In ISO/IEC 27001, human resources (HR) security refers to the controls that are put in place to protect the organisations information assets from security risks associated with its employees, contractors, and other third-party workers. This includes risks related to the recruitment, training, and management of staff, as well as risks related to the termination of staff.
Human resources security controls typically include the following:
It's important to remember that human resources security is not just a one-time process but rather an ongoing effort, that should be part of the overall ISMS. It should be integrated with the other controls and process, such as access control, incident management and compliance.
Regular review of the human resources security controls, should be conducted, and updated as necessary, to make sure it is still effective and relevant. Also, it is important to communicate and create a security culture in the organisation that promotes compliance with the HR security controls.
Contact Periculo for expert cyber security solutions tailored to the digital health industry.