A.6.4 People
Disciplinary process
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (4)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-8mostlyaligns with — Both controls establish a formal, graduated disciplinary process triggered by verified policy violations and scaled according to intent, severity, and prior offenses.
- IR-4partialaligns with — The ISO disciplinary process serves as one of the response actions that IR-4 may invoke after an incident has been confirmed.
- PS-6partialaligns with — The ISO control’s requirement to consider training status and policy awareness before imposing sanctions directly supports the access-agreement obligations addressed by PS-6.
Aligned NIST CSF 2.0 outcomes (7)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.PO-02mostlyaligns with — The control operationalizes policy enforcement by mandating consistent, graduated sanctions that reflect changes in requirements and ensure personnel understand consequences of non-compliance.
- GV.RR-01mostlyaligns with — The ISO control enforces leadership accountability by requiring a formal, graduated disciplinary process that deters policy violations and reinforces a risk-aware culture.
- GV.RR-02partialaligns with — By defining how violations are investigated and sanctioned, the control clarifies roles and authorities for handling misconduct within the cybersecurity risk management framework.
- PR.AT-01partialaligns with — The disciplinary process considers whether violators received proper training, thereby linking awareness outcomes to accountability when personnel fail to apply expected security knowledge.
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialmitigates — The deterrent effect of disciplinary measures lowers the probability that employees will deliberately disclose or expose sensitive information to unauthorized parties.
- CWE-284partialfinds — By establishing a formal, graduated disciplinary process for confirmed policy violations, the control reduces the likelihood that personnel will intentionally abuse or exceed granted access rights.
- CWE-732partialfinds — Personnel who know they may face sanctions for misconfiguring permissions are less likely to assign overly permissive access rights to critical resources.
- CWE-269nonedetects — Awareness of potential disciplinary consequences discourages staff from granting or retaining unnecessary privileges beyond what their role requires.
- CWE-862nonenone — The threat of disciplinary action for unauthorized actions discourages staff from invoking functionality without verifying that the required authorization checks have been performed.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.