betterjobs

Free form template · Word

Information Security Declaration

An information security declaration is a formal statement in which an employee confirms they understand the company’s information security management system, including data classification levels, handling rules for each level, and breach reporting duties. It is commonly used by ISO 27001-certified firms and companies serving overseas clients.

  • Editable Word (.docx)
  • Made for India
  • 13 fill-in fields highlighted
  • Free, no sign-up

Preview of the form

[Highlighted] = fill in
[Company Logo][Company Name]

INFORMATION SECURITY DECLARATION

Employee Name:
[Employee Name]
Employee ID:
[Employee ID]
Designation:
[Designation]
Department:
[Department]
Declaration Type:
[Joining / Annual]
Date:
[Date]

I declare that I have read the following information security policies of [Company Name]: [Information Security Policy], [Access Control Policy], [Data Classification Policy] and [Incident Management Procedure].

Data Classification and Handling

ClassificationExamplesHandling Rule
PublicWebsite content, brochuresMay be shared freely
InternalInternal circulars, org chartsShare only within the company
ConfidentialClient data, contracts, salariesNeed-to-know access; encrypted when sent outside
RestrictedSource code, personal data, credentialsNamed access only; never stored on personal devices

I Declare That

  1. I will handle information according to its classification.
  2. I will process personal data only for authorised purposes and in line with the data privacy policy.
  3. I will follow client security requirements on the projects I work on.
  4. I will not try to access information or systems I am not authorised to use.
  5. I will report any actual or suspected security incident to [Security Contact] without delay.

I understand that violation of these responsibilities may result in disciplinary action and may also have legal consequences.

Employee
[Employee Name]
Date: [Date]
Information Security Officer
[Name]
Date: [Date]

What this template includes

  • Reference to the ISMS policy set
  • Data classification table with handling rules
  • Declaration on handling client and personal data
  • Breach and incident reporting duty
  • Annual re-declaration
  • Signatures

When to use it

  • At joining in ISO 27001 or SOC 2 environments
  • For annual information security re-declaration
  • When employees join client projects with security clauses
  • After major ISMS policy changes

How to customise this template

  1. 1Match the classification labels to your ISMS
  2. 2List the policies employees must read
  3. 3Add client-specific security requirements
  4. 4Set the re-declaration frequency

HR tips

  • Make classification labels visible on documents
  • Keep a register of who has declared and when
  • Use the declaration as audit evidence

For HR & hiring managers

Hire top talent from BetterJobs

Experienced and fresher candidates across India — blue, grey and white collar. Post a job in 5 minutes and start receiving applications.

  • Post in 5 minutesDescribe the role in one line — we write the job description.
  • Verified applicantsEvery applicant has a verified mobile number.
  • Resume databaseSearch experienced candidates by skill, city and experience.

Frequently asked questions

What is an information security declaration?+

A signed statement that an employee has read the information security policies and will handle information according to its classification.

Is this needed for ISO 27001?+

ISO 27001 expects staff awareness of security responsibilities; a signed declaration is a common way to evidence it.

How often should it be signed?+

At joining and then annually, or when the policies change significantly.