Why it matters
Without a stated process, security policy violations have no real consequence — and auditors know that.
How a self-led small team implements it
Reference your existing HR disciplinary process rather than building a security-specific one.
What auditors expect to see
HR disciplinary policy referencing security violations.
Track A.6.4 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS