GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-003 Employment Agreements and Security Obligations

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Employment contracts and agreements include explicit information security obligations, confidentiality requirements, and acknowledgement of the organisation's security policies. Personnel sign these agreements before receiving system access, and they are updated when security obligations change.

Rationale

Security obligations are legally unenforceable unless they are written into employment agreements and acknowledged. Signed agreements create a documented record of consent and obligation that can be relied upon in disciplinary or legal proceedings.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (14)

HRS-07Employment Agreement Processfull
HRS-08Employment Agreement Contentfull
HRS-10Non-Disclosure Agreementspartial
HRS-07Employment Agreement Processfull
HRS-08Employment Agreement Contentfull
HRS-10Non-Disclosure Agreementspartial
HIPAA-164.308.a.1.ii.CSanction Policyinformative
6.2Terms and conditions of employmentfull
6.6Confidentiality or non-disclosure agreementspartial
NIS2-CIR-10.1Human Resources Securitypartial
NIS2-CIR-10.3Termination or Change of Employment Procedurespartial
NIS2-CIR-12.5Deposit, Return or Deletion of Assets upon Termination of Employmentinformative
PL-4Rules of Behaviorinformative
PS-6Access Agreementsfull

Evidence (2)

contractdocumentmanual

Signed employment agreement template containing explicit information security obligations, confidentiality requirements, and policy acknowledgement clauses.

Example: Employment agreement template (legal counsel-approved), with clearly identified sections for: information security obligations, confidentiality and NDA terms, acceptable use policy acknowledgement, and data protection obligations, signed copies on file for a sample of current employees.

Test: Request the current employment agreement template and signed copies for a sample of five current employees spanning different tenures. Verify: (1) information security obligations are explicitly stated (not just by reference to a policy document without specifics), (2) confidentiality obligations survive employment, (3) the agreement was signed before or on the first day of employment, (4) signed copies are retained in the HRIS or document store.

recorddocumentmanual

Evidence that agreements are updated and re-acknowledged when security obligations change materially.

Example: Change notification record and re-acknowledgement log (HRIS / policy platform) showing the date a material change was made to the employment agreement or security obligations, the communication sent to affected staff, and the re-acknowledgement completion date.

Test: Request records of any material changes to employment agreements or security obligations in the last two years. Verify: (1) affected personnel were notified of the change, (2) re-acknowledgement was required and tracked, (3) completion records show all affected employees acknowledged the updated terms within a defined period.

Questions (3)

boolean

Do your employment agreements state explicit information security obligations?

Obligations should be stated in the agreement itself, not just referenced by pointer. Signed copies should be on file and the agreement should be signed before or on the first day of employment.

select

When security obligations in employment agreements change materially, how does your organisation ensure affected personnel acknowledge the updated terms?

Formal re-acknowledgement process tracked to 100% completion in the HRIS or policy platformCommunication sent to all staff but re-acknowledgement is not formally trackedUpdated agreements are issued only to new hires; existing staff are not re-acknowledgedMaterial changes to security obligations have not occurred, and no process exists for this scenario

A change notification record and re-acknowledgement log showing all affected employees confirmed updated terms within a defined period is the expected evidence.

multi

Which of the following do your employment agreements contain?

Confidentiality requirementsAcknowledgement of the organisation's security policiesObligations stated in the agreement itself rather than referenced by pointerA signature recorded before system access is grantedNone of the above

Options run from the most commonly present to the least. An agreement that points at a policy the person has never read transfers no obligation they can be held to.