Managing Information Security Violations Fairly, Consistently, and Proportionately
An Information Security Disciplinary Policy establishes the organization’s approach to handling violations of information-security requirements by employees, contractors, and other personnel.
The purpose is not simply to punish individuals. The policy provides a structured process for identifying security violations, assessing their seriousness, applying proportionate action, and reducing the likelihood of recurrence.
Security violations may include deliberate misuse, unauthorized access, policy violations, inappropriate information handling, failure to follow security requirements, or other behavior that creates information-security risk.
Identify → Investigate → Assess → Decide → Act → Record → Review → Improve
1. Purpose
The purpose of this policy is to:
- Define information-security violations
- Establish consistent disciplinary principles
- Support fair and proportionate treatment
- Protect organizational information and systems
- Deter intentional or negligent security violations
- Define escalation requirements
- Support incident and investigation processes
- Ensure appropriate management and HR involvement
- Protect evidence and investigation records
- Support corrective action and continual improvement
Disciplinary action should be based on established facts, applicable policies, contractual requirements, and applicable employment and legal requirements.
2. Scope
This policy applies to personnel who have access to organizational information or systems, including:
☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary personnel
☐ Privileged users
☐ Remote workers
☐ Other personnel where contractually applicable
Third-party organizations may be subject to contractual remedies and supplier-management processes rather than employee disciplinary procedures.
3. Core Principles
The organization should apply the following principles:
Fairness
Personnel should have an opportunity to understand and respond to allegations.
Proportionality
The response should reflect the seriousness and circumstances of the violation.
Consistency
Similar circumstances should generally receive comparable treatment.
Evidence-Based Decisions
Actions should be based on reliable information and documented evidence.
Confidentiality
Investigations and disciplinary records should be restricted to authorized personnel.
Legal Compliance
Actions must comply with applicable employment, privacy, labor, contractual, and other legal requirements.
Non-Retaliation
Personnel should not be disciplined merely for reporting genuine security concerns or incidents in good faith.
Risk Reduction
The objective is to reduce security risk and prevent recurrence, not merely to assign blame.
4. Relationship With Security Incidents
A security incident and a disciplinary matter are not automatically the same thing.
For example:
An employee accidentally clicks a phishing link and immediately reports it.
This may be a security incident requiring investigation and awareness reinforcement, but it does not automatically justify disciplinary action.
In contrast:
An employee deliberately accesses customer information without authorization.
This may represent both a security incident and a potential disciplinary matter.
The organization should assess each situation individually.
5. Information Security Violations
Potential violations include:
Unauthorized Access
- Accessing systems without authorization
- Attempting to bypass access controls
- Using another person’s account
- Sharing credentials
- Using unauthorized privileged access
Information Handling
- Unauthorized disclosure
- Improper sharing of confidential information
- Sending restricted information to unauthorized recipients
- Unauthorized copying or removal of information
- Improper disposal
Authentication
- Sharing passwords
- Sharing MFA codes
- Approving unauthorized MFA requests
- Circumventing authentication controls
Technology Use
- Installing unauthorized software
- Using unauthorized cloud services
- Connecting unauthorized devices
- Circumventing security controls
- Disabling security software without authorization
Security Monitoring
- Tampering with logs
- Disabling monitoring
- Deleting security evidence
- Circumventing security monitoring
Acceptable Use
- Using organizational systems for prohibited activities
- Misuse of organizational resources
- Unauthorized system activity
Confidentiality
- Violating confidentiality obligations
- Disclosing protected business information
- Misusing customer information
Security Procedures
- Deliberately bypassing required security procedures
- Repeated failure to follow security requirements
- Failure to complete required security activities without reasonable justification
6. Intentional vs Unintentional Violations
The organization should distinguish between:
Intentional
The person knowingly violated a security requirement.
Reckless
The person demonstrated serious disregard for a known security requirement.
Negligent
The person failed to exercise reasonable care.
Accidental
The event occurred without intent or unreasonable disregard.
Good-Faith Reporting
The person made a mistake but promptly reported the issue and cooperated with the response.
These circumstances should be considered when determining an appropriate response.
7. Severity Classification
A practical classification may be used.
| Level | Description | Example |
|---|---|---|
| Low | Minor or isolated violation with limited risk | Minor policy deviation |
| Medium | Meaningful security weakness or repeated violation | Repeated unauthorized file-sharing |
| High | Significant security risk or serious violation | Unauthorized access to sensitive information |
| Critical | Deliberate or severe activity causing major risk or harm | Intentional data theft or destructive activity |
The organization’s approved risk methodology may use different classifications.
8. Factors Considered
When determining an appropriate response, consider:
☐ Nature of the violation
☐ Intent
☐ Actual impact
☐ Potential impact
☐ Information classification
☐ Systems affected
☐ Customer impact
☐ Personal-data exposure
☐ Regulatory implications
☐ Duration
☐ Scope
☐ Previous violations
☐ Employee knowledge of the requirement
☐ Training provided
☐ Role and responsibilities
☐ Level of access
☐ Privileged access
☐ Cooperation during investigation
☐ Promptness of reporting
☐ Attempts to conceal activity
☐ Corrective actions already taken
☐ Applicable legal requirements
9. Disciplinary Response Levels
Possible responses may include:
Level 1 — Awareness Reinforcement
Appropriate for minor or accidental issues.
Examples:
- Security reminder
- Additional training
- Coaching
- Policy clarification
Level 2 — Formal Warning
May be appropriate for repeated or more significant violations.
Examples:
- Written warning
- Formal performance discussion
- Mandatory retraining
Level 3 — Restricted Access
Where security risk requires immediate protection.
Examples:
- Temporary access restriction
- Removal of privileged access
- Suspension of specific system access
Access restrictions may be implemented as a security-control measure and are not necessarily disciplinary action.
Level 4 — Formal Disciplinary Action
May be appropriate for serious or repeated violations, subject to applicable HR processes.
Level 5 — Termination or Contractual Action
May be considered for severe violations where permitted by applicable law and contractual arrangements.
For contractors or suppliers, contractual remedies may apply.
10. Security Access Suspension
Where there is an immediate security risk, access may need to be restricted before a disciplinary decision is made.
Examples:
☐ Disable account
☐ Suspend privileged access
☐ Revoke VPN access
☐ Revoke cloud access
☐ Revoke source-code access
☐ Revoke database access
☐ Restrict physical access
☐ Rotate credentials or secrets
☐ Preserve relevant evidence
Security access suspension should be handled through the organization’s incident and access-management processes.
11. Investigation Process
A potential disciplinary matter should be assessed through an appropriate process.
Report → Preserve → Assess → Investigate → Establish Facts → Review Context → Decide → Document → Follow Up
Investigation activities may include:
☐ Review security logs
☐ Review access records
☐ Review relevant communications
☐ Interview relevant personnel
☐ Review system activity
☐ Review security alerts
☐ Review policies
☐ Review training records
☐ Review previous incidents
☐ Review evidence
Technical investigation should be performed only by authorized personnel.
12. Evidence Preservation
Where a serious violation is suspected:
☐ Relevant logs preserved
☐ Relevant account information preserved
☐ Relevant devices preserved where appropriate
☐ Evidence access restricted
☐ Evidence integrity protected
☐ Investigation records maintained
☐ Chain of custody used where appropriate
Evidence collection should follow the organization’s approved incident investigation and evidence-preservation procedures.
13. Employee Notification
Where appropriate and legally permissible, the individual should be informed of:
- The concern or allegation
- Relevant policy or requirement
- Applicable process
- Opportunity to provide information
- Expected next steps
The organization should avoid making premature conclusions before the appropriate review has been completed.
14. Investigation Outcome
Possible outcomes include:
☐ No violation established
☐ Policy misunderstanding
☐ Accidental violation
☐ Negligent violation
☐ Repeated violation
☐ Intentional violation
☐ Security incident confirmed
☐ Further investigation required
☐ Corrective action required
☐ Disciplinary action required
☐ Risk acceptance required
15. Employee Cooperation
Personnel are expected to cooperate with authorized security investigations, subject to applicable rights and legal requirements.
Cooperation may include:
- Providing relevant information
- Participating in interviews
- Preserving evidence
- Following security instructions
- Supporting incident containment
- Participating in corrective actions
Attempts to obstruct or intentionally mislead an authorized investigation may be considered when determining the appropriate response.
16. Self-Reporting and Good-Faith Reporting
The organization should encourage prompt reporting of mistakes and suspected security incidents.
Examples:
“I accidentally sent confidential information to the wrong recipient.”
“I clicked a suspicious link.”
“I approved an MFA request that I did not initiate.”
“I believe my password may have been exposed.”
Prompt reporting may allow the organization to contain an incident before significant harm occurs.
Personnel should not be discouraged from reporting mistakes in good faith.
17. Non-Retaliation
The organization should not retaliate against personnel who:
- Report a suspected security incident in good faith
- Report a policy violation
- Raise a security concern
- Cooperate with an authorized investigation
- Report suspected misuse or security weaknesses
This principle does not prevent action where an investigation establishes that the reporting individual independently committed a violation.
18. Security Awareness and Disciplinary Action
Security training should be considered when evaluating whether an individual reasonably understood a requirement.
Review:
☐ Was the policy communicated?
☐ Was relevant training provided?
☐ Was role-based training provided?
☐ Was the requirement clearly documented?
☐ Was the individual informed of changes?
☐ Was the individual expected to have the required knowledge?
☐ Was the individual previously warned?
Training records may therefore form part of the investigation evidence.
19. Repeated Violations
Repeated violations should be assessed carefully.
Examples:
- Repeated failure to complete mandatory training
- Repeated unauthorized information sharing
- Repeated password or authentication violations
- Repeated failure to follow access requirements
- Repeated policy violations after corrective action
The organization should determine whether recurrence is caused by:
- Lack of awareness
- Unclear procedures
- Poor system design
- Excessive process complexity
- Insufficient technical controls
- Workload or operational pressure
- Individual negligence
- Deliberate misconduct
The root cause should be addressed rather than automatically escalating punishment.
20. Privileged User Violations
Additional consideration may be required when the individual has:
☐ Administrator access
☐ Production access
☐ Database access
☐ Cloud administration access
☐ Security administration access
☐ Source-code access
☐ Access to security monitoring
☐ Access to sensitive customer information
Privileged-user violations may require immediate access restriction and enhanced investigation.
21. Customer and Personal Data
If a violation involves customer or personal data:
☐ Data involved identified
☐ Classification determined
☐ Scope assessed
☐ Potential exposure assessed
☐ Incident process initiated
☐ Privacy assessment performed where applicable
☐ Regulatory requirements considered
☐ Contractual requirements considered
☐ Notification requirements assessed
☐ Evidence preserved
Disciplinary action should not replace the organization’s incident, privacy, or breach-response processes.
22. Regulatory and Legal Considerations
Before taking formal disciplinary action, the organization should consider applicable:
- Employment law
- Labor requirements
- Privacy requirements
- Contractual obligations
- Regulatory requirements
- Collective agreements where applicable
- Internal HR procedures
The policy should be reviewed and adapted by appropriate HR and legal personnel for the jurisdictions in which the organization operates.
23. Confidentiality
Disciplinary and investigation information should be restricted to authorized personnel.
Access may include, depending on the situation:
☐ HR
☐ Information Security
☐ Legal
☐ Management
☐ Compliance
☐ Internal Audit where appropriate
☐ External advisors where authorized
Personnel involved in investigations should maintain confidentiality.
