There should be Nondisclosure Agreements (NDAs) in place to protect sensitive data from unauthorized distribution by parties involved with the organization.

Control Type: Administrative

Control Function: Preventive

Description: Organizations that handle sensitive data should require employees to sign sworn statements promising to respect and protect the confidentiality of that data. Combining NDAs with non-repudiation tools, such as session monitoring and logging can help reduce the risk of insider threats. NDAs should be role-specific and address the specific datasets that will be handled by the specific roles. Besides use between organizations and their employees, NDAs may also be necessary for relationships with third parties that need to access sensitive internal data to perform their services. There are two ways an NDA can function: one-way, which means only one party needs to adhere to the agreement, or two-way, meaning the terms are respected by both parties.

The NDA should clearly state the scope and the included parties. The agreement text should give a clear definition of sensitive/confidential information, including any nuances specific to the role and data being addressed. Any data that is specifically excluded from the terms of the NDA should be documented. For example, a database may store confidential data, but also have some pieces of public data included that do not need the same level of confidentiality.

The text of the NDA should contain the duration of the agreement and the expectations of the receiving party (employee). For example, the agreement may be in effect for the entire duration of the data’s lifecycle and require that the employee only access the data for employment purposes and refrain from any illegal activity.

NDAs must be signed by both parties and stored in secure environments with backups and controls for data at rest.