ISO/IEC 27001 Control 6.6: Confidentiality or non-disclosure agreements

Control

Confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information should be identified, documented, regularly reviewed and signed by personnel and other relevant interested parties.

Necessity of MidPoint

MidPoint is optional for implementation of this control.

Implementation of this control without midPoint is feasible. However, midPoint provides considerable advantages for implementation of this control, making the implementation more efficient and reliable.

Implementation Overview

Information classification and clearance mechanism can be used to enforce the presence of appropriate agreements.

Implementation Details

Clearances can be used to represent appropriate confidentiality and non-disclosure agreements (NDA). Archetypes and organizations may be used to imply a clearance, e.g. in case that all employees or all members of an organizational unit have equivalent non-disclosure clause in their contracts. Policy rules can be used to limit access to sensitive applications in such a way that a valid NDA is required to grant access to them. Access certification and micro-certification mechanisms can be used to initiate check of a user (supplier), to verify whether the latest valid version of NDA is signed. Reporting capabilities can be used to analyze and review the state of the agreements granted as clearances. Audit trail and assignment meta-data can be used to review history of assignment of clearances.

Implementation Notes

  • Inducements in archetype can be used to denote implied clearances. E.g. all employees have implicit NDA clearance, as they have non-disclosure clause in their employment contracts. This can be modeled by inducing the NDA clearance in employee archetype.

Rationale

MidPoint cannot handle the contractual details of confidentiality and non-disclosure agreements, as required by the control. However, midPoint can enforce the presence of appropriate agreement before access is granted to information that requires it.

Documentation

Version Title Description
4.9 Information Classification and Clearances Using clearances to represent non-disclosure agreement
Development Information Classification and Clearances Using clearances to represent non-disclosure agreement
4.8 Information Classification and Clearances Using clearances to represent non-disclosure agreement
Was this page helpful?
YES NO
Thanks for your feedback