ISO 27001 Control A.6.4: Disciplinary Process

· 5 min read · Lyudmil Arkov

Control A.6.4 is what gives the rest of your people controls their teeth. You can screen people, put security duties in their contracts, and train them, but if a deliberate violation carries no consequence, the obligations are hollow. A.6.4 requires a formal, communicated disciplinary process for information security violations - not to punish for its own sake, but to make clear that security rules are real rules. Handled well it is a deterrent and a fairness mechanism at once. This is the fourth control in our walk through Annex A.

What the control requires

Annex A control 6.4 of ISO 27001:2022 states that a disciplinary process shall be formalized and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.

Two words carry the weight:

  • Formalized - the process exists in writing, with defined steps, rather than being improvised case by case
  • Communicated - people know it exists and, broadly, what conduct it covers, so it can actually act as a deterrent

The control also reaches “other relevant interested parties” - contractors and third parties, where your agreements allow - not only employees. In the ISO 27002 attributes, A.6.4 is both preventive (deterrence) and corrective (response after a violation).

Annex A states the control; ISO 27002 gives the guidance, and your Statement of Applicability records how you apply it.

How to implement a disciplinary process

Do not build a security-only process - connect to HR

Most organizations already have a disciplinary or conduct process run by HR. The security requirement is not to create a parallel one, but to ensure information security violations are explicitly in scope of the existing process. The cleanest implementation references your HR disciplinary policy and confirms that breaches of the information security policy are grounds for action under it.

Make it fair and proportionate

A defensible process grades response to the violation. Consider factors such as whether the breach was deliberate or accidental, first-time or repeated, its actual and potential impact, and whether the person had been trained on the rule. An honest mistake by an untrained new joiner is not the same as a deliberate data exfiltration, and treating them identically undermines both fairness and credibility. Proportionality also protects the organization legally.

Keep it lawful

Disciplinary action sits squarely in employment law, which varies by jurisdiction. Due process - notice, a chance to respond, consistent treatment, documented decisions - matters both for fairness and to avoid unfair-dismissal exposure. Involve HR and, where needed, legal counsel in the design. For contractors, disciplinary “action” usually means contractual remedies, so make sure the supplier and confidentiality agreements provide for them.

Communicate it without weaponizing it

People should know the process exists and that security violations fall under it - this is what creates deterrence. Fold it into onboarding and awareness material. But tone matters: a process framed purely as a threat can suppress the event reporting you are trying to encourage. Be clear that honest mistakes reported in good faith are handled very differently from deliberate or concealed violations.

Keep proportionate records

Evidence for this control is the documented process plus, where actions have been taken, records that they followed it. These records are sensitive personal data - keep them in HR’s confidential systems with restricted access and appropriate retention, not in the general ISMS document store.

A.6.2 connection. Terms and conditions of employment create the obligations; A.6.4 is the consequence when they are breached. The contract should reference the disciplinary consequences of violation.

A.6.3 connection. Awareness and training is the fairness precondition: you can only fairly discipline someone for a rule they were told about.

A.6.8 connection. The disciplinary process and information security event reporting (A.6.8) must be balanced so that fear of discipline does not discourage honest reporting.

A.5.24 to A.5.27 connection. Incident management controls handle the security event; the disciplinary process handles the human accountability side where a person caused it.

Clause 5.2 connection. The information security policy defines the rules whose violation triggers the process.

What auditors check

A formalized process exists. Auditors look for a documented disciplinary process (usually the HR one) that explicitly covers information security violations - not just an assumption that “HR would handle it.”

It has been communicated. They check that personnel are aware the process exists, typically through onboarding or awareness records.

Coverage of third parties. Auditors probe whether contractors and suppliers are covered through contractual remedies, matching the “other relevant interested parties” wording.

Fairness and consistency. Where actions have been taken, auditors may check (carefully, given the sensitivity) that the process was followed consistently and proportionately.

Balance with reporting. Mature auditors look for evidence that the disciplinary process does not undermine a healthy reporting culture.

Common mistakes to avoid

Assuming HR has it covered. If information security violations are not explicitly within the scope of the disciplinary process, the control is not met, even if HR has a general process.

Never communicating it. A disciplinary process nobody knows about provides no deterrence. Communication is an explicit part of the control.

All-or-nothing responses. A process with no proportionality - treating every mistake as gross misconduct, or every breach as trivial - is both unfair and not credible.

Ignoring the law. Disciplinary action without due process invites unfair-dismissal claims. Keep HR and legal involved.

Scaring people out of reporting. If staff fear that reporting a mistake will trigger discipline, they will hide incidents. Make the distinction between honest reporting and deliberate violation explicit.

Storing records carelessly. Disciplinary records are sensitive personal data. Keep them confidential and access-controlled, not in shared ISMS folders.

How 27kay can help

We help organizations connect information security to their disciplinary process in a way that is fair, lawful, and actually deters violations - without poisoning the reporting culture you depend on. As part of ISO 27001 implementation, we align your security policy, contracts, awareness programme, and HR process so the accountability chain holds together and stands up to audit. For the full picture, see our ISO 27001 knowledge hub.

Not sure your disciplinary process actually covers security violations, or worried it discourages reporting? Get in touch - we will review it and help you strike the right balance.