Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.6.4 Disciplinary Process

Control Objective

A disciplinary process shall be formalised and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.

Policy Statement

anDREa enforces accountability across its workforce through a formalized, transparent disciplinary process. This framework governs the response to deliberate, negligent, or accidental information security policy violations, ensuring that corrective and punitive actions are applied fairly and proportionally to the severity of the infraction.

Due to the sensitive legal, HR, and compliance frameworks required to execute disciplinary actions under local labor laws and international standards, this control is fully operationalized within its own dedicated document.


Reference Document

For the classification of policy infractions (e.g., minor negligence vs. willful misconduct), escalation pathways, right-to-appeal procedures, and contractual enforcement mechanisms, please refer directly to the primary document: