unified
UC-HR-04 — Enforce a formal disciplinary process for violations
A formal, communicated disciplinary process is applied to personnel who violate information security policies, providing graduated, consistent sanctions proportional to severity and intent. Violations, sanctions applied, and notifications to defined roles are documented and retained, and outcomes feed back into awareness and control improvements.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Human Resources / Personnel Security
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-HR-04
- title
- Enforce a formal disciplinary process for violations
- statement
- A formal, communicated disciplinary process is applied to personnel who violate information security policies, providing graduated, consistent sanctions proportional to severity and intent. Violations, sanctions applied, and notifications to defined roles are documented and retained, and outcomes feed back into awareness and control improvements.
- domain
- Human Resources / Personnel Security
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PS-8
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.6.4
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-HR-04 — Enforce a formal disciplinary process for violations mitigates Insufficient personnel screening and vetting
- strength
- related
- rationale
- Consistent, proportional sanctions deter personnel, including potential malicious or negligent insiders, from misusing access or violating policy.
- UC-HR-04 — Enforce a formal disciplinary process for violations maps_to A.6.4 — Disciplinary process
- framework
- iso-27001
- control_id
- A.6.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-HR-04 — Enforce a formal disciplinary process for violations maps_to PS-8 — Personnel Sanctions
- framework
- nist-800-53
- control_id
- PS-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-04 — Enforce a formal disciplinary process for violations
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-04 — Enforce a formal disciplinary process for violations
- Security Control Assessment & POA&M Remediation tests UC-HR-04 — Enforce a formal disciplinary process for violations
- Personnel Screening, Agreements & Sanctions Administration operates UC-HR-04 — Enforce a formal disciplinary process for violations
- UC-HR-04 — Enforce a formal disciplinary process for violations mitigates Missing security terms in contracts and no disciplinary process
- strength
- primary
- rationale
- Supplies the formal, graduated disciplinary process the risk names as absent, restoring deterrence and recourse for security-policy violations.