24. Disciplinary Record
Maintain an appropriate record containing:
| Field | Details |
|---|---|
| Case ID | |
| Date Reported | |
| Person/Role | |
| Violation | |
| Relevant Policy | |
| Severity | |
| Systems/Information Affected | |
| Investigation Owner | |
| Evidence | |
| Findings | |
| Employee Response | |
| Risk | |
| Immediate Controls | |
| Corrective Action | |
| Decision | |
| HR Review | |
| Approval | |
| Closure Date |
Records should be protected and retained according to applicable organizational and legal requirements.
25. Corrective Action
Disciplinary action should not be the only response.
Possible corrective actions include:
☐ Additional training
☐ Policy clarification
☐ Process improvement
☐ Technical control
☐ Access restriction
☐ Additional monitoring
☐ Role change
☐ Privileged-access review
☐ Increased supervision
☐ Security awareness campaign
☐ Procedure update
☐ Risk treatment
The goal is to reduce the likelihood and impact of recurrence.
26. Management Escalation
Escalate significant cases where there is:
☐ Critical information exposure
☐ Customer impact
☐ Personal-data exposure
☐ Regulatory implications
☐ Deliberate misuse
☐ Privileged-user abuse
☐ Significant financial impact
☐ Major operational disruption
☐ Repeated serious violations
☐ Potential criminal activity
Escalation should follow the organization’s incident-management, HR, legal, and management-escalation procedures.
27. Third-Party Personnel
Where a security violation involves a contractor or third-party worker:
☐ Incident reported
☐ Supplier owner notified
☐ Access reviewed
☐ Access restricted where necessary
☐ Supplier security requirements reviewed
☐ Contractual requirements reviewed
☐ Supplier corrective action requested where appropriate
☐ Contractual remedies considered
☐ Personnel replacement considered where appropriate
☐ Offboarding performed where required
Third-party personnel should generally be handled through applicable contractual and supplier-management processes.
28. Disciplinary Decision Matrix
The following is an example only:
| Situation | Possible Response |
|---|---|
| Minor accidental violation | Coaching/training |
| First-time low-risk policy violation | Awareness/retraining |
| Repeated low-risk violation | Formal warning/retraining |
| Significant negligent violation | Formal HR review and corrective action |
| Unauthorized access attempt | Investigation/access restriction |
| Deliberate unauthorized access | Formal disciplinary review |
| Intentional data disclosure | Formal disciplinary/legal review |
| Destruction or manipulation of evidence | Serious escalation |
| Privileged-user misuse | Immediate access review + investigation |
| Deliberate theft/misuse | HR/legal/management escalation |
The final action should depend on the facts and applicable law.
29. AWS SaaS Startup Example
Consider a SaaS startup operating:
- AWS
- GitHub
- Production databases
- Customer data
- Microsoft 365
- Remote employees
Scenario
A developer intentionally uses another employee’s credentials to access a production database.
Immediate Response
- Restrict the unauthorized access.
- Preserve relevant logs.
- Identify affected systems and information.
- Start the incident investigation.
- Notify appropriate security, management, HR, and legal stakeholders.
- Assess customer and regulatory impact.
Investigation
Determine:
- Why access occurred
- Whether the individual knew the access was unauthorized
- What information was accessed
- Whether information was copied or changed
- Whether the credentials were shared
- Whether the activity was concealed
- Whether similar activity occurred previously
Outcome
The organization determines the appropriate security, corrective, HR, contractual, or legal response based on established facts.
Security containment → Investigation → Risk assessment → HR/legal review → Decision → Corrective action → Follow-up
30. Startup-Friendly Model
A startup should avoid creating a complex disciplinary bureaucracy.
