A.6.4 Disciplinary Process
Control Objective
A disciplinary process shall be formalised and communicated to take actions against personnel and other relevant interested parties who have committed an information security policy violation.
Policy Statement
anDREa enforces accountability across its workforce through a formalized, transparent disciplinary process. This framework governs the response to deliberate, negligent, or accidental information security policy violations, ensuring that corrective and punitive actions are applied fairly and proportionally to the severity of the infraction.
Due to the sensitive legal, HR, and compliance frameworks required to execute disciplinary actions under local labor laws and international standards, this control is fully operationalized within its own dedicated document.
Reference Document
For the classification of policy infractions (e.g., minor negligence vs. willful misconduct), escalation pathways, right-to-appeal procedures, and contractual enforcement mechanisms, please refer directly to the primary document: