A.6.5 Responsibilities After Termination or Change of Employment
Control Objective
Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, enforced and communicated to relevant personnel and other interested parties.
Policy Statement
anDREa enforces strict security protocols for both internal role transitions and formal offboarding. This ensures that access rights are adjusted or revoked instantly, company assets are securely recovered, and post-employment confidentiality obligations remain legally binding and actively communicated.
Personnel Offboarding Protocol
When employment or a third-party contract is terminated, the offboarding process is executed via Onboarding & Offboarding Process. Key mandatory security controls include:
- Post-Employment Confidentiality: In accordance with Articles 9 and 11 of the standard employment contract, the signed Non-Disclosure Agreement (NDA) remains legally binding after the individual departs the organization.
- Asset Retrieval and Data Sanitization: Departing personnel are formally instructed on the retrieval of company-owned equipment and the mandatory purging of any local anDREa data from personal environments, in alignment with A.07.14: Secure Disposal or Re-Use of Equipment and the Retention & Destruction Policy.
- Compliance Documentation: A formal offboarding notification email detailing these requirements is sent to the departing individual. The email confirmation and the individual's formal acknowledgment are archived within their personnel file to maintain an audit trail.
Internal Role Transition Protocol
When personnel transfer to a different position within anDREa, the Business Manager and respective Asset Owners must formally assess and execute changes to the individual's security profile. This evaluation determines:
- Asset Allocation: Whether current company resources must be returned, replaced, or updated.
- Identity and Access Management: Necessary adjustments to platform, application, and network permissions to ensure alignment with the principle of least privilege (see A.05.15: Access Control).
- Transfer of Accountability: The structured handoff of specific information security roles, tasks, or system ownership.
- Screening Re-Evaluation: Whether the risk profile of the new position necessitates requesting a new Certificate of Conduct (VOG) or international equivalent (see A.06.01: Screening).