Skip to content
Singahi

Compliance · guide

ISO 27001 A.6.4: Disciplinary Process

52 min read

Share
On this page

Quick Reference (60 Seconds)

AttributeDetail
Control IDA.6.4
TitleDisciplinary Process
ObjectiveEnsure a formal disciplinary process is in place for employees who commit information security breaches
DomainPeople
ISO 27001:2022 ClauseAnnex A.6.4
What You Must DoEstablish, document, and enforce a fair disciplinary process for information security violations with graduated sanctions and due process
OwnerHR / Legal / CISO
Maturity Level 1Ad-hoc disciplinary action; no formal process
Maturity Level 2Basic disciplinary policy; informal enforcement
Maturity Level 3Formal disciplinary process; graduated sanctions; documented investigations; appeal mechanism
Maturity Level 4Consistent enforcement; automated case tracking; metrics-driven; integrated with HRIS; union-compliant
Maturity Level 5Fair, consistent, learning-oriented process; outcomes measured and fed back into training and controls; good security behaviour recognised
ISO 27002 attributesControl type: Preventive, Corrective · Properties: Confidentiality, Integrity, Availability · Concepts: Protect, Respond · Capabilities: Human resource security · Domains: Governance and ecosystem

What the Control Asks For

Do you need this control?

A.6.4 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Most organisations with staff include it, usually by linking information security breaches to the existing HR disciplinary process. The process must follow Indian labour law and natural justice.

The Control in Brief

Annex A 6.4 asks organizations to formalise and communicate a disciplinary process so that action can be taken against personnel and other relevant interested parties who violate the information security policy.

Implementation Guidance (ISO 27002:2022, paraphrased)

  • The disciplinary process should not start without prior verification that a violation occurred (evidence collected under A.5.28)
  • It should provide a graduated response that takes into account: (a) the nature (who, what, when, how) and gravity of the breach and its consequences; (b) whether it was intentional (malicious) or unintentional (accidental); (c) whether it is a first or repeated offence; (d) whether the person was properly trained
  • The response should consider legal, statutory, regulatory, contractual and business requirements
  • The process should act as a deterrent, and allow immediate action for deliberate violations
  • The identity of people subject to disciplinary action should be protected in line with applicable requirements
  • Good information security behaviour can be recognised and rewarded

Good practice on top of this: a documented procedure, communication to all staff, consistency, an appeal route and securely kept records.

"Shall" vs "Should" Analysis

  • Shall (once you have selected this control): a disciplinary process is formalised and communicated
  • Should: Specific sanctions and procedures are flexible based on organizational context and legal requirements

Common Misinterpretations

MisinterpretationReality
"Disciplinary process is just HR's job"Security must define what constitutes a security breach and appropriate sanctions; HR manages the process
"We can fire anyone for a security mistake"Indian labor law requires due process; termination must be for gross misconduct with fair investigation
"Disciplinary action is always punitive"Disciplinary process should also be corrective, retraining, mentoring, and improvement
"Only intentional breaches need discipline"Negligent breaches that cause harm may also require disciplinary action
"We don't need a formal process for small companies"Even startups need basic disciplinary procedures to meet ISO 27001 requirements

Why Disciplinary Process Matters

The Business Risk Narrative

A formal disciplinary process is essential for maintaining security culture and accountability. Without it, security policies become unenforceable:

  • Labour disputes can take years to resolve, and reinstatement with back wages can be ordered if the process was unfair
  • DPDP Act 2023: a breach caused by staff misuse is still the fiduciary's breach; failing to take reasonable safeguards can attract penalties of up to ₹250 crore
  • Courts in India look at whether the employer followed "principles of natural justice" (fair hearing, opportunity to defend)

Regulatory Landscape in India

RegulationDisciplinary Process RequirementConsequence
Industrial Relations Code 2020 (in force from 21 Nov 2025; replaced the Industrial Disputes Act 1947 and the Industrial Employment (Standing Orders) Act 1946)Standing orders (certified, or the model standing orders) set misconduct, suspension and the disciplinary procedure for covered establishments; dismissal must follow due processUnfair dismissal claims: reinstatement, back wages
Code on Wages 2019 (replaced the Payment of Wages Act 1936)Deductions from wages only on permitted grounds and within limits (s.18), after an opportunity to show causePenalties; recovery orders
State Shops and Establishments ActsConditions of service for shops and offices; some states set notice and termination rulesPenalties under the state Act
Companies Act 2013, s.177Listed and certain other companies must run a vigil (whistle-blower) mechanism with protection against victimisation, reporting to the Audit CommitteePenalties for non-compliance
DPDP Act 2023Disciplinary and investigation records are personal data: process them for employment purposes (s.7(i)), protect them (s.8(5)) and erase them when no longer needed (s.8(7))Up to ₹250 crore for failing to take reasonable safeguards
Principles of natural justice (case law)Notice of charges, a fair hearing, an unbiased decision-maker and a reasoned decisionOrders set aside if not followed

Industry-Specific Consequences

IndustryDisciplinary Process Failure Scenario
BFSIEmployee shares customer data without consequence; other employees follow; RBI audit failure; systemic breach
HealthtechNurse accesses celebrity patient records without authorization; no action taken; media scandal; DPDP exposure
SaaS / B2BDeveloper repeatedly bypasses security review; no action; vulnerabilities accumulate; customer exodus
E-commerceWarehouse employee steals customer data repeatedly; no formal action; DPDP penalty; class action
GovernmentEmployee leaks classified data; no formal disciplinary process; national security breach; Official Secrets Act
ManufacturingSafety violations ignored; no disciplinary process; fatal accident; criminal prosecution

Cost of Getting It Wrong

  • Inconsistent or unfair discipline is challenged before labour authorities and courts, often for years, with possible reinstatement and back wages
  • Perceived unfairness damages morale and discourages people from reporting incidents

Scope and Applicability

What the Control Covers

  • Formal disciplinary procedure: Documented, step-by-step process for handling violations
  • Graduated sanctions: Proportionate consequences based on violation severity
  • Investigation process: Fair, evidence-based investigation of alleged violations
  • Due process: Show cause, hearing, opportunity to defend, reasoned decision
  • Appeal mechanism: Process for challenging disciplinary decisions
  • Communication: Employees informed of disciplinary process and consequences
  • Record keeping: Secure maintenance of disciplinary records
  • Corrective action: Retraining, mentoring, improvement plans alongside sanctions
  • Union compliance: Process aligned with collective bargaining agreements and standing orders
  • Cross-reference: Linkage to employment terms, security policies, and legal requirements

Who It Applies To

RoleResponsibility
HRDisciplinary process design, investigation support, employee communication, records management, labor law compliance
LegalLegal compliance, due process review, termination documentation, labour court defense, appeal review
CISODefining security breach categories, assessing severity, recommending sanctions, investigating technical violations
Line ManagersIdentifying violations, supporting investigations, enforcing sanctions, monitoring improvement
Security TeamTechnical investigation, evidence collection, breach assessment, violation documentation
EmployeeComplying with policies, responding to allegations, participating in hearings, appealing decisions
Union RepresentativesRepresenting union members, ensuring fair process, participating in joint committees (if applicable)
Compliance ManagerEnsuring process meets regulatory requirements, audit support, evidence preparation
Board / ManagementReviewing critical cases, policy approval, risk acceptance, strategic oversight

What It Does NOT Cover

  • General performance management (covered by HR processes)
  • Grievance handling by employees against employer (covered by grievance procedures)
  • Criminal prosecution (covered by law enforcement)
  • Civil litigation (covered by Legal)
  • Termination for non-security reasons (covered by general HR/termination procedures)

Size-Based Applicability

Organization SizeApproach
Startups (< 50)Simple disciplinary procedure (2-3 pages); graduated sanctions (verbal, written, termination); basic documentation
SMB (50-500)Formal disciplinary policy; investigation committee; graduated sanctions; appeal process; basic case tracking
Mid-market (500-5000)Complete disciplinary process; multi-level investigation; automated case tracking; union compliance; performance integration
Enterprise (5000+)Enterprise disciplinary framework; predictive analytics; behavioral forensics; union/works council integration; global consistency

Key Definitions and Terminology

TermDefinitionSource
Disciplinary ProcessA formal procedure for addressing violations of organizational policies and rulesHR Management
Gross MisconductSerious violation that may warrant immediate termination without noticeIndustrial Law
Show Cause NoticeWritten notice requiring an employee to explain why disciplinary action should not be takenIndian Labour Law
Domestic InquiryInternal inquiry conducted by the employer before disciplinary actionStanding orders and case law
Principles of Natural JusticeFair hearing, opportunity to present case, impartial decision-maker, reasoned decisionAdministrative law and case law (constitutional only for public employment, Art. 311)
Graduated SanctionsProgressive penalties that increase with repeated or severe violationsISO 27002
SuspensionTemporary removal from duties pending investigation or as punishmentIndustrial Law
TerminationEnd of employment relationship, with or without noticeLabour Law
AppealProcess for challenging a disciplinary decisionHR Practice
Corrective ActionNon-punitive measures aimed at improving behavior (retraining, mentoring)HR Practice
Standing OrdersRules of conduct for industrial establishments certified by the labor authorityIndustrial Relations Code 2020
Collective Bargaining Agreement (CBA)Negotiated agreement between employer and union governing employment termsLabour Law
Industrial TribunalAdjudicating body for industrial disputes in IndiaIndustrial Relations Code 2020
Labour CourtCourt for resolving industrial disputesIndustrial Relations Code 2020
WorkmanEmployee as defined under the Industrial Relations Code 2020 (generally non-managerial; formerly the Industrial Disputes Act)Industrial Relations Code 2020
MisconductViolation of organizational rules or standards of conductIndustrial Law
Ex-Parte DecisionDecision made without hearing the other party (allowed only after due notice and absence)Legal Procedure
Charge SheetFormal document listing allegations against an employeeIndustrial Law
Enquiry OfficerPerson appointed to conduct domestic inquiryIndustrial Law
Presenting OfficerPerson who presents management's case in domestic inquiryIndustrial Law
Defence RepresentativePerson who assists the employee in defending chargesIndustrial Law
Witness ExaminationProcess of questioning witnesses during inquiryLegal Procedure
FindingsConclusions reached by the enquiry officer after investigationIndustrial Law
Order of PunishmentFormal decision imposing sanctionsIndustrial Law

Relationship to Other Controls

Figure · Matrix

Comparison: A.5.1 to A.5.34

RelationshipWhy It Matters
A.5.1Policies for InformationSecurity policy must
A.6.1ScreeningScreened employees must
A.6.2Terms and ConditionsContractual terms
A.6.3Information SecurityEmployees must know rules
A.5.32Intellectual PropertyIP violations must
A.5.34Privacy and ProtectionPrivacy violations must
Condensed from the table below, which carries the full detail for each cell.

Upstream Controls (Prerequisites)

Control IDRelationshipWhy It Matters
A.5.1Policies for Information SecuritySecurity policy must define violations before they can be disciplined
A.6.1ScreeningScreened employees must be bound by terms that can be enforced
A.6.2Terms and Conditions of EmploymentContractual terms and sanctions enable disciplinary action
A.6.3Information Security AwarenessEmployees must know rules before being disciplined for breaking them
A.5.32Intellectual Property RightsIP violations must be in the disciplinary scope
A.5.34Privacy and Protection of PIIPrivacy violations must be in the disciplinary scope

Downstream Controls (Enabled By)

Control IDRelationshipWhy It Matters
A.6.5Responsibilities after TerminationDisciplinary termination triggers exit procedures
A.6.6Confidentiality AgreementsBreach of NDA is a disciplinary matter
A.6.7Remote WorkingRemote work violations are disciplinary matters
A.6.8Information Security Event ReportingFailure to report incidents is a disciplinary matter
A.8.15LoggingLogs provide evidence for disciplinary investigations
A.8.16Monitoring ActivitiesMonitoring detects violations for disciplinary action

Parallel Controls (Work Alongside)

Control IDRelationshipWhy It Matters
A.5.19Information Security in Supplier RelationshipsVendor violations may be disciplinary for vendor personnel
A.8.30Outsourced DevelopmentDeveloper violations are disciplinary matters
A.8.10Information DeletionUnauthorized deletion is a disciplinary matter
A.8.12Data Leakage PreventionDLP alerts may trigger disciplinary investigations
A.8.24Use of CryptographyCryptography violations are disciplinary matters
A.8.20Networks SecurityNetwork security violations are disciplinary matters

Implementation Roadmap (Week-by-Week)

Phase 1: Discovery & Assessment (Weeks 1-2)

Week 1: Current Disciplinary Process Assessment

  • Deliverable: Current disciplinary process maturity assessment
  • Owner: HR + Legal + CISO
  • Activities:
    1. Review existing disciplinary policy (if any)
    2. Assess current handling of security violations (ad-hoc? formal?)
    3. Interview managers about how they handle security violations
    4. Review past disciplinary cases (security-related) for consistency and fairness
    5. Assess current documentation of disciplinary cases
    6. Identify legal compliance gaps (Industrial Relations Code, standing orders, CBA)
    7. Survey employees on their understanding of disciplinary process
    8. Benchmark against industry practices and ISO 27001 requirements

Week 2: Risk and Gap Analysis

  • Deliverable: Disciplinary process gap analysis report
  • Owner: HR + Legal + CISO + Compliance
  • Activities:
    1. Map security violations to current disciplinary response (or lack thereof)
    2. Identify violations that have gone undisciplined
    3. Assess legal risk of current ad-hoc approach (wrongful termination, labor disputes)
    4. Identify inconsistencies in how different departments handle violations
    5. Map regulatory requirements for disciplinary process
    6. Assess union/CBA implications for disciplinary process
    7. Define target state for disciplinary process maturity
    8. Create gap closure plan

Phase 2: Design & Planning (Weeks 3-4)

Week 3: Disciplinary Policy and Procedure Design

  • Deliverable: Draft Disciplinary Policy + Procedure + Sanctions Matrix
  • Owner: HR + Legal + CISO
  • Activities:
    1. Draft formal Disciplinary Policy for Information Security Violations
    2. Define violation categories (Minor, Moderate, Major, Critical)
    3. Create graduated sanctions matrix for each category
    4. Design investigation procedure (who investigates, evidence standards, timeline)
    5. Design due process procedure (show cause, hearing, defense, decision)
    6. Design appeal mechanism (who hears appeals, timeline, grounds)
    7. Define roles (Enquiry Officer, Presenting Officer, Defence Representative, Appellate Authority)
    8. Create documentation templates (charge sheet, findings, order, appeal)
    9. Review for labor law compliance (Industrial Relations Code, standing orders, CBA)
    10. Create union/CBA alignment strategy (if applicable)

Week 4: Communication and Training Design

  • Deliverable: Communication Plan + Training Materials + Employee FAQ
  • Owner: HR + CISO + Training Team
  • Activities:
    1. Design employee communication strategy (why, what, how, consequences)
    2. Create disciplinary process FAQ for employees
    3. Create manager training on identifying and reporting violations
    4. Create HR training on conducting investigations and inquiries
    5. Create enquiry officer training on conducting fair inquiries
    6. Create employee awareness materials (posters, videos, intranet)
    7. Design case tracking system (HRIS, ticketing, or dedicated tool)
    8. Create metrics and reporting framework

Phase 3: Implementation (Weeks 5-8)

Week 5: Policy Approval and Publication

  • Deliverable: Approved policy published and communicated to all employees
  • Owner: HR + Legal + CISO + Management
  • Activities:
    1. Finalize policy and procedure with Legal review
    2. Obtain management approval (CEO, board if required)
    3. Align with Standing Orders (if applicable, submit for certification)
    4. Communicate policy to all employees (email, town hall, intranet)
    5. Publish policy on employee portal
    6. Add to employee handbook
    7. Create acknowledgment requirement (all employees must acknowledge)
    8. Track acknowledgment completion

Week 6: Training Rollout

  • Deliverable: All managers and HR trained; employees aware
  • Owner: HR + CISO + Training Team
  • Activities:
    1. Train all managers on violation identification and reporting (2-hour session)
    2. Train all HR staff on investigation and inquiry procedures (4-hour session)
    3. Train designated enquiry officers on conducting fair inquiries (1-day session)
    4. Conduct employee awareness sessions (30 minutes, all hands)
    5. Create and share disciplinary process video (5 minutes)
    6. Publish FAQ on intranet
    7. Create quick reference card for managers

Week 7: Case Tracking and Tools Implementation

  • Deliverable: Case tracking system operational; first mock case processed
  • Owner: HR + IT + CISO
  • Activities:
    1. Implement case tracking system (HRIS module, ServiceNow, or spreadsheet)
    2. Create case intake form (violation report, evidence, initial assessment)
    3. Create case workflow (intake → investigation → inquiry → decision → appeal → close)
    4. Configure alerts and escalations (SLA, overdue cases, critical cases)
    5. Create case documentation templates (charge sheet, findings, order)
    6. Process first mock case end-to-end to test workflow
    7. Train case managers on system use

Week 8: Union and CBA Alignment (if applicable)

  • Deliverable: Union agreement or CBA alignment achieved
  • Owner: Legal + HR + Union Representatives
  • Activities:
    1. Present disciplinary process to union representatives
    2. Negotiate security-related disciplinary terms in CBA
    3. Establish joint disciplinary committee (management + union) if required
    4. Align Standing Orders with new disciplinary process
    5. Obtain union sign-off on security violation definitions and sanctions
    6. Create union-specific communication materials
    7. Ensure grievance mechanism integrates with appeal process

Phase 4: Testing & Validation (Weeks 9-10)

Week 9: Process Testing

  • Deliverable: Process validation report with mock cases
  • Owner: HR + Internal Audit + CISO
  • Activities:
    1. Process mock minor violation case (e.g., unreported lost badge)
    2. Process mock moderate violation case (e.g., unauthorized software installation)
    3. Process mock major violation case (e.g., data leakage to wrong party)
    4. Test investigation procedure (evidence collection, witness interviews)
    5. Test due process (show cause, hearing, defense, decision)
    6. Test appeal process (filing, hearing, decision)
    7. Test case tracking system workflow and documentation
    8. Test union/CBA compliance (if applicable)
    9. Verify legal compliance at each step

Week 10: Compliance and Audit Validation

  • Deliverable: Compliance validation report
  • Owner: Legal + Compliance Manager + HR
  • Activities:
    1. Validate policy against Industrial Relations Code 2020 requirements
    2. Validate Standing Orders compliance (if applicable)
    3. Validate CBA compliance (if applicable)
    4. Verify employee acknowledgment completion
    5. Test case record security and confidentiality
    6. Verify DPDP compliance for disciplinary records (personal data)
    7. Prepare compliance evidence package
    8. Conduct internal audit of disciplinary process

Phase 5: Documentation & Certification Prep (Weeks 11-12)

Week 11: Documentation

  • Deliverable: Complete disciplinary process documentation
  • Owner: HR + Compliance Manager
  • Activities:
    1. Document all policies, procedures, and templates
    2. Create illustrative scenarios and examples (anonymized)
    3. Create training materials and videos
    4. Create FAQ and quick reference guides
    5. Create metrics dashboard and reporting templates
    6. Create evidence repository for audits
    7. Document union/CBA agreements (if applicable)

Week 12: Certification Readiness

  • Deliverable: Audit-ready evidence package
  • Owner: CISO + Compliance Manager
  • Activities:
    1. Conduct internal audit of disciplinary process
    2. Prepare evidence for external ISO 27001 auditor
    3. Remediate any gaps found
    4. Conduct management review
    5. Make the programme and its records available for internal and certification audits

Detailed Implementation Guidance

Step-by-Step Implementation

Step 1: Define Security Violation Categories

CategoryDefinitionExamplesTypical Sanctions
MinorUnintentional violation with no security impactClean desk violation, unreported lost badge, minor password policy violation, unlocked screen, failure to attend trainingVerbal warning + retraining; Manager counseling; Improvement plan
ModerateUnintentional or negligent violation with limited impactSharing credentials with colleague, unauthorized software installation, unencrypted USB, unreported minor incident, repeated minor violationsWritten warning + mandatory training; Restricted access; Suspension (1-3 days); Performance plan
MajorSignificant violation causing security impact or intentional circumventionData leakage (no malicious intent), unauthorized access attempt, policy violation causing incident, intentional bypass of security control, repeated moderate violationsFinal written warning; Suspension (3-10 days); Role change; Demotion; Consideration of termination
CriticalIntentional, malicious, or catastrophic violationData theft, sabotage, unauthorized system modification, fraud, espionage, installation of malware, physical security breach, repeated major violationsImmediate suspension; Investigation; Termination (after due process); Legal action; Regulatory reporting; Criminal referral

Simulated phishing: a click in a phishing simulation is a learning event, not a violation. It triggers coaching, never sanctions (see A.6.3). Discipline applies to wilful or concealed breaches and to failing to report. ISO 27002 also expects the disciplinary process to consider whether the person was properly trained.

Step 2: Create Graduated Sanctions Matrix

OffenseFirst ViolationSecond ViolationThird ViolationFourth Violation
MinorVerbal warning + retrainingWritten warning + retrainingWritten warning + restricted accessWritten warning + suspension (within standing-order limits)
ModerateWritten warning + mandatory trainingWritten warning + restricted accessFinal written warning + suspension (within standing-order limits)Final written warning + termination consideration
MajorFinal written warning + suspension (within standing-order limits)Final written warning + suspension + role changeTermination considerationTermination
CriticalImmediate suspension pending inquiry (with subsistence allowance) + investigation; termination if provenN/A (first offense may result in termination)N/AN/A

Weigh the 27002 factors in every case: nature and gravity, intentional or accidental, first or repeat, and whether the person was properly trained. Suspension as a punishment must stay within your certified or model standing orders (the model standing orders cap it at four days at a time); check with Legal.

Note: For critical violations, the process may skip graduated steps. Immediate termination is possible only after due process, not as a knee-jerk reaction. Suspension pending investigation is appropriate.

Step 3: Design Investigation Procedure

  1. Violation Detection: Security monitoring, incident report, audit finding, tip, or manager observation
  2. Initial Assessment: Security team assesses if the incident constitutes a violation and determines category
  3. Case Assignment: HR assigns case to investigator (Enquiry Officer or investigation team)
  4. Evidence Collection: Gather logs, emails, witness statements, device analysis, access records
  5. Employee Notification: Employee informed of alleged violation and invited to respond (show cause)
  6. Employee Response: Employee provides explanation, evidence, and context
  7. Investigation Report: Investigator prepares report with findings, evidence, and recommendation
  8. Sanctions Committee Review: Committee (HR, Legal, CISO, manager) reviews report and recommends sanction
  9. Decision: Sanction determined and documented
  10. Communication: Employee notified of decision in writing with appeal rights
  11. Execution: Sanction implemented (warning, suspension, termination, etc.)
  12. Appeal: Employee may appeal within specified timeframe
  13. Close: Case closed, records maintained, lessons learned documented

Step 4: Design Due Process Procedure (For Major and Critical Violations)

Under Indian labor law, for major and critical violations, a formal domestic inquiry must be conducted before termination:

  1. Charge Sheet: Formal document listing specific charges against the employee with supporting evidence
  2. Show Cause Notice: Employee given 3-7 days to explain why disciplinary action should not be taken
  3. Enquiry Officer Appointment: Neutral officer appointed to conduct inquiry (can be internal or external)
  4. Presenting Officer: Management representative who presents the case
  5. Defence Representative: Employee may be represented by a colleague or union representative
  6. Witness Examination: Management and employee examine witnesses; cross-examination allowed
  7. Employee Defense: Employee presents evidence and defense against charges
  8. Findings: Enquiry officer prepares findings based on evidence and testimony
  9. Order of Punishment: Management issues order based on findings; must be proportionate and reasoned
  10. Appeal: Employee may appeal to appellate authority (higher management)

Note: For minor and moderate violations, a simplified process may be used (manager inquiry, HR review, documented warning) rather than full domestic inquiry. However, for dismissing a "worker" under the Industrial Relations Code 2020 (formerly a "workman" under the ID Act), a full domestic inquiry following natural justice is generally required.

Step 5: Create Documentation Templates

Charge Sheet Template:

Template

Order of Punishment Template:

Template

Step 6: Implement Case Tracking System

Use a case tracking system to manage all disciplinary cases:

Case IDEmployeeViolation CategoryDate ReportedInvestigatorStatusSanctionAppealClosed Date
D-2026-001[Name]Minor2026-01-15[Investigator]ClosedVerbal warningNone2026-01-20
D-2026-002[Name]Moderate2026-02-03[Investigator]Under inquiryPending--
D-2026-003[Name]Major2026-02-20[Investigator]Awaiting decisionPending--

Case Status Values: Reported → Under Investigation → Awaiting Show Cause → Under Inquiry → Awaiting Decision → Sanction Issued → Appeal Filed → Under Appeal → Closed

Step 7: Create Appeal Mechanism

Appeal LevelAuthorityTimelineGrounds
Level 1Manager's Manager or HR HeadWithin 7 daysProcedural error, new evidence, disproportionate sanction, bias
Level 2VP HR or CEOWithin 15 days of Level 1 decisionLegal error, fundamental unfairness, new significant evidence
ExternalLabour Court / Industrial TribunalAs per the Industrial Relations Code 2020Violation of labor law, principles of natural justice, wrongful termination

Step 8: Implement Corrective Action alongside Sanctions

For non-termination cases, always include corrective action:

  • Retraining: Mandatory security training relevant to the violation
  • Mentoring: Pair with security-conscious colleague for guidance
  • Shadowing: Observe security procedures before independent work
  • Access Review: Restricted or supervised access until improvement demonstrated
  • Check-ins: Regular manager check-ins on security behavior
  • Improvement Plan: 30/60/90-day plan with specific security goals
  • Peer Support: Security champion buddy system

Step 9: Create Manager Training

Managers must be trained on:

  • Identifying security violations (what to look for)
  • Reporting violations (how, when, to whom)
  • Supporting investigations (providing evidence, witness statements)
  • Enforcing sanctions fairly and consistently
  • Supporting employee improvement (retraining, mentoring)
  • Avoiding bias and discrimination in enforcement
  • Documenting violations and actions
  • When to escalate to HR and Security

Step 10: Implement Union/CBA Compliance

For unionized organizations:

  • Include security violation definitions in CBA negotiations
  • Establish joint disciplinary committee (management + union)
  • Define union representative rights in disciplinary inquiries
  • Ensure standing orders reflect security disciplinary process
  • Get labor authority certification for updated standing orders
  • Ensure grievance mechanism integrates with appeal process
  • Conduct union training on security risks and business impact
  • Frame security as job protection and worker safety

Step 11: Create Communication Plan

Employees must understand:

  • What the disciplinary process is
  • What behaviors can lead to disciplinary action
  • What the graduated sanctions are
  • What their rights are (defense, appeal, representation)
  • How to report violations (without fear of retaliation)
  • That the process is fair, consistent, and non-discriminatory
  • Examples of violations and consequences (anonymized)

Step 12: Maintain Records Securely

  • Store all disciplinary records in secure, access-controlled system
  • Limit access to HR, Legal, and CISO (need-to-know)
  • Maintain confidentiality of records
  • Retain records for 7 years or employment duration + 7 years
  • Secure disposal after retention period (cryptographic erasure)
  • DPDP compliance for all personal data in disciplinary records
  • Separate disciplinary records from general personnel files (confidential)

Step 13: Implement Metrics and Reporting

  • Track violations by category (minor, moderate, major, critical)
  • Track sanctions applied (warning, suspension, termination)
  • Track repeat violations (recidivism rate)
  • Track investigation timelines (time to resolution)
  • Track appeal rates and outcomes
  • Track training completion for sanctioned employees
  • Track improvement rates (employees who improve after sanctions)
  • Report quarterly to management and board
  • Benchmark against industry data

Step 14: Integrate with Incident Management

  • All security incidents involving employee misconduct should be evaluated for disciplinary action
  • Incident response team should notify HR of potential violations
  • Disciplinary investigation should be separate from incident investigation (but coordinated)
  • Incident findings can be used as evidence in disciplinary inquiry
  • Disciplinary outcome should be recorded in incident register
  • Learn from incidents to improve disciplinary policy

Step 15: Continuous Improvement

  • Annual review of disciplinary policy and sanctions
  • Quarterly metrics review
  • Annual training for managers and enquiry officers
  • Post-incident review of disciplinary process effectiveness
  • Benchmark against industry best practices
  • Update for regulatory changes (labor law, DPDP, industry-specific)
  • Gather feedback from employees and managers on process fairness
  • Learn from appeals and legal challenges to improve process

Tools, Technologies, and Solutions

Complete Tool Comparison

ToolCategoryBest ForPricing modelKey FeaturesIntegration
ServiceNowCase ManagementEnterprise case trackingCommercialCase workflow, SLA, evidence management, reporting, HRIS integrationFull enterprise
BambooHRHRISSMB case trackingCommercialEmployee records, performance, disciplinary notes, reporting100+ integrations
WorkdayHRISEnterprise HR managementCommercialDisciplinary case management, performance, compliance, analyticsFull enterprise
SAP SuccessFactorsHRISEnterprise HRCommercialCase management, performance, employee relations, complianceSAP ecosystem
Oracle HCMHRISEnterprise HRCommercialCase management, performance, legal compliance, globalOracle ecosystem
Zoho PeopleHRISIndian SMBCommercialEmployee records, performance, case notes, basic disciplinary trackingZoho ecosystem
GreytHRHRISIndian SMBCommercialEmployee records, compliance, attendance, basic case trackingIndian compliance
HR AcuityEmployee RelationsDisciplinary investigationCommercialInvestigation management, case tracking, documentation, analyticsHRIS, legal
Case IQInvestigationInvestigations and case managementCommercialInvestigation workflow, evidence, interviews, reporting, analyticsHRIS, legal
ConvercentEthicsEthics and compliance reportingCommercialHotline, case management, investigation, analytics, reportingHRIS, legal
Navex GlobalEthicsEnterprise ethics and complianceCommercialHotline, case management, investigation, policy, trainingEnterprise
EthicsPointHotlineAnonymous reportingCommercialAnonymous hotline, case management, investigation workflowHRIS, legal
Document ManagementRecordsSecure record storageVariesSecure storage, access control, version control, audit trailHRIS, case management
DocuSignE-SignatureCharge sheet, order signingCommercialElectronic signatures, workflow, templates, audit trailHRIS, case management
Adobe SignE-SignatureEnterprise contract signingCommercialE-signatures, workflow, templates, complianceAdobe, HRIS
Microsoft 365ProductivityDocumentation, communicationCommercialWord, Teams, SharePoint, email, secure storageMicrosoft ecosystem
Google WorkspaceProductivityDocumentation, communicationCommercialDocs, Meet, Drive, email, secure storageGoogle ecosystem
SIEMMonitoringEvidence collectionCommercialLog aggregation, evidence collection, incident correlationSecurity tools
DLPMonitoringViolation detectionCommercialData loss detection, policy violation alerts, evidenceSecurity, HRIS
UEBAMonitoringBehavioral evidenceCommercialUser behavior analytics, anomaly detection, evidenceSecurity, SIEM
eDiscoveryLegalEvidence preservationCommercialLegal hold, evidence collection, chain of custodyLegal, case management
VaultLegalLegal hold and complianceCommercialEmail hold, evidence collection, legal complianceGoogle Workspace
Microsoft PurviewComplianceeDiscovery and complianceCommercialeDiscovery, legal hold, compliance, data governanceMicrosoft 365

Recommendations by Organization Size

SizeCase ManagementHRISInvestigationHotlineEvidence
Startup (<50)Spreadsheet + BambooHRBambooHR or ZohoManualEmail/phoneCloud storage
SMB (50-500)BambooHR + HR AcuityBambooHR or GreytHRHR AcuityEthicsPointSharePoint/Drive
Mid-market (500-5000)ServiceNow or Case IQWorkday or SAPCase IQ + HR AcuityConvercent or EthicsPointServiceNow + eDiscovery
Enterprise (5000+)ServiceNow + NavexWorkday or OracleCase IQ + NavexNavex GlobalServiceNow + eDiscovery + legal hold

Policy and Procedure Templates

Disciplinary Policy for Information Security (Key Sections)

Template

Disciplinary Procedure

Template


Risk Assessment and Treatment

Key Risks Addressed by This Control

Risk IDRisk DescriptionLikelihoodImpactRisk LevelTreatment
R-001Employee violates security policy without consequenceMediumHighMediumMitigate, Formal disciplinary process, consistent enforcement
R-002Wrongful termination lawsuit due to lack of due processMediumHighMediumMitigate, Legal-compliant procedure, documentation, appeal
R-003Disciplinary action applied inconsistently (discrimination)LowHighMediumMitigate, Structured procedure, committee review, bias training
R-004Union resistance to disciplinary actionMediumHighMediumMitigate, CBA alignment, joint committee, fair process
R-005Disciplinary records not maintained securelyLowHighMediumMitigate, Secure storage, access controls, DPDP compliance
R-006Employee fear of reporting violations (no whistleblower protection)MediumMediumLowMitigate, Non-retaliation policy, anonymous reporting, protection
R-007Investigation bias or unfairnessMediumMediumLowMitigate, Neutral enquiry officer, representation, appeal
R-008Disciplinary process delays create legal riskMediumMediumLowMitigate, SLA, automated tracking, escalation
R-009Sanctions too lenient, repeat violationsMediumMediumLowMitigate, Graduated sanctions, recidivism tracking, escalation
R-010Sanctions too severe, morale and retention impactMediumMediumLowMitigate, Proportionate sanctions, corrective action, manager training

Audit and Compliance Checklist

Audit Questions (25 Questions)

#Audit QuestionExpected EvidenceRed Flags
1Is there a formal disciplinary policy for security violations?Approved policyNo policy, ad-hoc approach
2Are violation categories defined?Policy document with categoriesNo categories, all violations treated same
3Are graduated sanctions defined?Sanctions matrixNo graduated sanctions, arbitrary decisions
4Is the disciplinary process communicated to employees?Communication records, acknowledgmentNo communication, employees unaware
5Is there an investigation procedure?Investigation procedureNo investigation, immediate action
6Is there a due process for major/critical violations?Due process procedureNo due process, summary action
7Is there an appeal mechanism?Appeal procedureNo appeal, decisions final
8Are disciplinary cases documented?Case records, tracking systemNo records, undocumented decisions
9Is there a case tracking system?Tracking system, reportsNo tracking, cases lost
10Are sanctions applied consistently?Case records showing consistencyInconsistent sanctions for same violations
11Are minor violations addressed?Minor case recordsOnly major violations addressed
12Is there a corrective action component?Improvement plans, retraining recordsPunitive only, no corrective action
13Are disciplinary records secure?Access controls, encryptionOpen access, no security
14Is there union/CBA compliance?CBA terms, union agreementNo union alignment, labor disputes
15Are enquiry officers trained?Training recordsUntrained enquiry officers
16Are managers trained on identifying violations?Training recordsNo manager training
17Is there a non-retaliation policy?Non-retaliation policyNo protection for reporters
18Are termination decisions legally reviewed?Legal review recordsNo legal review, wrongful termination risk
19Are investigation timelines defined?Timeline SLANo timelines, indefinite delays
20Are disciplinary metrics tracked?Metrics dashboardNo metrics, no improvement
21Is the process reviewed annually?Management review minutesNo review, stale process
22Are standing orders updated?Standing orders documentOutdated standing orders
23Are charge sheets and orders properly drafted?Sample charge sheets and ordersPoorly drafted, legally vulnerable
24Is there a hotline for reporting violations?Hotline recordsNo reporting mechanism
25Are lessons learned from cases?Lessons learned documentationNo learning, repeat violations

Metrics and KPIs

Figure · Measures

The measures that show A.6.4 is working

  • Self-Reported IncidentsRising trendMonthly
  • Case Resolution Time<15 daysMonthly
  • Sanction Consistency Score>90%Quarterly
  • Repeat Violation Rate<15%Quarterly
  • Appeal Rate<10%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Metrics Dashboard

KPIFormulaTargetFrequency
Self-Reported IncidentsNumber of incidents reported by staff themselves (rising early on is healthy)Rising trendMonthly
Case Resolution TimeAverage days from report to close<15 days (minor), <30 days (moderate), <60 days (major/critical)Monthly
Sanction Consistency ScoreConsistency of sanctions for same violation types>90%Quarterly
Repeat Violation Rate(Employees with repeat violations / Total sanctioned employees) × 100<15%Quarterly
Appeal Rate(Appeals filed / Total sanctions) × 100<10%Monthly
Appeal Outcomes ReviewAppeal outcomes reviewed for patterns (inconsistency, weak investigations)Reviewed each quarterQuarterly
Investigation SLA Compliance(Cases resolved within SLA / Total cases) × 100>95%Monthly
Minor Violation Addressed Rate(Minor violations with action / Total minor violations) × 100100%Monthly
Corrective Action Completion(Corrective actions completed / Assigned) × 100100%Monthly
Training Completion (Sanctioned)(Sanctioned employees completing retraining / Total) × 100100%Monthly
Case Documentation Completeness(Cases with complete documentation / Total) × 100100%Monthly
Union Dispute Rate(Union disputes / Total cases in union environment) × 100<5%Quarterly
Legal Challenge Rate(Legal challenges / Total terminations) × 100<5%Quarterly
Case Record SecuritySecurity audit score for case records>95%Quarterly
Employee Understanding(Employees who understand disciplinary process / Total) × 100>90%Annual
Manager Training Completion(Trained managers / Total managers) × 100100%Annual
Whistleblower Report RateAnonymous reports of violationsTrending upMonthly
Improvement Rate(Employees improving after sanctions / Total sanctioned) × 100>80%Quarterly
Case BacklogCases open beyond SLA<5%Monthly

Common Pitfalls and How to Avoid Them

#PitfallWhy It HappensHow to Avoid
1No formal disciplinary processSmall company, informal cultureCreate simple formal procedure even for small teams
2Inconsistent sanctionsDifferent managers handle violations differentlySanctions matrix, committee review, training, documentation
3No due process for terminationUrgency, assumption of guiltFollow Industrial Relations Code requirements and natural justice; charge sheet, inquiry, reasoned order
4Investigation biasPreconceived notions, manager influenceNeutral enquiry officer, evidence-based, representation
5No appeal mechanismEfficiency, assumption of fairnessCreate appeal process; appellate authority; documented rationale
6Disciplinary records not secureConvenience, lack of awarenessSecure storage, access controls, DPDP compliance
7Ignoring minor violationsFocus on major issues onlyAddress all violations; minor violations escalate if unchecked
8Punitive only, no corrective actionPunishment mentalityInclude retraining, mentoring, improvement plans
9No union/CBA alignmentUnilateral management approachEngage union early; include in CBA; joint committee
10Retaliation against reportersManager bias, loyalty conflictsNon-retaliation policy, anonymous reporting, whistleblower protection
11Poor documentationRushing, informalityTemplates, checklist, case tracking, mandatory documentation
12No manager trainingAssumption that managers knowMandatory training on violation identification and handling
13Delays in investigationWorkload, complexitySLA, dedicated resources, automated tracking, escalation
14Sanctions too severe for minor first offenseOverreaction, fearGraduated sanctions, proportionality, context consideration
15No learning from casesCase-by-case approachAggregate analysis, trend identification, policy improvement
16Discrimination in enforcementUnconscious bias, favoritismStructured procedure, diverse committee, bias training, metrics
17No employee communicationAssumption that policy is knownTown halls, FAQ, video, intranet, acknowledgment
18Hotline not promotedFear of misusePromote hotline, protect reporters, celebrate reporting culture
19Ignoring mental health in sanctionsFocus on behavior onlyConsider mental health, offer support, EAP referral
20No integration with incident managementSiloed security and HRSecurity incidents trigger HR review; coordinated investigation

