|
controlPS-8

Personnel Sanctions (PS-8)

Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and Notify [organization-defined] within [organization-defined] when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction.

Security Baselines

LOWMODERATEHIGH
personnel-securityscreeningtermination

Why These Connect

Maps To2

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports43

These related controls work together — a change to one may affect the others.

Cross-Framework Mappings(2)

ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5

Organization-Defined Parameters(2)

Assignmentorganization-defined personnel or roles
Assignmentorganization-defined time period