PPPR-07

Do you require new employees to fill out agreements and review policies?

Explanation

This question is asking whether your organization has a formal process requiring new employees to read, understand, and acknowledge company policies and sign relevant agreements when they join the company. These typically include confidentiality agreements, acceptable use policies, security policies, code of conduct, and other employment-related documents. Why this is asked in security assessments: 1. Accountability: Signed agreements create a record that employees were informed of their responsibilities. 2. Legal protection: These agreements establish the employer-employee relationship regarding handling of sensitive data and systems. 3. Security awareness: The process ensures employees are aware of security expectations from day one. 4. Compliance requirements: Many regulations (like HIPAA, SOC2, ISO 27001) require documented evidence that employees understand their security obligations. The question helps assessors understand if your organization has baseline security awareness measures in place and if you're creating accountability for security practices at the employee level. Without such agreements, it's difficult to enforce security policies or take action if violations occur. When answering this question, you should: - Be specific about which agreements and policies are required - Mention when in the onboarding process these are reviewed (ideally before system access is granted) - Note if you track completion and maintain records of these signed documents - Mention if there are consequences for non-completion

Example Responses

Example Response 1

Yes, our organization requires all new employees to review and acknowledge key policies and sign agreements as part of our formal onboarding process Before receiving system access credentials, new hires must complete the following: (1) Sign a confidentiality and non-disclosure agreement, (2) Review and acknowledge our information security policy, acceptable use policy, and code of conduct, (3) Complete basic security awareness training, and (4) Sign an acknowledgment of employment handbook receipt HR maintains digital records of all signed documents in our secure document management system Employees cannot receive system access until these requirements are completed, and compliance is tracked through our onboarding checklist.

Example Response 2

Yes, we implement a comprehensive policy acknowledgment process for all new hires During their first week, employees must review and electronically sign our security policies, acceptable use policy, code of conduct, and confidentiality agreement through our HR management platform The system automatically tracks completion status and sends reminders for any outstanding items Our IT department is automatically notified when these requirements are completed, which triggers the provisioning of appropriate system access We maintain these records for the duration of employment plus three years Additionally, employees must re-acknowledge these policies annually as part of our security refresher training.

Example Response 3

No, we currently don't have a formal process requiring new employees to sign agreements or review policies during onboarding While we do verbally communicate our expectations regarding confidentiality and system usage during orientation, we haven't implemented a documented process with signed acknowledgments Our small team size (under 10 employees) has allowed us to operate with more informal processes until now However, we recognize this is a gap in our security practices, and we're developing a formal onboarding checklist that will include policy reviews and signed agreements We plan to implement this within the next quarter and retroactively have existing employees complete these requirements.

Context

Tab
Organization
Category
Policies, Processes, and Procedures

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron