FedRAMP Controls / PS

PS-8 Personnel Sanctions

Family PS
Baselines moderate
Mapped KSIs 1

Control statement

a. Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and
    b. Notify {{ insert: param, ps-08_odp.01 }} within {{ insert: param, ps-08_odp.02 }} when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-06Suspicious Activity
Automatically disable or otherwise secure accounts with privileged access in response to suspicious activity
Identity and Access Management