GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-006 Disciplinary Process for Security Violations

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A formal disciplinary process is documented and communicated to all personnel, covering the consequences of information security policy violations. The process is applied consistently and proportionately, and investigations are conducted before sanctions are applied.

Rationale

Deterrence of intentional security violations requires credible consequences. A documented and communicated disciplinary process demonstrates organisational commitment to security policy enforcement and provides legal protection in disciplinary proceedings.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(1)(ii)(C) makes the sanction policy a required specification, and asks for sanctions applied rather than only a policy written. The evidence is the application record.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (8)

HRS-09Personnel Roles and Responsibilitiesinformative
HRS-09Personnel Roles and Responsibilitiesinformative
HIPAA-164.306.aGeneral Requirementsinformative
HIPAA-164.308.a.1.ii.CSanction Policyfull
6.4Disciplinary processfull
NIS2-CIR-10.4Disciplinary Processpartial
PS-8Personnel Sanctionsfull
CC1.5COSO Principle 5: Enforces Accountabilitypartial

Evidence (2)

policydocumentmanual

Disciplinary policy defining consequences of information security policy violations and the process for consistent, proportionate enforcement.

Example: Employee Disciplinary Policy or Code of Conduct (Confluence / HRIS policy library), with a section on information security violations, describing: violation categories, proportionate consequence tiers (informal warning through to termination), the investigation process, and appeal rights.

Test: Request the disciplinary policy. Verify: (1) information security policy violations are explicitly included as a violation category, (2) consequence tiers are defined proportionate to severity, (3) an investigation requirement (before sanctions are applied) is stated, (4) the policy has been communicated to all staff, confirmed via training completion or acknowledgement record, (5) approval date is within the last 12 months.

recorddocumentmanual

Anonymised security-related disciplinary case records for the last 12 months, or a management attestation of no violations corroborated by an export from the human resources case system for the same period.

Example: Anonymised case log entry showing case type, investigation completion date, outcome and closure date, or a signed attestation of no violations together with a case-system export for the period filtered to the security category

Test: Request either the anonymised security-related disciplinary case records for the last 12 months or a management attestation of no violations. Verify: (1) where cases exist, the investigation completed before any sanction was applied, (2) the sanction applied falls in the band the documented process sets for that severity, (3) the case record names the appeal route offered, (4) where no case exists, the attestation is supplied together with an export from the human resources case system covering the whole period and showing no case in the security category, (5) the export covers the full period rather than a sample, with its filter visible in the export rather than asserted.

Questions (2)

boolean

Does your organisation have a documented disciplinary process covering information security policy violations?

The process should define tiered consequences proportionate to severity, require investigation before sanctions are applied, and include an appeal mechanism.

multi

Which of the following apply to your disciplinary process for security violations?

It is communicated to all personnelIt defines consequences proportionate to the severity of the violationIt requires an investigation before a sanction is appliedIt provides an appeal routeEach case is recorded, with the investigation and the outcomeNone of the above

Options run from the most commonly in place to the least. Answer on the process as written and operated, not on whether evidence of a past case could be produced. A process that has never been invoked can still meet every item here.