ISO/IEC 27001:2022 Annex A · Control 5.36
Compliance with Policies, Rules and Standards for Information Security: A Practical Implementation Guide
Verify that security requirements are followed in practice and correct deviations consistently.
This control concerns regular review of compliance with information security policies, topic-specific rules and standards.
What should the control achieve?
- Compliance responsibilities and checks are defined.
- Reviews use reliable evidence and risk-based frequency.
- Non-compliance is recorded and treated.
- Patterns improve controls, training and policy design.
Step-by-step implementation
Map requirements to checks
For each important rule define evidence, owner, frequency and acceptable criteria.
Prioritize risk
Review high-impact and frequently changing areas more often.
Use multiple methods
Combine automated monitoring, samples, attestations, walkthroughs and technical tests.
Record deviations
Capture requirement, scope, cause, risk and immediate safeguards.
Correct and escalate
Assign actions, manage exceptions and use disciplinary processes when appropriate.
Analyze trends
Identify recurring failures and revise unclear or unrealistic rules.
What this could look like in practice
Quarterly compliance checks sample privileged accounts, backup tests, supplier reviews and secure-development records. Findings enter a central tracker. Repeated exceptions to one standard trigger a policy-owner review.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Automated check | Configuration rules identify baseline deviations. | Compliance dashboard |
| Sample review | Control owner inspects approvals and evidence. | Review worksheet |
| Deviation | Risk, owner and deadline are recorded. | Finding ticket |
| Trend review | Management examines repeated causes. | Management report |
Implementation evidence
- Compliance review program
- Requirement-control mapping
- Automated reports
- Sample records
- Findings
- Exception approvals
- Corrective actions
- Trend analysis
Useful metrics
- Planned checks completed
- Non-compliance by severity
- Repeat deviations
- Corrective actions overdue
Common mistakes
- Relying only on self-attestation.
- Checking every rule at the same frequency.
- Treating all deviations as misconduct.
- Approving exceptions without expiry.
- Failing to improve impractical policies.
Questions an auditor may ask
- How is policy compliance tested?
- Show evidence from a recent sample.
- How are deviations distinguished from approved exceptions?
- What trends reached management?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.