Human Resources Security Policy
Employee screening, NDA, onboarding, offboarding and disciplinary procedures
1. Pre-employment – Screening
▸ Organisation completes – scope of screening per applicable labour law
| Screening element | For positions | Applied in organisation? | Legal basis |
|---|---|---|---|
| Identity verification (ID document) | All | ▸ YES / NO | Applicable labour law |
| Qualification / diploma verification | All (if required) | ▸ YES / NO | Applicable labour law |
| Reference check | ▸ [positions with access to critical data] | ▸ YES / NO | Voluntary practice |
| Criminal record check | ▸ [per applicable sector regulations] | ▸ YES / NO (if required by sector) | As permitted by applicable law |
2. At Hiring – Agreements and Commitments
Every employee/contractor signs before gaining access to systems:
| Document | Mandatory? | Signing deadline |
|---|---|---|
| Non-Disclosure Agreement (NDA) | YES – all | ▸ [before first access to systems]before access |
| Acknowledgement of Security Policy (DOC-001) | YES – all | ▸ [on onboarding day]before access |
| Acceptable Use Policy (AUP) acceptance | YES – all | ▸ [on onboarding day]before access |
| Contractual penalty clause for breaches | ▸ [YES / NO] | ▸ in employment / collaboration contract |
3. Onboarding – Procedure for New Employee
| Step | Action | Responsible | Deadline |
|---|---|---|---|
| 1 | Notify IT of new employee (account request) | HR | ▸ [3 business days before start date] |
| 2 | Sign NDA and security declarations | HR | Day 1 |
| 3 | Information security induction training | CISO / HR | ▸ [within 5 business days]max. 14 days |
| 4 | Account and access creation (per request) | IT Admin | Day 1 |
| 5 | MFA configuration | IT Admin + employee | ▸ [Day 1]before first remote login |
| 6 | Training register entry | HR | After training |
4. Offboarding – Leaver Procedure
⚠️
Access must be blocked no later than on the employee's last day (and ideally as soon as the departure decision is known – particularly for immediate dismissals).
| Step | Action | Responsible | Deadline |
|---|---|---|---|
| 1 | HR notifies IT of departure date and employee | HR | ▸ [min. 5 business days before] or immediately upon disciplinary dismissal |
| 2 | Block AD / system accounts | IT Admin | On departure day, by 17:00 |
| 3 | Return company equipment (laptop, phone, MFA tokens) | HR / IT Admin | On departure day |
| 4 | Revoke external accounts (cloud, SaaS) | IT Admin | ▸ [within 24h]max. 24h |
| 5 | Change shared account passwords (if applicable) | IT Admin | ▸ [within 24h] |
| 6 | Return physical keys / access cards | HR / Security | On departure day |
| 7 | Sign equipment return and confidentiality confirmation | HR | On departure day |
| 8 | Archive account (email, data) for ▸ [90 days] | IT Admin | On departure day |
5. Disciplinary Procedures for Security Violations
| Type of violation | Possible consequences |
|---|---|
| Unintentional policy violation (first occurrence) | ▸ [e.g. verbal warning + additional training] |
| Deliberate violation or repeated violations | ▸ [e.g. written warning / financial penalty / termination] |
| Serious violation (data theft, sabotage) | ▸ [immediate termination + report to law enforcement] |
Disciplinary procedures must comply with applicable labour law and the organisation's internal regulations.
Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ | ▸ | ▸ Initial release | ▸ Board |
DOC-016 HR Security | v1.0 | NIS2/ISMS