Security Process Policy for the Termination of Employees and Contractors
Security Process Policy for the Termination of Employees and Contractors
Simplebooklet Marketing Inc. | Approved December 1, 2024
1. Purpose
This policy outlines the security procedures for the termination of employees and contractors at Simplebooklet Marketing Inc. The goal is to ensure that all access to company systems, networks, and physical premises is promptly revoked, company assets are recovered, and risks to organizational security are minimized.
2. Scope
This policy applies to all employees and contractors, including full-time, part-time, temporary staff, and third-party vendors. It covers all terminations, including voluntary resignations, involuntary terminations, and contract expirations.
3. Termination Categories
- Voluntary Resignation: Employee or contractor initiates the termination.
- Involuntary Termination: Organization initiates the termination due to performance issues, policy violations, or other reasons.
- Contract Expiration: Contractor's agreement reaches its end date without renewal.
4. Pre-Termination Security Procedures
4.1 Notification
- For voluntary resignations:
- Employees/contractors must provide a written notice at least two weeks before their last working day.
- For involuntary terminations:
- The decision must be approved by HR and the department head.
- Legal counsel should be consulted if necessary.
4.2 Coordination with IT and Security Teams
- Notify IT and security teams at least 48 hours before termination to prepare for:
- Account deactivation
- Revocation of system and physical access rights
- Recovery of company-owned devices and badges
4.3 Risk Assessment
- Conduct a risk assessment to identify potential security threats based on the employee's or contractor's role and access level.
- Plan mitigation steps to address identified risks, including monitoring for suspicious activity.
5. Termination Day Security Procedures
5.1 Security Meeting
- Conduct a termination meeting with HR, the direct manager, and, if applicable, a representative from IT or security.
- Discuss:
- Reasons for termination
- Expectations for returning company assets
- Continuing obligations under confidentiality or non-compete agreements
5.2 Access Termination
- Immediately deactivate all system access, including:
- Network accounts
- Email accounts
- Security tools, databases, and cloud services
- Revoke access to physical premises by:
- Collecting ID badges, access cards, and keys
- Changing door codes or biometric access settings
5.3 Asset Recovery
- Ensure all company-owned equipment is returned, including:
- Laptops, mobile devices, and storage devices
- Documentation or proprietary materials
- Verify the condition and integrity of returned devices and materials.
6. Post-Termination Security Procedures
6.1 Security Audit
- Perform a comprehensive security audit to confirm:
- All accounts and credentials have been deactivated
- No data has been exfiltrated or shared without authorization
- Returned devices are intact and secure
6.2 Monitoring
- Monitor for any unauthorized attempts to access company systems or data.
- Flag unusual activity for investigation by the security team.
6.3 Documentation
- Maintain detailed records of:
- Access revocations
- Returned assets
- Findings from post-termination audits
7. Compliance and Confidentiality
- Terminated employees and contractors remain bound by any confidentiality, non-compete, or intellectual property agreements signed during their tenure.
- Breaches of these agreements may result in legal action.
8. Monitoring and Review
This policy will be reviewed annually or as necessary to address changes in organizational practices or security risks.
9. Approval
Approved by: Ken Kwasnicki
Date: December 1st, 2024
Updated on: 08/09/2026
Thank you!
