Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.6.2 Terms and Conditions of Employment

Control Objective

The employment contractual agreements shall state the personnel’s and the organisation’s responsibilities for information security.

Policy Statement

anDREa embeds information security obligations directly into its employment contracts and operational onboarding workflows. All personnel must contractually commit to safeguarding organizational and user data, maintaining compliance with security policies, and completing regular training.


Contractual and Operational Obligations

Information security responsibilities are enforced through a combination of legal agreements, clear role definitions, and continuous education:

  • Contractual Enforcement: Specific, legally binding information security responsibilities, confidentiality mandates, and non-compliance consequences are integrated directly into Articles 9, 12, and 15 of the standard anDREa Employment Agreement Employee Contracts (templates).
  • Role-Specific Accountabilities: Operational security boundaries and ownership are granularly mapped out per function within the Definition of (Security) Roles and Responsibilities and the master Roles & Responsibilities Matrix.
  • Onboarding & Annual Re-Attestation: To ensure ongoing awareness of current threat vectors and regulatory demands (such as GDPR and NIS 2), all employees must complete the following milestones upon onboarding and annually thereafter: