People Controls
People Controls are the set of security measures in ISO/IEC 27001 that address the human side of information security, such as employee screening, training, and terms of employment. They aim to reduce risks that arise from how staff and contractors handle data and systems, in part by fostering a culture of security awareness. These controls are one grouping among the reference controls listed in Annex A, and are selected based on an organization's risk assessment rather than being universally mandatory.
In the ISO/IEC 27001:2022 revision, People Controls form one of the four themes into which the 93 Annex A reference controls were reorganized (the others being Organizational, Technological, and Physical controls). This theme, corresponding to ISO/IEC 27002 Clause 6, comprises 8 controls addressing the secure management of human resources, including screening (6.1), terms and conditions of employment (6.2), and related measures across the employment lifecycle. As Annex A reference controls, People Controls are selected and justified through the risk assessment and documented in the Statement of Applicability; they are not inherently required in every ISMS. Note that the four-theme structure and control counts reflect the 2022 edition and differ from the 2013 version, and Annex A controls are distinct from the SOC 2 Trust Services Criteria.
Why it matters
Many information security incidents originate not from technical vulnerabilities but from human behavior, how staff and contractors handle data, credentials, and systems. People Controls in ISO/IEC 27001 address this human dimension directly, targeting risks that purely technological safeguards cannot fully mitigate. By covering the employment lifecycle from screening through terms of employment, this theme helps organizations reduce the likelihood that gaps in awareness, judgment, or accountability lead to compromise.
Beyond individual measures, People Controls contribute to building a security-first culture. Regular awareness training, for example, can help employees recognize and respond appropriately to threats, while clearly defined terms and conditions of employment establish accountability for how personnel interact with information assets. Because these controls are selected and justified through the risk assessment and documented in the Statement of Applicability, they allow an organization to tailor its human-factor safeguards to the specific risks it faces rather than applying a fixed checklist.
It is worth emphasizing that People Controls are Annex A reference controls, not inherently mandatory in every ISMS. Their applicability depends on the outcome of the organization's risk assessment, and their presence in an ISMS reflects a deliberate scoping decision. They also address only the human-factor risks within the defined scope of the ISMS and should be understood as one grouping among the broader set of Organizational, Technological, and Physical controls.
Who it's relevant to
Inside People Controls
Common questions
Answers to the questions practitioners most commonly ask about People Controls.