isms.coach
← All controls

A.6.4 · People

Disciplinary process

Why it matters

Without a stated process, security policy violations have no real consequence — and auditors know that.

How a self-led small team implements it

Reference your existing HR disciplinary process rather than building a security-specific one.

What auditors expect to see

HR disciplinary policy referencing security violations.

Track A.6.4 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More people controls