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian SaaS Company, TechFlow Analytics

Company Profile:

  • Size: 180 employees
  • Industry: B2B SaaS, Data Analytics Platform
  • Location: Gurgaon, India
  • Customers: 200 enterprise clients globally
  • Regulatory Scope: DPDP Act 2023, SOC 2 Type II, ISO 27001, GDPR

Challenge: TechFlow had no formal disciplinary process for security violations:

  • When a developer accidentally committed AWS credentials to GitHub, the CTO "had a chat" with him but no formal action
  • When a sales rep emailed customer list to personal Gmail, no action was taken because "sales needs data"
  • When a QA engineer repeatedly ignored mandatory security training, the manager just "reminded" him with no documentation
  • When a developer intentionally bypassed code review for a critical fix, no investigation was conducted
  • No employee understood what would happen if they violated security policies
  • Managers were afraid to take action because they didn't know the process
  • A developer who was "warned" 3 times for credential leaks finally caused a breach exposing 50,000 customer records
  • The breach led to remediation costs, a regulatory inquiry and customer churn
  • The developer could not be terminated quickly because there was no formal procedure or documentation
  • The company faced a wrongful termination lawsuit when they eventually terminated the developer without due process

Solution:

  1. Week 1-2: Emergency Policy Creation

    • Engaged an external security consultant for emergency disciplinary process design
    • Created formal Disciplinary Policy for Security Violations
    • Defined 4 violation categories with specific examples
    • Created graduated sanctions matrix
    • Created investigation and due process procedure
    • Created documentation templates (charge sheet, findings, order)
    • Legal review for labor law compliance
    • Created anonymous hotline for reporting violations
  2. Week 3-4: Manager Training and Communication

    • Trained all 25 managers on identifying and reporting violations (2-hour session)
    • Created manager quick reference card for violation handling
    • Communicated policy to all employees (town hall, email, intranet)
    • Created employee FAQ (20 questions)
    • Required 100% employee acknowledgment
    • Created anonymous reporting hotline (EthicsPoint)
  3. Week 5-6: Case Tracking and Implementation

    • Implemented case tracking in BambooHR (HRIS module)
    • Created case intake workflow (violation → investigation → decision → close)
    • Closed the 12 outstanding cases under the rules in force when the conduct happened
    • Created enquiry officer roster (5 trained HR and security staff)
    • First case processed: minor violation (clean desk) → verbal warning + retraining
    • Second case: moderate (unauthorized software) → written warning + retraining + restricted access
  4. Week 7-8: Integration and Culture Change

    • Integrated disciplinary process with incident management (security incidents auto-flag HR)
    • Created security champion program (employees recognized for reporting violations)
    • Created monthly security culture report (violations, sanctions, improvements)
    • First major case: developer bypassed security review → formal inquiry → final written warning + 5-day suspension + mandatory security training
    • Employee accepted sanction without appeal; completed retraining successfully
  5. Week 9-12: Metrics and Continuous Improvement

    • Created quarterly metrics review with management
    • 100% employee acknowledgment achieved
    • 25 managers trained and certified
    • 5 enquiry officers trained
    • Zero appeals in first 10 cases (fairness perceived)
    • Created lessons learned documentation from each case
    • Policy updated based on first-quarter experience

Results:

  • Security violations: 45% reduction in 6 months (deterrence effect)
  • Repeat violations: 15% recidivism rate (down from 60% before formal process)
  • Employee understanding: 91% of employees understand disciplinary process (survey)
  • Reporting: 40% increase in violation reporting (hotline + culture change)
  • Case resolution: Average 12 days for minor, 18 days for moderate (within SLA)
  • Legal risk: Zero legal challenges; zero wrongful termination risk
  • Breach prevention: Zero breaches in 6 months (vs. 3 in previous 6 months)
  • Culture: Security compliance became part of organizational culture

Illustrative Scenario 2: Large Manufacturing, Indian Auto Components Ltd. (IACL)

Company Profile:

  • Size: 4,500 employees, 3,800 unionized workers
  • Industry: Automotive Components Manufacturing
  • Location: Chennai, India
  • Customers: 15 major automotive OEMs
  • Regulatory Scope: DPDP Act 2023, OSH Code 2020, ISO 27001, IATF 16949, ISO 14001
  • Union: Strong trade union; CBA renewal every 3 years

Challenge: IACL had a strong union and outdated disciplinary framework:

  • Standing Orders from 1995 had no information security provisions
  • CBA had no security-related disciplinary terms
  • Security violations were handled by "suspending the worker for 3 days" (arbitrary, no process)
  • Workers did not understand what constituted a security violation
  • A union leader was suspended for 10 days for "computer misuse" without charge sheet or inquiry
  • Union filed unfair labor practice claim; labour court ordered reinstatement with back wages
  • OT/ICS systems were repeatedly accessed by unauthorized personnel; no disciplinary action because "workers need to do their job"
  • A worker stole proprietary CAD designs from shared drive; no formal procedure to investigate
  • No formal inquiry for any security violation in 10 years
  • Management was afraid to take action due to union power and labor court risk
  • ISO 27001 certification was at risk because A.6.4 was not implementable in union environment

Solution:

  1. Months 1-2: Union Engagement and Partnership

    • Engaged an external security consultant for union-compliant disciplinary process design
    • Established Joint Security-Disciplinary Committee (3 management + 3 union representatives)
    • Conducted 8 workshops with union leaders on security risks in manufacturing
    • Presented data: 1 OT security incident could halt production, affecting 4,500 jobs
    • Shared industry examples: competitors with security breaches lost OEM contracts
    • Union agreed to security disciplinary terms if:
      • Security training is paid work time
      • Security equipment is provided by company
      • No surveillance of personal activity
      • Full due process (charge sheet, inquiry, representation)
      • Union representative on every enquiry committee
  2. Months 3-4: Standing Orders and CBA Update

    • Updated Standing Orders with information security misconduct provisions
    • Added 12 security misconduct categories (unauthorized access, data theft, sabotage, credential sharing, etc.)
    • Defined graduated sanctions: oral warning → written warning → suspension → dismissal
    • Included due process: charge sheet, show cause, enquiry, order, appeal
    • Standing Orders submitted to Labor Commissioner for certification
    • CBA updated with security terms in appendix (jointly signed by management and union)
    • Created joint enquiry committee for security violations (3 management + 3 union)
  3. Months 5-6: Training and Communication

    • Security training made mandatory and paid (union requirement)
    • Created plant-floor security awareness in Tamil and Hindi
    • Created visual posters on shop floor: "Security Misconduct = Production Risk"
    • Trained 50 supervisors on violation identification and reporting
    • Trained 20 enquiry committee members on conducting fair inquiries
    • Created worker-friendly FAQ on security and discipline
  4. Months 7-9: Implementation and First Cases

