ISO 27001:2022 Annex A 5.36 Compliance with Policies, Rules, and Standards Explained

ISO 27001 Annex A 5.36 Compliance with policies and standards for information security

In this guide you will learn how to implement ISO 27001 Annex A 5.36 compliance with policies, rules and standards for information security and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.36 is an ISO 27001 control that wants you to ensure that you are compliant with the information security policy, topic specific policies, rules and standards that you have defined and that it is reviewed regularly.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.36 Compliance with policies, rules and standards for information security is to ensure that what you are doing is still suitable, adequate and effective.

The ISO 27001 standard defines ISO 27001 Annex A 5.36 as:

Compliance with the organisations information security policy, topic-specific policies, rules and standards should be regularly reviewed.

ISO 27001:2022 Annex A 5.36 Compliance with policies, rules and standards for information security

FREE ISO 27001 Annex A 5.36 Training Video

In this free training video you will learn How to implement ISO 27001 Compliance (Annex A 5.36) and Pass Your Audit.

Implementation Guide

Put in place policies and processes for reviews

You will have policy and process for reviews. Consider the guidance in ISO 27001 Clause 9.2 Internal audit.

For the process of review and audit you can learn the exact process by reading How to Conduct an Internal Audit.

Plan your reviews

You will plan your reviews on a periodic basis. There is no real guidance on periodic so plan to do one full audit of everything at least annually. You can implement an audit plan that includes both internal and external audits and reviews.

Who does the review

Independence is not required for 5.36 but it covered under ISO 27001 Annex A 5.35 Independent Review of Information Security.

It is acceptable for the reviews to be conducted by managers, service, product or information owners.

The use of automatic reporting and measuring tools is also acceptable. See the controls 8.15, 8.16 and 8.17.

The review can be conducted by:

  • The manager of the area where the process is being operated
  • The audit team
  • The information security manager
  • A third party consultant

Continual Improvement

Opportunities for continual improvement form part of the independent review. Based on the continual improvement policy and process this is an opportunity to identify any needs for change or enhancements.

Consider the guidance in ISO 27001 Clause 10.1 Continual Improvement.

Corrective Actions

Corrective actions may be required and should be implemented if the review finds things not working as intended. You would record it in the incident and corrective action log, potentially in the risk register if there is a risk identified and manage it as part of the corrective action process.

For further guidance refer to ISO 27001:2002 Clause 10.2 Corrective Action

Keep reports and records

It is important for evidence that is happened to maintain records and reports of the reviews.

When to conduct reviews

The reviews are done at least annually and if anything changes. Examples of things that change that would lead to a review include:

  • Laws change
  • Regulations change
  • You start a new business venture
  • You change business practice
  • You enter a new jurisdiction
  • Your security controls change

How to implement ISO 27001 Annex A 5.36

Implementation of ISO 27001 Annex A 5.36 ensures that your organisation’s information security practices align with internal policies, external standards, and legal requirements. As an ISO 27001 Lead Auditor, I expect to see more than just a policy on a shelf: I look for evidence of active monitoring, technical verification, and executive accountability. Follow these ten technical steps to formalise your compliance framework and satisfy rigorous audit requirements.

1. Formalise the Information Security Compliance Framework

Formalise a comprehensive framework that identifies all relevant legal, regulatory, and contractual obligations: result: establishes the legal and procedural baseline for all organisational security activities.

  • Identify specific regional laws, such as the UK GDPR or Data Protection Act 2018, and list them in your Legal Register.
  • Document all industry-specific standards, such as PCI DSS or SOC2, that apply to your technical operations.
  • Define clear ownership for the maintenance of this framework within the Information Security Management System (ISMS).

2. Provision Compliance Monitoring and Technical Verification Tools

Provision automated tools to monitor system configurations against established security baselines: result: provides real-time visibility into technical policy violations.

  • Deploy vulnerability scanners to identify unpatched software or non-compliant service configurations.
  • Implement Security Information and Event Management (SIEM) systems to alert on unauthorised configuration changes.
  • Utilise Data Loss Prevention (DLP) tools to monitor for the unauthorised movement of sensitive records.

3. Implement IAM Roles and MFA Enforcement

Implement strict Identity and Access Management (IAM) roles and mandate Multi-Factor Authentication (MFA) across all administrative interfaces: result: ensures that only authorised personnel can modify security-critical settings.

  • Apply the principle of least privilege to ensure staff only access resources necessary for their specific roles.
  • Enforce MFA for all remote access and cloud-based management consoles to mitigate credential theft.
  • Regularly audit account permissions to identify and revoke “privilege creep” or orphaned accounts.

