DOC-016 ← Document Portal

Human Resources Security Policy

Employee screening, NDA, onboarding, offboarding and disciplinary procedures
Document Number
DOC-016
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ HR Director / CISO
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2)(i) NIS2; ISO/IEC 27001:2022 A.6.1–A.6.5; Labour Law
Related Documents
DOC-008 | DOC-017 | DOC-004

1. Pre-employment – Screening

▸ Organisation completes – scope of screening per applicable labour law
Screening elementFor positionsApplied in organisation?Legal basis
Identity verification (ID document) All ▸ YES / NO Applicable labour law
Qualification / diploma verification All (if required) ▸ YES / NO Applicable labour law
Reference check ▸ [positions with access to critical data] ▸ YES / NO Voluntary practice
Criminal record check ▸ [per applicable sector regulations] ▸ YES / NO (if required by sector) As permitted by applicable law

2. At Hiring – Agreements and Commitments

Every employee/contractor signs before gaining access to systems:

DocumentMandatory?Signing deadline
Non-Disclosure Agreement (NDA) YES – all ▸ [before first access to systems]before access
Acknowledgement of Security Policy (DOC-001) YES – all ▸ [on onboarding day]before access
Acceptable Use Policy (AUP) acceptance YES – all ▸ [on onboarding day]before access
Contractual penalty clause for breaches ▸ [YES / NO] ▸ in employment / collaboration contract

3. Onboarding – Procedure for New Employee

StepActionResponsibleDeadline
1Notify IT of new employee (account request)HR▸ [3 business days before start date]
2Sign NDA and security declarationsHRDay 1
3Information security induction trainingCISO / HR▸ [within 5 business days]max. 14 days
4Account and access creation (per request)IT AdminDay 1
5MFA configurationIT Admin + employee▸ [Day 1]before first remote login
6Training register entryHRAfter training

4. Offboarding – Leaver Procedure

⚠️
Access must be blocked no later than on the employee's last day (and ideally as soon as the departure decision is known – particularly for immediate dismissals).
StepActionResponsibleDeadline
1HR notifies IT of departure date and employeeHR▸ [min. 5 business days before] or immediately upon disciplinary dismissal
2Block AD / system accountsIT AdminOn departure day, by 17:00
3Return company equipment (laptop, phone, MFA tokens)HR / IT AdminOn departure day
4Revoke external accounts (cloud, SaaS)IT Admin▸ [within 24h]max. 24h
5Change shared account passwords (if applicable)IT Admin▸ [within 24h]
6Return physical keys / access cardsHR / SecurityOn departure day
7Sign equipment return and confidentiality confirmationHROn departure day
8Archive account (email, data) for ▸ [90 days]IT AdminOn departure day

5. Disciplinary Procedures for Security Violations

Type of violationPossible consequences
Unintentional policy violation (first occurrence) ▸ [e.g. verbal warning + additional training]
Deliberate violation or repeated violations ▸ [e.g. written warning / financial penalty / termination]
Serious violation (data theft, sabotage) ▸ [immediate termination + report to law enforcement]

Disciplinary procedures must comply with applicable labour law and the organisation's internal regulations.

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-016 HR Security | v1.0 | NIS2/ISMS