A.6 8 controls

ISO 27001 People Controls (A.6)

Eight controls covering screening, terms of employment, awareness, disciplinary process and remote working.

What the People Controls theme covers

A.6 is the smallest theme and the one most likely to be owned outside the security team. The evidence lives in HR systems — screening records, signed terms, training completions, offboarding checklists — which makes reconciliation the usual failure point: the joiner, mover and leaver records have to agree with your current headcount and your access lists. Auditors commonly sample recent leavers and trace them through to access revocation, so A.6 and A.5.18 tend to be tested together.

All 8 People Controls

A.6.1 Screening
Perform background verification checks on all candidates for employment, in accordance with applicable laws, regulations and ethics, proportional to business requirements and the risks involved.
A.6.2 Terms and conditions of employment
Employment agreements shall state employees' and the organisation's responsibilities for information security.
A.6.3 Information security awareness, education and training
Ensure all personnel receive appropriate IS awareness, education and training relevant to their job function.
A.6.4 Disciplinary process
Have a formal and communicated disciplinary process for personnel who have committed an IS breach.
A.6.5 Responsibilities after termination or change of employment
Define, communicate and enforce IS responsibilities that remain valid after change or termination of employment.
A.6.6 Confidentiality or non-disclosure agreements
Identify, regularly review and document requirements for confidentiality or non-disclosure agreements reflecting the organisation's needs.
A.6.7 Remote working
Implement security measures to protect information accessed, processed or stored at remote working sites.
A.6.8 Information security event reporting
Provide a mechanism for personnel to report observed or suspected IS events through appropriate channels in a timely manner.

Other Annex A themes

A.5 Organisational Controls A.7 Physical Controls A.8 Technological Controls
Crosswalk to SOC 2 & NIST CSF →
Map these controls across frameworks in the Control Mapper.
Search all 93 controls →
Filter Annex A by keyword, theme or control ID.

Frequently asked questions

How many People Controls are there in ISO 27001:2022?

There are 8 controls in the A.6 People Controls theme. Annex A defines 93 controls in total across four themes: Organisational (37), People (8), Physical (14) and Technological (34).

Do I have to implement every People Controls control?

No. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify any exclusion in the Statement of Applicability — it does not require you to apply all 93. What auditors test is whether the justification is risk-based and documented, not whether the count is high.

What replaced the ISO 27001:2013 domains?

The 2013 edition organised 114 controls into 14 domains (A.5–A.18). The 2022 revision restructured them into 93 controls across four themes, merging 57 and introducing 11 new ones. Each control page below lists its 2013 predecessors so you can re-point existing evidence during transition.