unified
UC-HR-02 — Formalize security responsibilities in employment terms
Employment contracts and terms state each individual's information security responsibilities, including obligations that survive employment. Personnel sign confidentiality or non-disclosure agreements and access agreements before being granted access, and re-sign when agreements are materially updated. Position descriptions document role-specific security duties, and signed acknowledgments are retained as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Human Resources / Personnel Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-HR-02
- title
- Formalize security responsibilities in employment terms
- statement
- Employment contracts and terms state each individual's information security responsibilities, including obligations that survive employment. Personnel sign confidentiality or non-disclosure agreements and access agreements before being granted access, and re-sign when agreements are materially updated. Position descriptions document role-specific security duties, and signed acknowledgments are retained as evidence.
- domain
- Human Resources / Personnel Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PS-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PS-9
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.6.2
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.6.6
- coverage
- partial
- delta
- NDAs from external/other interested parties, addressed by the third-party personnel control
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-02 — Formalize security responsibilities in employment terms
- UC-HR-02 — Formalize security responsibilities in employment terms mitigates Discrimination, harassment and hostile-workplace culture
- strength
- related
- rationale
- Personnel Screening, Agreements & Sanctions Administration operates UC-HR-02 — Formalize security responsibilities in employment terms
- UC-HR-02 — Formalize security responsibilities in employment terms maps_to A.6.2 — Terms and conditions of employment
- framework
- iso-27001
- control_id
- A.6.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-02 — Formalize security responsibilities in employment terms
- UC-HR-02 — Formalize security responsibilities in employment terms maps_to PS-6 — Access Agreements
- framework
- nist-800-53
- control_id
- PS-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-HR-02 — Formalize security responsibilities in employment terms maps_to A.6.6 — Confidentiality or non-disclosure agreements
- framework
- iso-27001
- control_id
- A.6.6
- coverage
- partial
- delta
- NDAs from external/other interested parties, addressed by the third-party personnel control
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-HR-02 — Formalize security responsibilities in employment terms
- UC-HR-02 — Formalize security responsibilities in employment terms maps_to PS-9 — Position Descriptions
- framework
- nist-800-53
- control_id
- PS-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-HR-02 — Formalize security responsibilities in employment terms mitigates Missing security terms in contracts and no disciplinary process
- strength
- primary
- rationale
- Embeds infosec responsibilities, confidentiality/NDA and access agreements into employment terms, directly closing the missing-security-contract-terms gap.