Personnel Sanctions PS-8
Personnel Security · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PS-8 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Personnel Security family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PS-8 (Personnel Sanctions) sets up a formal, written process for handling people who fail to follow your information security and privacy rules — and for telling the right people when that process starts. It is a Personnel Security control that sits in the Low baseline. The point is not punishment for its own sake; it is fairness and consistency. Everyone knows the rules, everyone knows the same consequences apply, and a sanction is decided ahead of time rather than invented on the spot. For a shared lab server, this is what gives your access and change rules teeth.
What good looks like
- Have a written sanctions process that applies to everyone the same way — the consequence for breaking a rule is defined in advance, not decided in the moment.
- Tie sanctions to specific, documented rules (your security and privacy policies), so a person can see beforehand what is expected and what breaking it costs.
- Run the process through the right owners — typically Human Resources (HR) and management — not the system administrator acting alone.
- When a sanction is started, notify the defined people within a defined time, naming the individual and the reason — that notification step is the part PS-8 specifically calls out.
- Keep it proportional and consistent — the same violation draws the same range of response regardless of who did it.
Framework mapping
How to move it toward Implemented
- Write a one-page sanctions procedure: which rules it covers, who reviews a suspected violation, who decides the consequence, and the range of consequences (for example, warning, retraining, access removal, termination).
- Name the notification step explicitly — who is told when a sanction starts (for example, Human Resources and the system owner) and within what time window — because PS-8 requires the notification, not just the sanction.
- Point the procedure at the rules this server’s users actually agree to — your access agreement or the
/etc/motdlogin banner — so the ‘established policies’ a person can be sanctioned against are written down. - Keep sanction decisions owned by Human Resources and management, and record each case (date, rule broken, outcome) in a simple log so the process is applied evenly.
- Attach the written sanctions procedure (and the case log) as hardening evidence on the asset, naming
PS-8in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.