4. Establish Technical Rules of Engagement (ROE) for Reviews

Establish a formal Rules of Engagement (ROE) document for all internal and external security reviews: result: prevents operational disruption and defines the legal boundaries for security testing.

  • Define the specific technical scope, including IP addresses and domains, that are subject to active testing.
  • Specify the time windows for technical reviews to avoid impacting critical business processes.
  • Document the escalation procedures for any critical vulnerabilities discovered during the testing process.

5. Provision the Asset Register for Compliance Mapping

Provision the Asset Register to map every technical asset to its relevant security policy and compliance requirement: result: ensures 100 per cent coverage of the technical estate during compliance audits.

  • Assign an “Asset Owner” to every hardware and software entity recorded in the register.
  • Identify the data classification level for information stored on or processed by each asset.
  • Link assets to specific Annex A controls to simplify the generation of a Statement of Applicability (SoA).

6. Conduct Periodic Technical Compliance Reviews

Conduct regular technical reviews of system hardening and configuration standards: result: verifies that security implementations match the theoretical policy requirements.

  • Compare current server configurations against industry-standard hardening guides, such as CIS Benchmarks.
  • Review firewall rule sets quarterly to ensure they remain relevant and do not contain overly permissive entries.
  • Perform annual penetration testing of public-facing infrastructure to validate the effectiveness of security controls.

7. Formalise Policy Acknowledgment and Awareness Training

Formalise a mandatory policy acknowledgment process and security awareness training programme: result: ensures that the human element of the organisation is informed of the rules and standards.

  • Capture digital signatures or timestamps to prove that 100 per cent of staff have read and accepted the security policy.
  • Deploy role-based training modules that address the specific compliance risks associated with different departments.
  • Conduct regular phishing simulations to test the practical application of the organisation’s security rules.

8. Audit Non-Conformance and Corrective Action (CAPA) Processes

Audit the log of security non-conformities and track the completion of corrective actions: result: ensures that identified gaps are closed and risks are mitigated in a timely manner.

  • Implement a formal process for performing Root Cause Analysis (RCA) on all major compliance failures.
  • Assign clear deadlines and remediation owners for every non-conformity discovered during reviews.
  • Maintain a permanent audit trail of all remediation activities for certification body inspection.

9. Review Third-Party and Supplier Compliance

Review the security posture of third-party suppliers to ensure they meet your organisational compliance standards: result: mitigates supply chain risks and ensures data remains protected when processed by external partners.

  • Audit the “Right to Audit” clauses in existing supplier contracts to ensure technical verification is possible.
  • Request and review annual security certifications, such as ISO 27001 or SOC 2 reports, from key vendors.
  • Establish technical integration standards for suppliers accessing organisational networks or data lakes.

10. Present Compliance Status Reports to Management

Present detailed compliance status reports to the Management Review Team at planned intervals: result: ensures executive-level visibility and secures the necessary resources for ISMS maintenance.

  • Synthesise technical scan results and audit findings into high-level Key Performance Indicators (KPIs).
  • Document management’s approval of remediation plans and their acceptance of residual risks.
  • Review the effectiveness of the compliance programme annually to drive continuous improvement.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.36 Compliance with Policies, Rules, and Standards Templates
ISO 27001 Templates

How to Audit ISO 27001 Annex A 5.36

Auditing ISO 27001 Annex A 5.36 requires a technical deep dive into how your organisation validates its adherence to internal policies and external standards. As a Lead Auditor, I am looking for evidence that goes beyond a simple document review: I want to see technical asset mapping, automated scanning logs, and executive-level accountability for non-conformities. Use this 10 step technical roadmap to ensure your compliance review process is robust enough to withstand a rigorous certification audit.

1. Audit the information security compliance framework

Audit the documented schedule for compliance reviews to ensure that all business processes are regularly checked against policy: result: establishes the legal and procedural baseline for the audit programme.

  • Verify that the review frequency is determined by the level of risk associated with each business unit.
  • Check that the framework includes checks against both internal rules and external regulatory requirements.
  • Confirm the compliance framework is reviewed annually and carries senior management approval.

2. Inspect technical vulnerability management configurations

Inspect the results of the latest vulnerability scans to verify that technical assets remain compliant with hardening standards: result: ensures technical risks are identified and remediated in a timely manner.

  • Review the scan logs to confirm that all technical assets in scope are being scanned.
  • Verify that identified vulnerabilities are mapped to the organisational corrective action process.
  • Check for evidence of “clean” scans following the remediation of high-risk findings.

3. Provision restricted Identity and Access Management (IAM) roles for the auditor

Provision temporary, read-only access for the audit team to review security configurations while maintaining the principle of least privilege: result: provides the visibility required for evidence collection without compromising security.

