Guidelines for Inclusion in Employment Contracts¶
Introduction¶
Employment contracts are created and maintained by the hiring manager (TODO(owner): confirm who owns contract templates at Soon) and comply with all applicable laws of the country in which the employment takes place.
As part of the Information Security Management System (ISMS) it is important that information security responsibilities are understood by all employees and contractors providing services to Soon. In addition to ongoing awareness activities, these responsibilities must be clearly stated when the contract of employment is agreed.
Note: the following sections give a general indication of the areas that need to be included in employment contracts to satisfy the requirements of the ISO/IEC 27001 standard. Given the legal nature of a contract, the exact wording should be checked with legal counsel before use.
This control applies to all employees and contractors of the organization, particularly those who will have access to Soon's IT systems.
The following policies and procedures are relevant to this document:
Purpose of this document¶
This document provides guidance about the types of information that should be included in employment contracts and agreements with contractors.
Areas of the standard addressed¶
The following areas of the ISO/IEC 27001 standard are addressed by this document:
- A.6 People controls
- A.6.2 Terms and conditions of employment
Guidelines¶
Permanent employees¶
For all employees:
As an employee of Soon you will be required to comply with all applicable information security policies and procedures in force during the period of your employment and for TODO(owner): confirm survival period (e.g. 24 months) after your employment has ended.
This will include, but is not limited to:
- Remote Working Policy
- Device Management Policy
- Acceptable Use Policy
- Software Policy
- IP & Copyright Compliance Policy
- Privacy and Personal Data Protection Policy
- Cloud Services Policy
- Records Retention & Protection Policy
Failure to comply with the above policies and procedures may result in disciplinary action being taken in accordance with Soon's disciplinary process (see the HR Security Policy).
In addition, for those employees who will be given access to information classified as Confidential:
As a condition of your employment, you will be required to sign a Non-Disclosure Agreement before being given access to information or information processing facilities which are classified by the organization as Confidential.
Contractors¶
For all contractors:
As a contractor providing services to Soon you will be required to comply with all applicable information security policies and procedures in force during the period of your contract and for TODO(owner): confirm survival period (e.g. 24 months) after your contract has ended.
This will include, but is not limited to, the same policies listed for permanent employees above.
Failure to comply with the above policies and procedures may result in the termination of your contract and legal action being taken.
In addition, for those contractors who will be given access to information classified as Confidential:
As a condition of your contract, you will be required to sign a Non-Disclosure Agreement before being given access to information or information processing facilities which are classified by the organization as Confidential.
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2025-06-07 | Olaf Jacobson | First draft document |
| 0.2 | 2026-07-18 | Andrea Cardinali | Cleaned up and made Soon-specific (ISMS overhaul) |