Disciplinary process
Purpose
Make consequences of security violations clear, deter breaches and deal fairly with anyone who breaks the rules.
How to meet this control
In short: Establish and communicate a process for handling security violations.
- Step 01Document a formal disciplinary process for security violations and align it with the Fair Work Act and any enterprise agreement so action is procedurally fair
- Step 02Reference the disciplinary process inside the Acceptable Use Policy so consequences are visible before any breach occurs
- Step 03Define a graduated set of responses, from coaching and written warning through to termination, scaled to severity, intent and whether the act was a repeat
- Step 04Require evidence and a verified finding that a violation actually happened before any disciplinary step is taken
- Step 05Run the process jointly between HR and the line manager, with confidential records and protection of the identity of those involved
- Step 06Feed serious or deliberate cases into incident management and, where relevant, to authorities
Tip: Reference it in the AUP so consequences are clear up front.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Formalise and communicate the disciplinary process so people know action will follow a violation
- ›Do not start disciplinary action until you have verified that a violation actually occurred
- ›Apply a graduated response that weighs the nature, seriousness and impact of the breach
- ›Take into account whether the act was deliberate or accidental
- ›Consider whether it is a first offence or a repeat one
- ›Consider whether the person had actually been properly trained
- ›Factor in legal, regulatory and contractual requirements, and act immediately on deliberate violations
- ›Protect the identity of those facing disciplinary action where required
Audit evidence to keep
- - The documented disciplinary process or procedure
- - The Acceptable Use Policy clause referencing disciplinary consequences
- - Anonymised records of a disciplinary case showing the steps followed
- - Evidence that violations are verified before action, such as an investigation summary
- - HR sign-off confirming the process was applied consistently
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.6.4. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.