Employee Monitoring Law Planner
Sources

ISO/IEC 27001 (information security management)

A standard: voluntary unless a contract, a procurement or a regulator makes it binding. Placed only when you tick it. Placed at every location, when you tick ISO/IEC 27001. Read 30 Sep 2026; 2 provisions cited by the planner.

ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)

The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.

What a reviewer asks to see: Statement of Applicability entry for control A.5.34, showing inclusion or justified exclusion, implementation status and the risks it treats; The topic-specific privacy and PII protection policy and its communication to relevant parties; Privacy procedures communicated to everyone who processes PII; Appointment of a privacy officer or equivalent with documented responsibilities; A record of processing or PII inventory mapping which laws apply to each processing activity
Where monitoring plans usually fall short: Privacy is treated as a legal matter only, with no link to security controls; No one is formally responsible for guiding staff and providers on PII handling; Cross-border transfers of PII occur without checking applicable restrictions; Privacy impact assessments are not performed for new processing
Source: ISO/IEC 27001 (information security management), read 30 Sep 2026
ISO/IEC 27001 A.7.4Physical security monitoring

Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.

What a reviewer asks to see: Statement of Applicability entry for control A.7.4, showing inclusion or justified exclusion, implementation status and the risks it treats; Coverage plans for CCTV and intruder detection over sensitive areas, external doors, accessible windows and unoccupied zones; Alarm and detector installation certificates to applicable standards and periodic test records, including battery-powered components; Monitoring logs or monitoring-provider reports showing alarms raised and responses; Access restrictions and hardening of CCTV and alarm systems, including protection of video feeds and remote management
Where monitoring plans usually fall short: CCTV records but nobody reviews footage or responds to alerts; Detectors are installed but never tested, with flat batteries unnoticed; Video systems are exposed on the network with default credentials; Video is retained longer than local law permits
Source: ISO/IEC 27001 (information security management), read 30 Sep 2026

Open the full text on compliance.theartofservice.com

See the specimen plan run Plan your own list