    • First case: Worker accessed OT system without authorization (minor) → oral warning + safety briefing
    • Second case: Supervisor shared OT password with junior worker (moderate) → written warning + 2-day suspension + retraining
    • Third case: Worker copied CAD files to USB (major) → formal enquiry → final written warning + 5-day suspension + access restriction
    • Union supported all decisions because process was fair and agreed
    • Zero union disputes in first 9 cases
  5. Months 10-12: Continuous Improvement and Certification

    • Quarterly joint committee review of all cases
    • Worker suggestion scheme for security improvements (5 suggestions implemented)
    • Created case tracking system (shared access for management and union)
    • Annual review of Standing Orders security provisions
    • ISO 27001 audit raised no findings on A.6.4
    • Passed IATF 16949 audit with zero findings on personnel security

Results:

  • Union relations: Security disciplinary terms agreed with the union
  • Security incidents: 55% reduction in security violations in 12 months
  • OT security: Zero unauthorized OT access incidents in 6 months
  • Labor disputes: Zero labor disputes related to security discipline
  • IP protection: No IP theft incidents after formal process implementation
  • Production impact: Zero production stoppages due to security incidents
  • OEM contracts: Won 2 new OEM contracts citing security program
  • Cost: program cost vs. potential labor court costs ( per case) + production loss + contract loss
  • Industry recognition: Featured in CII manufacturing security best practices

Multi-Framework Mapping

The references below genuinely overlap with A.6.4. Use them when one set of evidence must satisfy several frameworks.

FrameworkReferenceHow it relates
NIST SP 800-53 Rev 5PS-8 Personnel sanctionsA formal sanctions process for people who break security policies
SOC 2 (2017 TSC)CC1.5The organisation holds individuals accountable for their responsibilities
COBIT 2019APO07 Managed human resourcesPerformance and conduct management
DPDP Act 2023s.7(i) employment purposes; s.8(5) safeguardsInvestigation and disciplinary records are personal data and must be protected
Indian labour lawIndustrial Relations Code 2020 (standing orders, misconduct, domestic inquiry); Code on Wages 2019 s.18 (deductions)The process must follow natural justice and labour law

Regulatory and Industry Context

India Regulatory Framework

RegulationDisciplinary Process RequirementConsequence
Industrial Relations Code 2020 (in force from 21 Nov 2025; replaced the Industrial Disputes Act 1947 and the Industrial Employment (Standing Orders) Act 1946)Standing orders (certified, or the model standing orders) set misconduct, suspension and the disciplinary procedure for covered establishments; dismissal must follow due processUnfair dismissal claims: reinstatement, back wages
Code on Wages 2019 (replaced the Payment of Wages Act 1936)Deductions from wages only on permitted grounds and within limits (s.18), after an opportunity to show causePenalties; recovery orders
State Shops and Establishments ActsConditions of service for shops and offices; some states set notice and termination rulesPenalties under the state Act
Companies Act 2013, s.177Listed and certain other companies must run a vigil (whistle-blower) mechanism with protection against victimisation, reporting to the Audit CommitteePenalties for non-compliance
DPDP Act 2023Disciplinary and investigation records are personal data: process them for employment purposes (s.7(i)), protect them (s.8(5)) and erase them when no longer needed (s.8(7))Up to ₹250 crore for failing to take reasonable safeguards
Principles of natural justice (case law)Notice of charges, a fair hearing, an unbiased decision-maker and a reasoned decisionOrders set aside if not followed

International Regulations

RegulationDisciplinary Process Requirement
GDPR (EU)Article 32, security measures including personnel accountability; Article 5, accountability principle
HIPAA (US)§164.308(a)(1)(ii)(C), Sanction policy
SOX (US)Internal controls including personnel accountability and disciplinary procedures
UK Employment Rights Act 1996Fair dismissal requires reason and procedure
EU Whistleblower DirectiveProtection for employees reporting violations; anti-retaliation
ILO ConventionWorker rights and fair treatment in disciplinary procedures

Sector-Specific Requirements

SectorDisciplinary-Specific Requirements
BFSIRBI expects staff accountability for fraud and security lapses; SEBI regulations for dealers and intermediaries' staff; vigil mechanism (Companies Act s.177)
HealthcareClinical staff discipline for patient-data misuse (DPDP Act); NABH standards where accredited
TelecomSecurity clearance revocation; subscriber data misuse; lawful interception misuse
ManufacturingStanding orders under the Industrial Relations Code; union agreements; OT operator accountability
GovernmentService and conduct rules; CVC guidelines; Official Secrets Act prosecution where relevant

Roles and Responsibilities (RACI)

ActivityAccountableResponsibleConsultedInformed
Disciplinary PolicyHR HeadHRLegal, CISOBoard
Violation InvestigationHR HeadSecurity Team (fact-finding)Manager, LegalEmployee
Case ManagementHRHR ManagerCISO, LegalManagement
Enquiry OfficerHREnquiry OfficerLegal, CISOEmployee, Management
Sanctions CommitteeDisciplinary authority (per standing orders / delegation of powers)HR HeadLegal, CISO (as adviser)Board
Sanctions DecisionDisciplinary authority (per standing orders / delegation of powers)HR HeadLegal, CISO (as adviser, not decision-maker)Employee, Manager
Appeal AuthorityCEOVP HRLegalEmployee, Board
Corrective ActionCISOTraining TeamHR, ManagerEmployee
Union LiaisonLegalHR HeadCISOUnion, Board
Standing Orders UpdateLegalHRCISOLabor Commissioner
Case TrackingHRHR AdminCISOManagement
Record ManagementHRHR AdminCISOCompliance
Manager TrainingCISOTraining TeamHRAll Managers
Employee CommunicationHRHR ManagerCISOAll Employees
Metrics and ReportingCISOHR AnalystComplianceBoard
Audit and ComplianceInternal AuditHR, CISOLegalBoard
Hotline ManagementCISOSecurity TeamHRManagement
Whistleblower ProtectionAudit Committee (vigil mechanism, Companies Act s.177) or Ethics functionLegalHRBoard
Policy ReviewCISOHR HeadLegalBoard
Incident-Disciplinary LinkCISOSecurity TeamHRManagement

Documentation and Evidence Requirements

Required Documents

DocumentOwnerRetention PeriodFormat
Disciplinary PolicyCISO7 yearsPDF + Word
Disciplinary ProcedureHR7 yearsPDF + Word
Violation CategoriesCISO7 yearsDocument
Sanctions MatrixCISO7 yearsDocument
Charge Sheet TemplatesHR7 yearsDocument templates
Enquiry Officer AppointmentHRPer caseAppointment letter
Investigation ReportsCISO7 yearsReports
Enquiry ReportsHR7 yearsReports
Findings and OrdersHR7 yearsOrders
Appeal RecordsLegal7 yearsCase files
Case Tracking RecordsHR7 yearsSystem records
Employee AcknowledgmentHR7 yearsSigned forms
Manager Training RecordsHR5 yearsLMS records
Enquiry Officer TrainingHR5 yearsTraining records
Standing OrdersLegal7 yearsCertified document
CBA Security TermsLegalDuration of CBA + 7 yearsAgreement
Union Negotiation RecordsLegal7 yearsMeeting minutes
Hotline ReportsCISO3 yearsSystem records
Metrics and ReportsHR3 yearsDashboard / reports
Audit EvidenceInternal Audit5 yearsAudit reports
Lessons LearnedCISO3 yearsDocumentation
Corrective Action PlansHR3 yearsImprovement plans

Continuous Improvement

Figure · Tiers

Maturity levels for disciplinary process

Maturity levels for ISO 27001 A.6.4, disciplinary process, from most to least mature: Optimizing, fair, consistent and learning-oriented; Quantitatively Managed, consistent enforcement; Defined, formal disciplinary process; Managed, basic disciplinary policy; Initial, ad-hoc disciplinary action.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model (Level 1-5)

