HRS-006 Disciplinary Process for Security Violations
Description
A formal disciplinary process is documented and communicated to all personnel, covering the consequences of information security policy violations. The process is applied consistently and proportionately, and investigations are conducted before sanctions are applied.
Rationale
Deterrence of intentional security violations requires credible consequences. A documented and communicated disciplinary process demonstrates organisational commitment to security policy enforcement and provides legal protection in disciplinary proceedings.
Applicability (9 profiles)
164.308(a)(1)(ii)(C) makes the sanction policy a required specification, and asks for sanctions applied rather than only a policy written. The evidence is the application record.
Framework Mappings (8)
| HRS-09 | Personnel Roles and Responsibilities | informative |
| HRS-09 | Personnel Roles and Responsibilities | informative |
| HIPAA-164.306.a | General Requirements | informative |
| HIPAA-164.308.a.1.ii.C | Sanction Policy | full |
| 6.4 | Disciplinary process | full |
| NIS2-CIR-10.4 | Disciplinary Process | partial |
| PS-8 | Personnel Sanctions | full |
| CC1.5 | COSO Principle 5: Enforces Accountability | partial |
Evidence (2)
Disciplinary policy defining consequences of information security policy violations and the process for consistent, proportionate enforcement.
Example: Employee Disciplinary Policy or Code of Conduct (Confluence / HRIS policy library), with a section on information security violations, describing: violation categories, proportionate consequence tiers (informal warning through to termination), the investigation process, and appeal rights.
Test: Request the disciplinary policy. Verify: (1) information security policy violations are explicitly included as a violation category, (2) consequence tiers are defined proportionate to severity, (3) an investigation requirement (before sanctions are applied) is stated, (4) the policy has been communicated to all staff, confirmed via training completion or acknowledgement record, (5) approval date is within the last 12 months.
Anonymised security-related disciplinary case records for the last 12 months, or a management attestation of no violations corroborated by an export from the human resources case system for the same period.
Example: Anonymised case log entry showing case type, investigation completion date, outcome and closure date, or a signed attestation of no violations together with a case-system export for the period filtered to the security category
Test: Request either the anonymised security-related disciplinary case records for the last 12 months or a management attestation of no violations. Verify: (1) where cases exist, the investigation completed before any sanction was applied, (2) the sanction applied falls in the band the documented process sets for that severity, (3) the case record names the appeal route offered, (4) where no case exists, the attestation is supplied together with an export from the human resources case system covering the whole period and showing no case in the security category, (5) the export covers the full period rather than a sample, with its filter visible in the export rather than asserted.
Questions (2)
Does your organisation have a documented disciplinary process covering information security policy violations?
The process should define tiered consequences proportionate to severity, require investigation before sanctions are applied, and include an appeal mechanism.
Which of the following apply to your disciplinary process for security violations?
Options run from the most commonly in place to the least. Answer on the process as written and operated, not on whether evidence of a past case could be produced. A process that has never been invoked can still meet every item here.