I am looking for documents, suggestions, white papers on “how to handle external “employees” regarding IT Security …
For example: a big IT company sometimes hires external consultants for a certain time (eg. 6 months) for a project.
what kind of IT Security relevant things do I have to take care of when I contract him? eg. let him sign how to handle confidential data, shall I give him an email-address of “my company” or not, shall the person wear a tag when he is around in our buildung, …
Are there any guidelines, iso norms, …? do you have documents to share which handle this?
thanks for your feedback,
Andy