Maintain clear ownership:
| Responsibility | Owner |
|---|---|
| Security violation identification | All personnel |
| Initial security assessment | Security/IT |
| Incident response | Security/IT |
| Employee disciplinary process | HR |
| Legal assessment | Legal/authorized counsel |
| Risk decision | Appropriate risk owner |
| Access restriction | IT/Security |
| Management escalation | Management |
| Corrective action | Assigned owner |
| Final record | HR/Security as appropriate |
Security should identify and manage the security risk; HR should manage employee disciplinary processes.
31. Common Mistakes
Avoid:
- Automatically punishing employees for every security incident.
- Treating accidental mistakes as intentional misconduct.
- Discouraging incident reporting.
- Taking disciplinary action without appropriate investigation.
- Ignoring applicable employment law.
- Allowing managers to bypass HR processes.
- Using disciplinary action instead of fixing weak technical controls.
- Failing to preserve evidence.
- Giving excessive access to investigation records.
- Applying inconsistent disciplinary decisions.
- Ignoring third-party contractual processes.
- Failing to distinguish security containment from disciplinary action.
- Failing to document the decision rationale.
- Retaining unnecessary sensitive personnel information.
32. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Establishes overall security requirements |
| Information Security Awareness Policy | Defines awareness expectations |
| Security Awareness and Training Procedure | Defines training |
| Employee Security Responsibilities | Defines personnel responsibilities |
| Acceptable Use Policy | Defines acceptable use |
| Access Management Procedure | Controls system access |
| Incident Response Procedure | Handles security incidents |
| Incident Investigation Procedure | Supports investigation |
| Evidence Preservation Procedure | Protects investigation evidence |
| Employee Screening Policy | Supports personnel security |
| Employee Offboarding Procedure | Removes access |
| Corrective Action Tracker | Tracks remediation |
| Information Security Exception Register | Records approved exceptions |
| HR Disciplinary Procedure | Governs employee disciplinary processes |
| Supplier Security Requirements | Applies to third-party personnel |
33. ISO 27001 Connection
A disciplinary policy can support the organization’s personnel-security framework by establishing consequences for violations of information-security requirements.
It can support areas relating to:
- Information-security responsibilities
- Security awareness
- Acceptable use
- Access control
- Incident management
- Protection of information
- Personnel security
- Corrective action
- Continual improvement
The Information Security Disciplinary Policy is not itself a universally prescribed ISO 27001 document. The organization should determine appropriate disciplinary and personnel-security arrangements based on its risks, organizational structure, employment arrangements, legal requirements, contractual obligations, and applicable controls.
The disciplinary process should also remain separate from the technical investigation process where appropriate.
34. Final Audit Checklist
☐ Disciplinary policy approved
☐ Scope defined
☐ Security violations defined
☐ Intentional and accidental behavior distinguished
☐ Severity levels defined
☐ Proportionality principle established
☐ HR responsibilities defined
☐ Security responsibilities defined
☐ Investigation process defined
☐ Evidence-preservation requirements defined
☐ Access restriction process defined
☐ Good-faith reporting protected
☐ Non-retaliation principle established
☐ Legal requirements considered
☐ Confidentiality requirements defined
☐ Third-party process defined
☐ Corrective-action process defined
☐ Disciplinary records controlled
☐ Management escalation defined
☐ Policy reviewed periodically
35. Final Audit Trail
For a significant information-security violation, the organization should be able to demonstrate:
What happened?
What security requirement was involved?
Was the activity accidental, negligent, reckless, or intentional?
What information or systems were affected?
What evidence supports the conclusion?
Was immediate security containment required?
Was the individual given appropriate opportunity to respond?
Were HR and legal requirements considered?
Was the response proportionate?
What corrective action was taken?
Was access appropriately managed?
Was the case properly documented and closed?
What can be improved to prevent recurrence?
Final Principle
Information-security disciplinary action should be fair, evidence-based, proportionate, legally appropriate, and focused on reducing security risk—not on discouraging employees from reporting mistakes or security incidents.
Security Disciplinary Lifecycle:
Identify → Preserve → Investigate → Assess → Decide → Act → Record → Follow Up → Improve
