In this guide you will learn how to implement ISO 27001 Annex A 5.36 compliance with policies, rules and standards for information security and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.36 is an ISO 27001 control that wants you to ensure that you are compliant with the information security policy, topic specific policies, rules and standards that you have defined and that it is reviewed regularly.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.36 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.36
- 1. Formalise the Information Security Compliance Framework
- 2. Provision Compliance Monitoring and Technical Verification Tools
- 3. Implement IAM Roles and MFA Enforcement
- 4. Establish Technical Rules of Engagement (ROE) for Reviews
- 5. Provision the Asset Register for Compliance Mapping
- 6. Conduct Periodic Technical Compliance Reviews
- 7. Formalise Policy Acknowledgment and Awareness Training
- 8. Audit Non-Conformance and Corrective Action (CAPA) Processes
- 9. Review Third-Party and Supplier Compliance
- 10. Present Compliance Status Reports to Management
- ISO 27001 Templates
- ISO 27001 Annex A 5.36 Templates
- ISO 27001 Annex A 5.36 FAQ
- Other applicable standards
- Further Reading
- ISO 27001 Controls and Attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.36 Compliance with policies, rules and standards for information security is to ensure that what you are doing is still suitable, adequate and effective.
The ISO 27001 standard defines ISO 27001 Annex A 5.36 as:
Compliance with the organisations information security policy, topic-specific policies, rules and standards should be regularly reviewed.
ISO/IEC 27001:2022 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.36 Training Video
In this free training video you will learn How to implement ISO 27001 Compliance (Annex A 5.36) and Pass Your Audit.
Implementation Guide
Put in place policies and processes for reviews
You will have policy and process for reviews. Consider the guidance in ISO 27001 Clause 9.2 Internal audit.
For the process of review and audit you can learn the exact process by reading How to Conduct an Internal Audit.
Plan your reviews
You will plan your reviews on a periodic basis. There is no real guidance on periodic so plan to do one full audit of everything at least annually. You can implement an audit plan that includes both internal and external audits and reviews.
Who does the review
Independence is not required for 5.36 but it covered under ISO 27001 Annex A 5.35 Independent Review of Information Security.
It is acceptable for the reviews to be conducted by managers, service, product or information owners.
The use of automatic reporting and measuring tools is also acceptable. See the controls 8.15, 8.16 and 8.17.
The review can be conducted by:
- The manager of the area where the process is being operated
- The audit team
- The information security manager
- A third party consultant
Continual Improvement
Opportunities for continual improvement form part of the independent review. Based on the continual improvement policy and process this is an opportunity to identify any needs for change or enhancements.
Consider the guidance in ISO 27001 Clause 10.1 Continual Improvement.
Corrective Actions
Corrective actions may be required and should be implemented if the review finds things not working as intended. You would record it in the incident and corrective action log, potentially in the risk register if there is a risk identified and manage it as part of the corrective action process.
For further guidance refer to ISO 27001:2002 Clause 10.2 Corrective Action
Keep reports and records
It is important for evidence that is happened to maintain records and reports of the reviews.
When to conduct reviews
The reviews are done at least annually and if anything changes. Examples of things that change that would lead to a review include:
- Laws change
- Regulations change
- You start a new business venture
- You change business practice
- You enter a new jurisdiction
- Your security controls change
How to implement ISO 27001 Annex A 5.36
Implementation of ISO 27001 Annex A 5.36 ensures that your organisation’s information security practices align with internal policies, external standards, and legal requirements. As an ISO 27001 Lead Auditor, I expect to see more than just a policy on a shelf: I look for evidence of active monitoring, technical verification, and executive accountability. Follow these ten technical steps to formalise your compliance framework and satisfy rigorous audit requirements.
1. Formalise the Information Security Compliance Framework
Formalise a comprehensive framework that identifies all relevant legal, regulatory, and contractual obligations: result: establishes the legal and procedural baseline for all organisational security activities.
- Identify specific regional laws, such as the UK GDPR or Data Protection Act 2018, and list them in your Legal Register.
- Document all industry-specific standards, such as PCI DSS or SOC2, that apply to your technical operations.
- Define clear ownership for the maintenance of this framework within the Information Security Management System (ISMS).
2. Provision Compliance Monitoring and Technical Verification Tools
Provision automated tools to monitor system configurations against established security baselines: result: provides real-time visibility into technical policy violations.
- Deploy vulnerability scanners to identify unpatched software or non-compliant service configurations.
- Implement Security Information and Event Management (SIEM) systems to alert on unauthorised configuration changes.
- Utilise Data Loss Prevention (DLP) tools to monitor for the unauthorised movement of sensitive records.
3. Implement IAM Roles and MFA Enforcement
