Information security responsibilities start before day one.
Annex A 6.2 exists to ensure organisations clearly define information security responsibilities within the terms and conditions of employment, so expectations are understood, agreed, and enforceable from the outset.
This control anchors information security obligations in contractual reality, not policy assumption.

Annex A 6.2 of ISO 27001:2022 focuses on information security responsibilities within employment terms.
At a practical level, this means:
The control does not prescribe contract wording or legal structure. It expects organisations to ensure information security responsibilities are formally agreed and legally enforceable.
Annex A 6.2 of ISO 27001:2022 focuses on information security responsibilities within employment terms.
At a practical level, this means:
The control does not prescribe contract wording or legal structure. It expects organisations to ensure information security responsibilities are formally agreed and legally enforceable.
A pragmatic approach to Annex A 6.2 typically includes the following elements.
Employment terms should make clear that individuals are responsible for:
This establishes security as a core duty, not a side obligation.
Where individuals may access confidential or sensitive information, terms often address:
Clarity here reduces both insider risk and legal ambiguity.
Contracts commonly reference:
This avoids duplicating content while ensuring contractual linkage.
Employment terms may outline responsibilities relating to:
This reinforces that legal compliance is part of the individual’s role.
Annex A 6.2 supports transparency around:
Consequences should be clear, lawful, and proportionate.
Information security obligations should be agreed:
Access should not be granted on the basis of unsigned or incomplete terms.
Where responsibilities change significantly, organisations may:
This ensures obligations remain aligned with access and risk.
Annex A 6.2 does not require:
It does require organisations to:
Contracts define boundaries.
Policies explain how to operate within them.
Most disputes arise from ambiguity, not intent.
Annex A 6.2 is about setting expectations that hold up under scrutiny.
When information security is embedded in employment terms:
Security awareness can be forgotten.
Contractual responsibility is harder to ignore.
That is exactly what Annex A 6.2 is designed to achieve.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today