules and protections for staff who access organisational information from outside the office, including home, client sites, and travel.
6.8 Information security event reporting – A clear, accessible process for staff to report suspected security events without fear of blame, so issues surface quickly.
Select a control family to explore it in more detail
ISO 27001 Annex A: People Controls
People controls are the behavioural and responsibility-based safeguards in Annex A.
They help ensure that employees, contractors, and suppliers act securely and follow the rules that keep information protected.
While technology and policies matter, human error remains the top cause of security incidents — which is why People Controls are vital for a functioning ISMS.
There’s little additional value in my repeating a description of the overall purpose of Annex A and how to approach it. If you are looking for that guide, then do review my guidance below.

ISO 27001 Full Document Toolkit
Every document your auditor
expects to see.
130+ Word & Excel templates, ready to edit. Policies, risk register, Statement of Applicability, audit pack, staff communications — all updated for ISO 27001:2022.
130 templates
Instant download
Written by practising consultant
ISO 27001:2022
The Importance of People Controls in 27001
So, why have “people” controls? Well, the benefits include;
- People are both your strongest defence and biggest vulnerability.
- Embedding awareness reduces accidental data loss and phishing incidents.
- HR-linked controls show that your ISMS is cultural, not just technical.
- They support compliance with privacy laws (GDPR, Data Protection Act) by ensuring everyone handles data responsibly.
Any glance at the newspaper headlines indicates why having strong controls around people and training is so important – At the heart of so many ransomware attacks that have had major disruptions to local and global busineses, the human aspect has been the weakest link.
A note on the people family in small businesses
In the SMEs I work with, the people controls are often the easiest family to get right, because most are essentially HR practices that are already happening. Background checks (A.6.1) usually exist for senior or sensitive roles. Confidentiality clauses (A.6.6) are typically already in employment contracts. Awareness training (A.6.3) is the one that often needs new investment, because most SMEs have never run formal security training. The work is usually about documenting what already happens, formalising what’s informal, and adding training where it’s missing.
Next Steps and Related Topics
Check out some of the other control families here;
Or, by group
FAQ: People Controls
Are People Controls mandatory for certification?
Like all Annex A controls, you must consider each one in your Statement of Applicability and justify any exclusions. In practice, very few organisations exclude People Controls because they apply wherever you have staff, contractors, or others with access to your information. Even one-person businesses need to consider most of them, because the controls cover relationships with third parties as well as direct employees.
Where do I start with the People controls?
Start with A.6.2 (terms and conditions of employment) and A.6.6 (confidentiality agreements), because these are usually already partly in place in your existing employment contracts and just need reviewing to confirm the security clauses are present. After that, A.6.3 (awareness, education and training) is usually where most of the new work sits, because formal annual security training isn’t something most SMEs have run before. The remaining controls tend to follow on naturally once these foundations are set.
Who owns the People controls?
In larger organisations, HR usually owns most of the People Controls in partnership with IT and information security. In smaller businesses where there’s no dedicated HR function, ownership often sits with the business owner or operations lead, supported by external HR advice if needed. What matters for audit isn’t who owns them but that ownership is documented and the controls are actually being run consistently.
How reguarly should I run awareness training?
The standard requires training at planned intervals, which most organisations interpret as annually as a minimum. Refresher training after major incidents, significant policy changes, or new threats (such as a wave of phishing attacks affecting your sector) is good practice. Induction training for new starters should happen as part of onboarding, not weeks or months after they’ve started accessing systems.
What counts as evidence of training for audit?
Auditors will ask for records showing who completed which training and when. This can be as simple as an LMS export, a signed register, or an email with attached training slides and a list of attendees. The format doesn’t matter; the consistency does. Auditors will sometimes ask staff what they remember from the training, so the content also needs to be substantive enough to actually stick.
Do background checks (A.6.1) need to be formal criminal records checks?
Not necessarily. The standard requires screening proportionate to the risk of the role and the sensitivity of the information involved. For most SME roles, that means reference checks, right-to-work verification, and confirming employment history. Formal criminal records checks (DBS in the UK) are appropriate for roles handling particularly sensitive data or where regulation requires them. The principle is to match the depth of screening to the level of trust the role requires.
How do People Controls apply to contractors and third parties?
A.6.6 (confidentiality and non-disclosure agreements) and A.6.3 (awareness training) explicitly cover non-employees with access to your information. This means your contractors, freelancers, and third-party staff who handle your data should sign appropriate NDAs and receive (or evidence) appropriate security training. The depth of training needed for a contractor accessing data for two weeks is different from a permanent employee, but the principle of “everyone with access has appropriate awareness” applies to both.
Do remote workers need special treatment?
Yes – A.6.7 specifically covers remote working. The control requires that information accessed outside the office is appropriately protected, which usually means a remote working policy covering VPN use, encryption, rules around personal devices, and expectations around physical security in home environments. For SMEs that are predominantly remote or hybrid, A.6.7 is one of the most important People Controls and worth getting right early.
What’s the difference between People Controls and Clause 7 Support?
Clause 7 covers the management system requirements around resources, competence, awareness, and communication – it’s about what the ISMS as a whole needs to support its operation. People Controls (A.6) are the specific operational practices that implement those requirements at an individual level. Clause 7 says the organisation must ensure people are competent and aware; A.6 specifies how that’s achieved through training, contracts, screening, and disciplinary processes.
What if a member of staff breaches a security policy?
The breach should be handled through your formal disciplinary process (A.6.4), with the response proportionate to the severity. Auditors aren’t looking for harsh punishment; they’re looking for evidence that you take breaches seriously, that there’s a documented process, and that staff understand the consequences exist. A.6.4 also serves a deterrent function – the existence of a formal process reinforces that security policies are genuinely required, not just guidance.
Includes all the mandatory document templates — free, no commitment