Implement strict Identity and Access Management (IAM) roles and mandate Multi-Factor Authentication (MFA) across all administrative interfaces: result: ensures that only authorised personnel can modify security-critical settings.
- Apply the principle of least privilege to ensure staff only access resources necessary for their specific roles.
- Enforce MFA for all remote access and cloud-based management consoles to mitigate credential theft.
- Regularly audit account permissions to identify and revoke “privilege creep” or orphaned accounts.
4. Establish Technical Rules of Engagement (ROE) for Reviews
Establish a formal Rules of Engagement (ROE) document for all internal and external security reviews: result: prevents operational disruption and defines the legal boundaries for security testing.
- Define the specific technical scope, including IP addresses and domains, that are subject to active testing.
- Specify the time windows for technical reviews to avoid impacting critical business processes.
- Document the escalation procedures for any critical vulnerabilities discovered during the testing process.
5. Provision the Asset Register for Compliance Mapping
Provision the Asset Register to map every technical asset to its relevant security policy and compliance requirement: result: ensures 100 per cent coverage of the technical estate during compliance audits.
- Assign an “Asset Owner” to every hardware and software entity recorded in the register.
- Identify the data classification level for information stored on or processed by each asset.
- Link assets to specific Annex A controls to simplify the generation of a Statement of Applicability (SoA).
6. Conduct Periodic Technical Compliance Reviews
Conduct regular technical reviews of system hardening and configuration standards: result: verifies that security implementations match the theoretical policy requirements.
- Compare current server configurations against industry-standard hardening guides, such as CIS Benchmarks.
- Review firewall rule sets quarterly to ensure they remain relevant and do not contain overly permissive entries.
- Perform annual penetration testing of public-facing infrastructure to validate the effectiveness of security controls.
7. Formalise Policy Acknowledgment and Awareness Training
Formalise a mandatory policy acknowledgment process and security awareness training programme: result: ensures that the human element of the organisation is informed of the rules and standards.
- Capture digital signatures or timestamps to prove that 100 per cent of staff have read and accepted the security policy.
- Deploy role-based training modules that address the specific compliance risks associated with different departments.
- Conduct regular phishing simulations to test the practical application of the organisation’s security rules.
8. Audit Non-Conformance and Corrective Action (CAPA) Processes
Audit the log of security non-conformities and track the completion of corrective actions: result: ensures that identified gaps are closed and risks are mitigated in a timely manner.
- Implement a formal process for performing Root Cause Analysis (RCA) on all major compliance failures.
- Assign clear deadlines and remediation owners for every non-conformity discovered during reviews.
- Maintain a permanent audit trail of all remediation activities for certification body inspection.
9. Review Third-Party and Supplier Compliance
Review the security posture of third-party suppliers to ensure they meet your organisational compliance standards: result: mitigates supply chain risks and ensures data remains protected when processed by external partners.
- Audit the “Right to Audit” clauses in existing supplier contracts to ensure technical verification is possible.
- Request and review annual security certifications, such as ISO 27001 or SOC 2 reports, from key vendors.
- Establish technical integration standards for suppliers accessing organisational networks or data lakes.
10. Present Compliance Status Reports to Management
Present detailed compliance status reports to the Management Review Team at planned intervals: result: ensures executive-level visibility and secures the necessary resources for ISMS maintenance.
- Synthesise technical scan results and audit findings into high-level Key Performance Indicators (KPIs).
- Document management’s approval of remediation plans and their acceptance of residual risks.
- Review the effectiveness of the compliance programme annually to drive continuous improvement.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

ISO 27001 Templates

ISO 27001 Annex A 5.36 Templates
The ISO 27001 Gap Analysis, Review and Audit Toolkit provides everything you need to conduct a review from the templates, reports, detailed step by step guides and audit work sheets.

ISO 27001 Annex A 5.36 FAQ
Yes, a documented process for reviewing compliance is mandatory for ISO 27001 certification to prove that security rules are being consistently applied across the organisation.
Compliance reviews should be conducted by managers or system owners responsible for the specific business area or technical system, with oversight from the CISO.
Reviews must be performed at regular intervals, typically at least annually for policies and quarterly for high-risk technical systems.
Auditors require review logs, configuration reports, meeting minutes, and records showing that corrective actions were taken when gaps were identified.
The organisation must document the deviation, determine the root cause, and apply corrective actions, which may include retraining or formal disciplinary measures.
Other applicable standards
ISO/IEC 27007 and ISO/IEC TS 27008 provide guidance for carrying out independent reviews.
Further Reading
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability Confidentiality Integrity | Identify Protect | Legal_and_compliance Information security assurance | Governance and ecosystem |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.
