A.7 Human resource security

A.7 Human resource security

Version: 3.0

Valid until: 2024-04-12

Classification: Low

Version Management


Version

Author(s)

Change(s)

Date approved

1.0

Stefan van Aalst

Theo Koster

Edward Robinson

Initiation document.


2022-07-04

1.1

Edward Robinson

Additions/changes as part of the periodic review and improvement.


Renamed to A.7 Human resource security from B09 Human resource security.

2022-10-17

2.0Edward RobinsonAdditions/changes as part of the annual review.

No changes were made.
2023-05-15
3.0
Edward Robinson
Pascalle Broer
Additions/changes as part of the annual review.

Added the link to the HR Manual under Availability.

Updated the link for the competence overview under 7.1.1.

Added the link to the Roles & Responsibilities matrix under 7.1.2 and 7.2.1.

Updated the link to the Information Security Training under 7.1.2 and 7.2.1

Purpose & background


In the interest of all the stakeholders, the top management of anDREa B.V. (hereafter called anDREa) is actively committed to demonstrably maintain and continually improve an information management system in accordance with the requirements of the ISO 27001:2017.


The purpose of this document is to describe the human resource security policy of anDREa and the associated controls, checks and administrations.


This document will be reviewed at least annually and when significant change happens.

Objectives


The objectives of this control are:


  • To ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered (A.7.1).

  • To ensure that employees and contractors are aware of and fulfil their information security responsibilities (A.7.2).

  • To protect the organisation’s interests as part of the process of changing or terminating employment (A.7.3).

Scope


The scope of this document corresponds to Clause 4 Context of the organisation.

Availability

This document is:


  • required reading for:

    • all employees and contractors of anDREa.

  • For anDREa employees, this is all summarised in the HR Manual.

  • available for all interested parties as appropriate.

Norm elements

A.7.1 Prior to employment

A.7.1.1 Screening


“Background verification checks on all candidates for employment shall be carried out in accordance with relevant laws, regulations and ethics and shall be proportional to the business requirements, the classification of the information to be accessed and the perceived risks.”


Before an applicant is hired, a basic background check will be performed that is in accordance with relevant laws and regulations, and is proportional to the business requirements, information classification and perceived risks:

  • A valid identity document must be checked for validity. The authenticity features of passports are indicated on the website of the central government. The passport must comply with this.

  • Attitude and eagerness to learn is a very important feature for anDREa employees. Therefore, employees that are not C-level do not necessarily need certain certifications upon onboarding. However, they are required to obtain specified certifications during their employment at anDREa. To this extent, anDREa has created the anDREa People - Competence Overview list. The Security Officer will maintain this list and will at least biannually check the correctness of the list or when changes occur.

  • Employees with C-level will, in addition to the certifications described in the competence list, also need to leverage a Certificate of Conduct (Verklaring omtrent het Gedrag; VOG) which is stored in the employee’s personnel file.


A.7.1.2 Terms and conditions of employment


“The contractual agreements with employees and contractors shall state their and the organisation’s responsibilities for information security.”


anDREa has defined the information security responsibilities in article 1.4 of the employee agreement. In addition, the article Definition of (Security) Roles and Responsibilities and the Roles & Responsibilities matrix further displays the information security responsibilities per role and upon onboarding, the employee has to complete the Information Security and Data Protection Training.

A.7.2 During employment

A.7.2.1 Management responsibilities


“Management shall require employees and contractors to apply information security in accordance with the established policies and procedures of the organisation.”


Similar to A.7.1.2, the management of anDREa has defined the information security responsibilities in article 1.4 of the employee agreement. In addition, the article Roles & Responsibilities matrix further displays the information security responsibilities per role and upon onboarding, the employee has to complete the Information Security and Data Protection Training

The Information Security and Data Protection Training is a mandatory and automatically generated task in the onboarding workflow. Verification that the training has been completed is done by the Security Officer.


A.7.2.2 Information security awareness, education and training


“All employees of the organisation and, where relevant, contractors shall receive appropriate awareness education and training and regular updates in organisation policies and procedures, as relevant for their job function.”


Information security awareness is described in A.7.2.2 Information security awareness, education and training.

A.7.2.3 Disciplinary process


“There shall be a formal and communicated disciplinary process in place to take action against employees who have committed an information security breach.”


The disciplinary procedure is described in A.7.2.3 Disciplinary procedure. Sending the disciplinary procedure to the employee and receiving a reply is a mandatory and automatically generated task in the onboarding workflow. Performing and verifying the task is done by the Security Officer.

A.7.3 Termination and change of employment

A.7.3.1 Termination and change of employment responsibilities


“Information security responsibilities and duties that remain valid after termination or change of employment shall be defined, communicated to the employee and enforced.”


Offboarding an employee follows the offboarding workflow, which automatically generates and assigns tasks. One of the mandatory tasks is to remind the employee about the transfer or disposal of anDREa-related information according to A.6.2 Mobile devices and teleworking and that the non-disclosure agreement (NDA) will remain valid after offboarding according to article 8.1 of the contractual agreement. The reminder (via e-mail) is registered in a ticket, together with the reply of the offboarded employee. 

When an employee switches to another position within anDREa, the Security Officer (together with the relevant asset accountables) will determine whether:


  • the employee has to hand in company resources and whether access to the network and applications must be adjusted. 

  • tasks / responsibilities in the field of information security need to be transferred.

  • authorisations need to be adjusted.

  • whether it is necessary to request a (new) VOG for the employee concerned.

Administrations


    • Related Articles

    • 20220713 Report Azure White Box Security Audit

      Version: 2022-07-14 Introduction anDREa has a Pentest Program program as part of the commitment to protect the security of its business information. At least once a year we request an external party to do the pentest and a white box security audit. ...
    • 20210224 Pentest 2021-Q1 Report & 20210301 White Box Security Audit 2021-Q1 Report

      In accordance with our Pentest Program, anDREa engaged nSEC/Resilience for the anDREa White Box Security and the Pentesting 2021-Q1. The core questions being: Can non-authorized people or services access Workspaces or affect anDREa’s core services? ...
    • 20220607 Security Management Report

      As part of anDREa's commitment to maintaining an Information Security Management System (ISMS) based on ISO 27001 please feel free to download and read the attached anDRE's 20220607 Security Management Report.
    • A.12 Operations security

      Version: 3.0 Valid until: 2025-04-10 Classification: Low Version Management Version Author(s) Change(s) Date approved 1.0 Stefan van Aalst Edward Robinson Sarang Kulkarni Johanna Hakonen Initiation document 2022-07-07 1.1 Edward Robinson ...
    • 20220714 Security Management Report Addendum

      As part of anDREa's commitment to maintaining an Information Security Management System (ISMS) based on ISO 27001. This document is an addendum to the 20220607 Security Management Report and addresses the on 2022-07-14 reported findings of the ISO ...