LevelNameDescription
1InitialAd-hoc disciplinary action; no formal process; no records; inconsistent
2ManagedBasic disciplinary policy; informal enforcement; paper records; some consistency
3DefinedFormal disciplinary process; graduated sanctions; due process; appeal mechanism; case tracking; union compliance; documentation
4Quantitatively ManagedConsistent enforcement; automated case tracking; metrics-driven; manager training; performance integration; corrective action
5OptimizingFair, consistent and learning-oriented; outcomes feed training and control design; good behaviour recognised; continuous improvement

Improvement Cycle

  • Plan: Annual review of disciplinary policy; quarterly metrics; industry benchmarking; regulatory updates; union feedback
  • Do: Deploy new tools; update sanctions; train managers; enhance investigation; improve documentation; corrective action innovation
  • Check: Measure fairness; audit consistency; benchmark; gather feedback; review appeals; analyze trends
  • Act: Standardize; communicate; update procedures; report to management; share best practices; union collaboration
  • AI Investigation Support: AI analyzing logs and evidence for investigation insights
  • Insider-risk monitoring: detecting risky activity for investigation (never pre-emptive discipline: action must follow a verified violation)
  • Behavioral Forensics: Analyzing behavior patterns to detect insider threat risk
  • Digital Case Management: End-to-end digital case management with blockchain evidence integrity
  • Automated Due Process: Workflow automation for charge sheet, inquiry, and order generation
  • Real-Time Monitoring: Continuous monitoring triggering automated case creation
  • Anonymous Reporting AI: AI-powered anonymous hotline with natural language processing
  • Union-Tech Collaboration: Digital platforms for joint management-union case review

FAQ

Frequently Asked Questions (20 Questions)

Q1: Is a formal disciplinary process required for ISO 27001 certification? A: Not automatically. No Annex A control is mandatory. Under clause 6.1.3 you choose the controls your risk assessment calls for, then record A.6.4 in your Statement of Applicability as included (and how) or excluded (and why). Most organisations with employees include it, often by linking information security breaches to their existing HR disciplinary procedure. If you include it, auditors will look for a documented, communicated process and evidence that it is applied fairly.

Q2: Can we terminate an employee immediately for a security breach? A: In India, immediate termination without due process is legally risky, especially for "workers" under the Industrial Relations Code 2020. For gross misconduct, you can suspend immediately pending inquiry, but termination requires a formal inquiry and reasoned order. Consult Legal.

Q3: What is the difference between a minor and major violation? A: Minor: unintentional, no impact (e.g., unlocked screen). Major: significant impact or intentional circumvention (e.g., data leakage, unauthorized access). The distinction determines the investigation depth and sanction severity.

Q4: Do we need a domestic inquiry for every violation? A: No. Minor and moderate violations can be handled through manager inquiry and HR review. Major and critical violations (especially those leading to termination) require a formal domestic inquiry under Indian labor law.

Q5: Can a manager issue a warning without HR involvement? A: For minor verbal warnings, yes, but it should be documented. For written warnings and above, HR should be involved to ensure consistency and legal compliance.

Q6: What is a show cause notice and when is it required? A: A show cause notice is a written document requiring the employee to explain why disciplinary action should not be taken. It is required for moderate and above violations, and mandatory before termination.

Q7: How do we handle a unionized workforce? A: Include security disciplinary terms in the CBA. Establish a joint committee. Ensure union representation in inquiries. Get standing orders certified. Frame security as job protection.

Q8: What is the role of CISO in disciplinary process? A: CISO defines security violations, assesses severity, provides technical evidence, recommends sanctions, and participates in the sanctions committee. CISO does not unilaterally terminate employees.

Q9: Can we discipline an employee for a mistake (not intentional)? A: Yes, if the mistake caused harm or violated a clear policy. Negligence can be a disciplinary matter. However, sanctions should be lighter than for intentional violations. Focus on corrective action.

Q10: What if an employee refuses to attend the inquiry? A: Proceed with the inquiry after due notice. The enquiry officer can make an ex-parte decision based on available evidence. However, ensure the employee was properly notified and given adequate opportunity.

Q11: How do we protect employees from retaliation for reporting violations? A: Create a non-retaliation policy. Protect anonymous reporters. Investigate retaliation claims. Discipline retaliators. Celebrate reporting culture.

Q12: Can we use security monitoring as evidence in disciplinary inquiry? A: Yes, but the evidence must be reliable, relevant, and obtained legally. Monitoring must comply with DPDP Act 2023 and labor law. Employees should be informed of monitoring. Evidence must be preserved with chain of custody.

Q13: What is the maximum suspension period? A: Suspension pending inquiry should not be indefinite and carries a subsistence allowance. Suspension as a punishment must stay within your certified or model standing orders (the model standing orders cap it at four days at a time). Prolonged suspension may be challenged in labor courts. Consult Legal.

Q14: Do contractors have the same disciplinary rights? A: Contractors are not employees under labor law, so Industrial Relations Code protections may not apply to them directly. However, their contracts should include disciplinary terms. The contractor's employer may also take action. Contractual terms govern.

Q15: How do we handle a security violation discovered after the employee has left? A: If the violation is discovered post-employment, legal action may still be possible if the contract has post-employment obligations (NDA, IP assignment). Criminal action is possible for theft, sabotage, or fraud. Consult Legal.

Q16: What is the role of HR in disciplinary process? A: HR manages the disciplinary process: case management, investigation coordination, due process, documentation, records, legal compliance, union liaison, and employee communication. HR ensures fairness and legal compliance.

Q17: Can we reduce salary as a disciplinary sanction? A: Under the Code on Wages 2019 (s.18), deductions from wages are allowed only on listed grounds and within limits, and fines are restricted. Wages due on exit must be paid within two working days (s.17(2)). Consult Legal before imposing financial penalties.

Q18: How do we ensure disciplinary process is not discriminatory? A: Use structured procedure, sanctions matrix, committee review, diverse decision-makers, bias training, metrics analysis, and regular audits. Document rationale for all decisions.

Q19: What is the difference between a disciplinary process and a grievance process? A: Disciplinary process: employer takes action against employee for violation. Grievance process: employee raises complaint against employer or situation. They are different but related. Employees should be able to grieve disciplinary decisions.

Q20: What will an ISO 27001 auditor look for in A.6.4? A: The auditor will verify: (1) formal disciplinary policy exists, (2) process is communicated to employees, (3) violation categories are defined, (4) sanctions are graduated, (5) cases are documented, (6) process is applied consistently, (7) there is evidence of use, (8) appeal mechanism exists, and (9) legal compliance is maintained.


References and Further Reading

ISO Standards

  • ISO 27001:2022: Information Security Management Systems
  • ISO 27002:2022: Information Security Controls
  • ISO/IEC 27701:2025: Privacy information management systems

Indian Law

  • Industrial Relations Code 2020 (standing orders; replaced the Industrial Employment (Standing Orders) Act 1946)
  • Industrial Relations Code 2020 (from 21 Nov 2025 replaced the Industrial Disputes Act 1947 and the Industrial Employment (Standing Orders) Act 1946)
  • OSH Code 2020 (replaced the Factories Act 1948)
  • Shops and Establishments Act (state-specific)
  • OSH Code 2020 (replaced the Contract Labour Act 1970)
  • Code on Wages 2019: Section 18 (permitted deductions; replaced the Payment of Wages Act 1936)
  • Code on Wages 2019 (replaced the Minimum Wages Act 1948)
  • Companies Act 2013
  • DPDP Act 2023
  • IT Act 2000
  • POSH Act 2013
  • Official Secrets Act 1923

International

  • GDPR (EU): Articles 5, 32, 28
  • HIPAA (US): §164.308(a)(3)**, Workforce security
  • SOX (US): Internal controls
  • UK Employment Rights Act 1996: Fair dismissal
  • EU Whistleblower Directive
  • ILO Convention: Worker rights and fair treatment

Industry

  • NASSCOM: IT industry employment practices
  • ISACA: Security and governance guidance
  • CII: Industrial employment and security practices
  • FICCI: Business and employment law
  • Labour Law Journals: Indian labour court judgments

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.