HRS-10: Non-Disclosure Agreements
Control Family:
CSF v1.1 References:
PF v1.0 References:
Threats Addressed:
Previous Version:
- Cloud Controls Matrix v3.0.1:
- HRS-06: Non-Disclosure Agreements
Control Statement
Identify, document, and review, at planned intervals, requirements for non-disclosure/confidentiality agreements reflecting the organization's needs for the protection of data and operational details.
Implementation Guidance
The non-disclosure agreement should address requirements to protect confidential information using legally binding terms. Agreement terms should be based on the organization’s information security requirements. The type of information covered should define permissible access and information handling protocols. The agreement should include, but is not limited to:
- What information is protected.
- The length of the agreement.
- Interested parties to the agreement.
- The responsibilities of each party in the agreement.
- Terms for the destruction of data once the agreement has ended.
- Expected actions if a breach of agreement terms occurs.
Auditing Guidance
- Examine if the organization has identified its requirements for non-disclosure and confidentiality.
- Determine the planned interval for review.
- Verify that the requirements are reviewed at such planned intervals.
[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]
Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.