A.6.4 People
Disciplinary process
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (5)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-8mostlyaligns with — Both controls establish a formal, graduated disciplinary process triggered by verified policy violations and scaled according to intent, severity, and prior offenses.
- PS-8mostlycovers — A.6.4's full requirement to maintain and apply a disciplinary process for policy violations directly accounts for the core formal sanctions process in PS-8, but leaves a residual on the specific notification timing and details that PS-8 additionally mandates.
- IR-4partialaligns with — The ISO disciplinary process serves as one of the response actions that IR-4 may invoke after an incident has been confirmed.
- PS-6partialaligns with — The ISO control’s requirement to consider training status and policy awareness before imposing sanctions directly supports the access-agreement obligations addressed by PS-6.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.PO-02mostlyaligns with — The control operationalizes policy enforcement by mandating consistent, graduated sanctions that reflect changes in requirements and ensure personnel understand consequences of non-compliance.
- GV.RR-01mostlyaligns with — The ISO control enforces leadership accountability by requiring a formal, graduated disciplinary process that deters policy violations and reinforces a risk-aware culture.
- GV.RR-02partialaligns with — By defining how violations are investigated and sanctioned, the control clarifies roles and authorities for handling misconduct within the cybersecurity risk management framework.
- PR.AT-01partialaligns with — The disciplinary process considers whether violators received proper training, thereby linking awareness outcomes to accountability when personnel fail to apply expected security knowledge.
- GV.PO-02implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.RR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.RR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AT-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-269nonedetects — Awareness of potential disciplinary consequences discourages staff from granting or retaining unnecessary privileges beyond what their role requires.
- CWE-200mitigates — The deterrent effect of disciplinary measures lowers the probability that employees will deliberately disclose or expose sensitive information to unauthorized parties.
- CWE-284finds — By establishing a formal, graduated disciplinary process for confirmed policy violations, the control reduces the likelihood that personnel will intentionally abuse or exceed granted access rights.
- CWE-732finds — Personnel who know they may face sanctions for misconfiguring permissions are less likely to assign overly permissive access rights to critical resources.
Mitigated MITRE ATT&CK techniques (131)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1021.004prevents — A disciplinary process (with graduated sanctions, deterrence messaging, and immediate action for deliberate violations) can deter some intentional insider misuse of valid accounts for SSH but does not stop the technique from being executed by external adversaries, compromised credentials, or untrained actors.
- T1052.001prevents — A.6.4's graduated disciplinary process (including as a deterrent) can prevent intentional insider USB exfiltration by trained personnel who understand policy consequences, but leaves accidental cases, untrained users, non-personnel vectors, and air-gapped scenarios largely untouched.
- T1110.001prevents — A.6.4's deterrent effect (via graduated disciplinary consequences and explicit use as a deterrent) can stop some insiders from choosing to run password guessing, but has no effect on external adversaries or automated techniques and does not alter the technical conditions that allow the technique to run.
- T1110.004prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including immediate action for deliberate violations) can prevent some insider or negligent credential-reuse behaviors that enable stuffing, but has no reach on external adversaries performing the technique.
- T1137.001prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can stop some insiders from choosing to plant malicious Office templates for persistence, but has no effect on external adversaries, automated malware, or already-compromised accounts that execute the technique.
- T1204prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including for intentional violations) can prevent some users from choosing to execute adversary-supplied payloads, but this is a minority slice of the technique given social-engineering deception, non-malicious user error, and technical execution vectors that training-plus-discipline do not stop.
- T1204.002prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including for deliberate violations) can prevent some user-driven malicious-file execution arising from social engineering or policy non-compliance, but leaves the bulk of the technique (technical delivery, masquerading, user error, non-personnel vectors) untouched.
- T1566prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including for intentional violations) can stop some insider-enabled or repeated phishing by trained personnel, but has no bearing on external adversaries executing the technique.
- T1566.002prevents — A.6.4's explicit purpose and guidance include using the disciplinary process as a deterrent to prevent violations of information security policy and procedures, which reaches the social-engineering/user-action slice of spearphishing (e.g., clicking malicious links or granting consent) but leaves the technical delivery, obfuscation, and non-policy-violation vectors untouched.
- T1566.003prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can stop some employees from falling for or assisting spearphishing via service, but the technique is executed by external adversaries and most of the social-engineering surface is untouched by internal discipline.
- T1566.004prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can prevent some intentional social-engineering violations like vishing when users fear consequences, but this is only a slice of the human-factors technique whose success also depends on training, awareness, technical controls, and accidental compliance failures.
- T1598prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including for intentional violations) can stop some internal personnel from performing or assisting T1598-style phishing, but the technique is primarily executed by external adversaries and the control has no technical or procedural reach against non-personnel actors.
- T1598.001prevents — A.6.4's deterrent effect via graduated disciplinary consequences (including for intentional policy violations) can stop some employees from falling for or assisting spearphishing lures that violate policy, but the technique is executed externally by the adversary and most of its social-engineering surface is untouched by internal discipline.
- T1598.002prevents — A.6.4 uses the disciplinary process explicitly as a deterrent to prevent policy violations (including social engineering that leads to spearphishing success), but only reaches the internal actor slice and does not stop external adversaries from sending the attachment.
- T1598.003prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can stop some internal personnel from executing spearphishing when they are the actor, but the control addresses only post-violation discipline of organizational insiders and has no reach against external adversaries or the social-engineering delivery itself.
- T1598.004prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can stop some internal personnel from executing or assisting vishing when they understand the personal consequences, but this is only a slice of the PRE technique which is overwhelmingly executed by external adversaries, hired call centers, or automated robocalls outside the disciplinary scope.
- T1684prevents — A.6.4's explicit purpose and guidance to use the disciplinary process as a deterrent (with graduated sanctions scaled to intent, training, and gravity) constrains the human-behavior slice of social engineering by raising perceived personal cost, but leaves the bulk of the technique (persuasion channels, narratives, urgency tactics, and non-malicious or first-time unwitting actions) untouched.
- T1684.001prevents — A.6.4's deterrent effect and graduated sanctions (including immediate action for deliberate violations) can stop some insider or authorized-user impersonation attempts by raising perceived consequences, but the technique is primarily external social engineering against victims who are not the organization's own personnel, so only a minority slice is reached.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.