|
controlPS-8
Personnel Sanctions (PS-8)
Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and Notify [organization-defined] within [organization-defined] when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction.
Security Baselines
LOWMODERATEHIGH
personnel-securityscreeningtermination
Why These Connect
Maps To2
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports43
These related controls work together — a change to one may affect the others.
Related Controls(22)
AC-1Policy and Procedures (AC-1)
LMH
AT-1Policy and Procedures (AT-1)LMH
AU-1Policy and Procedures (AU-1)LMH
CA-1Policy and Procedures (CA-1)LMH
CM-1Policy and Procedures (CM-1)LMH
CP-1Policy and Procedures (CP-1)LMH
IA-1Policy and Procedures (IA-1)LMH
IR-1Policy and Procedures (IR-1)LMH
MA-1Policy and Procedures (MA-1)LMH
MP-1Policy and Procedures (MP-1)LMH
PE-1Policy and Procedures (PE-1)LMH
PL-1Policy and Procedures (PL-1)LMH
PL-4Rules of Behavior (PL-4)LMH
PM-12Insider Threat Program (PM-12)PS-1Policy and Procedures (PS-1)LMH
PS-6Access Agreements (PS-6)LMH
PT-1Policy and Procedures (PT-1)RA-1Policy and Procedures (RA-1)LMH
SA-1Policy and Procedures (SA-1)LMH
SC-1Policy and Procedures (SC-1)LMH
SI-1Policy and Procedures (SI-1)LMH
SR-1Policy and Procedures (SR-1)LMH
Cross-Framework Mappings(2)
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined personnel or roles
Assignmentorganization-defined time period