I was hoping you might be able to give me some advice about the confidentiality statement.
We cover confidentiality in the employment contract so my question is it is Mandatory in ISO27K that there is a separate Confidentiality agreement signed by staff or is it OK if it’s covered in the employment contract. Does there have to be a confidentiality agreement or just a signed document that shows agreement to keep information confidential?
ISO 27001 does not prescribe how to implement a confidentiality agreement, so organizations can implement it as it best fits their needs.
Considering that, you can keep the confidentiality agreement in the employment contract.
Regarding the document content, please note that a confidentiality agreement is more than simply saying that the parts need to keep the information confidential. It also helps explain other things, like what is confidential information, what to do in case of information compromise, penalties in case of a breach, etc.