A.13.2.4 Confidentiality or non-disclosure agreements
A.13.2.4 in ISO 27001:2013 (ISO/IEC 27001:2013). All ISO 27001:2013 controls held. Open ISO 27001:2013 on the standards site.
The control as we hold it
Confidentiality or non-disclosure agreements. What confidentiality or non-disclosure agreements must contain, reflecting the organization's needs for protecting information are identified, reviewed regularly and written down. As an Annex A reference control it is compared with the controls chosen in risk treatment (6.1.3 c) and recorded in the Statement of Applicability, included with a reason and an implementation status or excluded with a reason (6.1.3 d). Carried into ISO/IEC 27001:2022 as A.6.6.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
ISO 27001:2022
- A.6.6 Confidentiality or non-disclosure agreements (reviewed pair)
What an auditor commonly asks for
General guidance for this control area (domain: A.13 Communications security), in our words, not a statement of the standard and not binding on an assessor.
- the network segmentation and control records
- the secure-transfer and confidentiality records
- the network-service agreements