ISO 27001 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security (The Unofficial Zero BS Guide)

ISO 27001 Annex A 5.36

ISO 27001 Annex A 5.36 Compliance with policies and standards for information security requires organisations to review compliance regularly. Documented reviews ensure staff and technical systems follow security rules and meet audit standards.

Key Takeaways

  • Review policy compliance regularly: Check that managers and teams carry out daily work in line with published security rules.
  • Store review logs centrally: Keep compliance reports, gap assessments, and action plans in a central document repository.
  • Automate technical checks: Use system monitoring tools and compliance scans to verify device configurations automatically.
  • Assign compliance ownership: Require department heads to review their own operational units and report gaps on a set schedule.
  • Address non-compliance quickly: Log security gaps as corrective actions and resolve non-conformities before external audits.
  • Maintain independent reviews: Combine self-assessments with objective internal audits to ensure impartial compliance checks.
  • Report findings to leadership: Present compliance metrics and audit findings during routine management review meetings.
  • Drive continuous improvement: Update security standards and training whenever compliance reviews highlight recurring weaknesses.

How to Implement ISO 27001 Annex A 5.36

  • Define compliance review rules: Write a documented policy review procedure and store it in your central document repository.
  • Set a compliance review schedule: Establish planned calendar dates to assess policy adherence across all business departments.
  • Run automated configuration scans: Deploy tools to check that servers, user endpoints, and cloud systems meet baseline security standards.
  • Train managers on assessment steps: Teach team leaders how to review staff practices, permissions, and records against security policies.
  • Log compliance gaps: Record every discovered policy violation or technical deviation in a central corrective action tracker.
  • Assign corrective action owners: Appoint named individuals and set fixed deadlines to resolve identified compliance gaps.
  • Perform spot checks: Conduct unannounced checks on clean desk rules, password safety, and physical access controls.
  • Report results to executives: Share compliance review summaries with leadership to guide security budget and policy decisions.
  • Update policies after reviews: Refine confusing or impractical policies when repeated non-compliance indicates process friction.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Annex A 5.36

  • Review compliance schedules: Inspect written review plans to verify regular assessments occur across all departments and systems.
  • Sample completed review reports: Check recent departmental assessment logs to confirm managers evaluated staff and systems.
  • Verify automated compliance scans: Inspect system audit logs to confirm automated scans verify endpoint and network configurations.
  • Track corrective actions: Sample flagged policy gaps to verify teams assigned remediation owners and closed issues on time.
  • Interview team leaders: Ask department managers how they verify that their team members follow organizational security rules.
  • Inspect spot check records: Review notes from unannounced audits to confirm teams carry out regular physical and digital checks.
  • Check management review inputs: Confirm leadership receives and discusses compliance review reports during formal meetings.
  • Verify auditor independence: Confirm internal auditors do not review their own operational areas or direct responsibilities.

Audit Evidence Checklist

  • Compliance review procedure: Maintain a documented policy review procedure with full version history in your central repository.
  • Annual review calendar: Supply a formal schedule showing completed and planned compliance assessments across all departments.
  • Departmental review reports: Provide signed records showing manager reviews of operational security practices.
  • Automated scan reports: Supply dashboard exports proving systems scan endpoints and cloud accounts against security baselines.
  • Corrective action logs: Maintain an active tracking register showing remediated policy deviations and resolution dates.
  • Management review minutes: Supply meeting notes proving executives reviewed policy compliance findings and action plans.
  • Spot check audit logs: Provide records from physical walkthroughs checking clear desk and clean screen compliance.

What to Teach Employees

  • Understand compliance duties: Teach staff that following published security rules is a mandatory part of everyday work.
  • Participate in regular reviews: Instruct workers to assist managers openly during internal checks, audits, and spot checks.
  • Report policy gaps safely: Encourage staff to flag impractical security rules so policies can be improved and simplified.
  • Avoid bypassing rules: Warn workers against taking unapproved security shortcuts to finish tasks faster.
  • Follow corrective instructions: Teach staff to complete assigned remediation steps promptly when security reviews identify gaps.
  • Know how compliance protects: Educate workers on how policy adherence protects client data and prevents severe business loss.

Common Implementation Challenges

  • Treating compliance as a tick-box: Teams rush through checklists without testing real security habits. Conduct practical spot checks.
  • Ignoring identified gaps: Reviews uncover non-compliance but nobody fixes root causes. Track all findings in a formal action register.
  • Overly complex policies: Staff ignore rules that create friction in daily workflows. Simplify policies to make compliance easy.
  • Lack of manager involvement: Department leaders assume compliance belongs solely to IT. Train managers to run reviews within their teams.
  • Manual verification bottlenecks: Checking systems manually takes too much time. Use automated tools to audit technical baselines.
  • Fear of reporting mistakes: Staff hide non-compliant practices from auditors. Foster a blameless culture focused on fixing process gaps.

How to Measure Effectiveness (KPIs)

  • Policy review completion rate: Track the percentage of scheduled compliance reviews completed on time across all units.
  • Technical baseline compliance rate: Measure the proportion of systems meeting automated security standards during scans.
  • Corrective action closure speed: Measure the average number of days taken to resolve identified policy non-conformities.
  • Repeat non-compliance rate: Track the percentage of security review findings that recur across consecutive audits.
  • Spot check pass rate: Measure the proportion of successful spot checks for clean desks, screen locks, and access controls.
  • External audit finding count: Monitor the number of non-conformities raised by external auditors during ISO 27001 assessments.

ISO 27001 Control A 5.36 connects to several other ISO 27001 requirements:

  • Clause 9.1: Monitoring, measurement, analysis, and evaluation.
  • Clause 9.2: Internal audit requirements.
  • Annex A 5.35: Independent review of information security.
ISO 27001 Compliance With Policies, Rules And Standards For Information Security Explained - Annex A 5.36 - High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply