Skip to content
arrow_back
search
Annex A 6.4 verified ISO/IEC 27001:2022

Disciplinary Process for Information Security Violations

Ensure staff understand consequences for breaking security rules to prevent violations.

record_voice_over

Plain language

This control is about having a clear set of rules and consequences for when people in your organisation break information security policies. It's important because without it, employees might not take security seriously, potentially risking data breaches or other security incidents.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

People controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

A disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.
verified ISO/IEC 27001:2022 Annex A 6.4
priority_high

Why it matters

Without a formal, communicated disciplinary process, security policy breaches repeat, weakening deterrence and increasing legal, financial and reputational risk.

settings

Operational notes

Document and communicate disciplinary steps (warnings to termination/contract actions), align with HR/legal, keep breach evidence, apply consistently, and review outcomes after incidents.

Mapping detail

Mapping

Direction

Controls