Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.36

Compliance with Policies, Rules and Standards for Information Security: A Practical Implementation Guide

Verify that security requirements are followed in practice and correct deviations consistently.

This control concerns regular review of compliance with information security policies, topic-specific rules and standards.

Practical interpretation: Policy publication does not prove compliance. Control owners need monitoring and sample-based checks that reveal both individual deviations and impractical requirements.

What should the control achieve?

  • Compliance responsibilities and checks are defined.
  • Reviews use reliable evidence and risk-based frequency.
  • Non-compliance is recorded and treated.
  • Patterns improve controls, training and policy design.

Step-by-step implementation

1

Map requirements to checks

For each important rule define evidence, owner, frequency and acceptable criteria.

2

Prioritize risk

Review high-impact and frequently changing areas more often.

3

Use multiple methods

Combine automated monitoring, samples, attestations, walkthroughs and technical tests.

4

Record deviations

Capture requirement, scope, cause, risk and immediate safeguards.

5

Correct and escalate

Assign actions, manage exceptions and use disciplinary processes when appropriate.

6

Analyze trends

Identify recurring failures and revise unclear or unrealistic rules.

What this could look like in practice

Quarterly compliance checks sample privileged accounts, backup tests, supplier reviews and secure-development records. Findings enter a central tracker. Repeated exceptions to one standard trigger a policy-owner review.

ActivityPractical implementationEvidence
Automated checkConfiguration rules identify baseline deviations.Compliance dashboard
Sample reviewControl owner inspects approvals and evidence.Review worksheet
DeviationRisk, owner and deadline are recorded.Finding ticket
Trend reviewManagement examines repeated causes.Management report

Implementation evidence

  • Compliance review program
  • Requirement-control mapping
  • Automated reports
  • Sample records
  • Findings
  • Exception approvals
  • Corrective actions
  • Trend analysis

Useful metrics

  • Planned checks completed
  • Non-compliance by severity
  • Repeat deviations
  • Corrective actions overdue

Common mistakes

  • Relying only on self-attestation.
  • Checking every rule at the same frequency.
  • Treating all deviations as misconduct.
  • Approving exceptions without expiry.
  • Failing to improve impractical policies.

Questions an auditor may ask

  • How is policy compliance tested?
  • Show evidence from a recent sample.
  • How are deviations distinguished from approved exceptions?
  • What trends reached management?
Implementation test: Choose one mandatory policy rule and demonstrate a repeatable check, recent result, deviation handling and management visibility.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.