A formal accountability process that includes disciplinary actions is implemented for personnel who fail to comply with established security policies and procedures
A disciplinary process is an essential administrative control for enforcing organizational resilience policies. Awareness of the disciplinary process provides staff an additional incentive to comply with the organization’s resilience policies and ensures fair and appropriate treatment in the event that wrongdoing is suspected. From the organization’s perspective, a formalized disciplinary process provides a preplanned response to suspected infractions of cybersecurity policy that is designed to address all relevant concerns while protecting the organization to the fullest extent possible. The disciplinary process should be formalized and documented. It should ensure fair treatment of staff in compliance with all applicable regulations and agreements, protect the organization’s interests, and include a range of acceptable responses that correspond to the seriousness of the infraction. Revise the disciplinary process as needed.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: WORKFORCE-1e, WORKFORCE-1g.