  • Apply Multi-Factor Authentication (MFA) to the auditor’s temporary account access points.
  • Record the specific roles assigned to the auditor within the Identity and Access Management (IAM) system.
  • Audit the revocation of these access rights immediately upon the conclusion of the audit activity.

4. Formalise the rules of engagement (ROE) for technical reviews

Formalise a written agreement defining the technical boundaries and limitations of the compliance audit: result: prevents operational disruption and defines legal accountability during testing.

  • Document the specific time windows for testing to avoid impact on critical business processes.
  • List any technical assets that are excluded from the scope of active testing for stability reasons.
  • Verify that all parties have signed the Rules of Engagement (ROE) document before testing begins.

5. Audit the information security policy acknowledgment records

Audit the records of staff signatures or digital acceptances of the security policy: result: confirms that employees have been informed of the rules they are expected to follow.

  • Check for 100 per cent completion of policy acknowledgments for all new starters.
  • Verify that acknowledgments are refreshed whenever a significant change is made to the policy.
  • Review the awareness training logs to ensure the policy content has been effectively communicated.

6. Inspect the non-conformity and corrective action log

Inspect the log of previous compliance failures to verify that root cause analysis was performed: result: ensures that historical failures drive continuous improvement within the ISMS.

  • Verify that every entry has an assigned “Action Owner” and a realistic remediation date.
  • Check for evidence that management has allocated the necessary resources to fix the non-conformity.
  • Confirm that remediation actions are tested for effectiveness before the issue is closed.

7. Audit the effectiveness of automated monitoring systems

Audit the alerts and reports generated by SIEM or DLP tools to verify that policy breaches are detected automatically: result: reduces reliance on manual checks and provides high-density security telemetry.

  • Inspect the configuration of automated alerts to ensure they trigger based on policy violations.
  • Review a sample of alerts to verify that the security team responded according to the incident plan.
  • Check for evidence of regular tuning of the monitoring tools to reduce false positives.

8. Review management oversight and meeting minutes

Review the minutes from Management Review Team meetings to verify that compliance status is reported to top management: result: ensures executive accountability for security investments and remediation.

  • Check that compliance reporting is a standing agenda item for the Management Review Team.
  • Verify that the board has documented their decision-making process for high-risk findings.
  • Confirm that compliance trends are tracked over time to identify systemic weaknesses.

9. Inspect physical security compliance through site walkthroughs

Inspect physical entry points and server rooms to verify that physical security rules are enforced in practice: result: identifies real-world gaps that may not be captured in digital logs.

  • Verify that the “Clean Desk” policy is being followed in high-sensitivity areas.
  • Check that physical access logs match the authorised personnel list in the Asset Register.
  • Inspect the integrity of physical perimeters, such as locks, cameras, and alarms.

10. Validate the integration of compliance with the asset register

Validate that every asset in the register is mapped to a specific compliance check or review cycle: result: ensures 100 per cent coverage of the technical estate during audit activities.

  • Compare the technical scan reports against the inventory in the Asset Register to find “Shadow IT.”
  • Verify that new assets are automatically included in the compliance review process upon deployment.
  • Check that decommissioned assets are formally removed from the compliance scope and the register.

ISO 27001 Annex A 5.36 Templates

The ISO 27001 Gap Analysis, Review and Audit Toolkit provides everything you need to conduct a review from the templates, reports, detailed step by step guides and audit work sheets.

ISO 27001 Gap Analysis and Audit Toolkit - ISO 27001 Annex A 5.36 Templates

ISO 27001 Annex A 5.36 FAQ

Is a formal compliance review process mandatory?

Yes, a documented process for reviewing compliance is mandatory for ISO 27001 certification to prove that security rules are being consistently applied across the organisation.

Who is responsible for conducting compliance reviews?

Compliance reviews should be conducted by managers or system owners responsible for the specific business area or technical system, with oversight from the CISO.

How often should compliance reviews be performed?

Reviews must be performed at regular intervals, typically at least annually for policies and quarterly for high-risk technical systems.

What is the difference between an internal audit and a compliance review?

Auditors require review logs, configuration reports, meeting minutes, and records showing that corrective actions were taken when gaps were identified.

What happens if an employee is found to be non-compliant?

The organisation must document the deviation, determine the root cause, and apply corrective actions, which may include retraining or formal disciplinary measures.

Other applicable standards

ISO/IEC 27007 and ISO/IEC TS 27008 provide guidance for carrying out independent reviews.

Further Reading

ISO 27001 Controls and Attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveAvailability Confidentiality IntegrityIdentify ProtectLegal_and_compliance Information security assuranceGovernance and ecosystem

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top