Skip to content

Guidelines for Inclusion in Employment Contracts

Introduction

Employment contracts are created and maintained by the hiring manager (TODO(owner): confirm who owns contract templates at Soon) and comply with all applicable laws of the country in which the employment takes place.

As part of the Information Security Management System (ISMS) it is important that information security responsibilities are understood by all employees and contractors providing services to Soon. In addition to ongoing awareness activities, these responsibilities must be clearly stated when the contract of employment is agreed.

Note: the following sections give a general indication of the areas that need to be included in employment contracts to satisfy the requirements of the ISO/IEC 27001 standard. Given the legal nature of a contract, the exact wording should be checked with legal counsel before use.

This control applies to all employees and contractors of the organization, particularly those who will have access to Soon's IT systems.

The following policies and procedures are relevant to this document:

Purpose of this document

This document provides guidance about the types of information that should be included in employment contracts and agreements with contractors.

Areas of the standard addressed

The following areas of the ISO/IEC 27001 standard are addressed by this document:

  • A.6 People controls
  • A.6.2 Terms and conditions of employment

Guidelines

Permanent employees

For all employees:

As an employee of Soon you will be required to comply with all applicable information security policies and procedures in force during the period of your employment and for TODO(owner): confirm survival period (e.g. 24 months) after your employment has ended.

This will include, but is not limited to:

Failure to comply with the above policies and procedures may result in disciplinary action being taken in accordance with Soon's disciplinary process (see the HR Security Policy).

In addition, for those employees who will be given access to information classified as Confidential:

As a condition of your employment, you will be required to sign a Non-Disclosure Agreement before being given access to information or information processing facilities which are classified by the organization as Confidential.

Contractors

For all contractors:

As a contractor providing services to Soon you will be required to comply with all applicable information security policies and procedures in force during the period of your contract and for TODO(owner): confirm survival period (e.g. 24 months) after your contract has ended.

This will include, but is not limited to, the same policies listed for permanent employees above.

Failure to comply with the above policies and procedures may result in the termination of your contract and legal action being taken.

In addition, for those contractors who will be given access to information classified as Confidential:

As a condition of your contract, you will be required to sign a Non-Disclosure Agreement before being given access to information or information processing facilities which are classified by the organization as Confidential.


Change log

Version Date Author Comments
0.1 2025-06-07 Olaf Jacobson First draft document
0.2 2026-07-18 Andrea Cardinali Cleaned up and made Soon-specific (ISMS overhaul)