ISO 27001:2022 Annex A 5.36 Compliance with Policies, Rules, and Standards Explained

In this guide you will learn how to implement ISO 27001 Annex A 5.36 compliance with policies, rules and standards for information security and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.36 is an ISO 27001 control that wants you to ensure that you are compliant with the information security policy, topic specific policies, rules and standards that you have defined and that it is reviewed regularly.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.36 Compliance with policies, rules and standards for information security is to ensure that what you are doing is still suitable, adequate and effective.

The ISO 27001 standard defines ISO 27001 Annex A 5.36 as:

Compliance with the organisations information security policy, topic-specific policies, rules and standards should be regularly reviewed.

ISO/IEC 27001:2022 Annex A 5.36 Compliance With Policies, Rules And Standards For Information Security

FREE ISO 27001 Annex A 5.36 Training Video

In this free training video you will learn How to implement ISO 27001 Compliance (Annex A 5.36) and Pass Your Audit.

Implementation Guide

Put in place policies and processes for reviews

You will have policy and process for reviews. Consider the guidance in ISO 27001 Clause 9.2 Internal audit.

For the process of review and audit you can learn the exact process by reading How to Conduct an Internal Audit.

Plan your reviews

You will plan your reviews on a periodic basis. There is no real guidance on periodic so plan to do one full audit of everything at least annually. You can implement an audit plan that includes both internal and external audits and reviews.

Who does the review

Independence is not required for 5.36 but it covered under ISO 27001 Annex A 5.35 Independent Review of Information Security.

It is acceptable for the reviews to be conducted by managers, service, product or information owners.

The use of automatic reporting and measuring tools is also acceptable. See the controls 8.15, 8.16 and 8.17.

The review can be conducted by:

  • The manager of the area where the process is being operated
  • The audit team
  • The information security manager
  • A third party consultant

Continual Improvement

Opportunities for continual improvement form part of the independent review. Based on the continual improvement policy and process this is an opportunity to identify any needs for change or enhancements.

Consider the guidance in ISO 27001 Clause 10.1 Continual Improvement.

Corrective Actions

Corrective actions may be required and should be implemented if the review finds things not working as intended. You would record it in the incident and corrective action log, potentially in the risk register if there is a risk identified and manage it as part of the corrective action process.

For further guidance refer to ISO 27001:2002 Clause 10.2 Corrective Action

Keep reports and records

It is important for evidence that is happened to maintain records and reports of the reviews.

When to conduct reviews

The reviews are done at least annually and if anything changes. Examples of things that change that would lead to a review include:

  • Laws change
  • Regulations change
  • You start a new business venture
  • You change business practice
  • You enter a new jurisdiction
  • Your security controls change

How to implement ISO 27001 Annex A 5.36

Implementation of ISO 27001 Annex A 5.36 ensures that your organisation’s information security practices align with internal policies, external standards, and legal requirements. As an ISO 27001 Lead Auditor, I expect to see more than just a policy on a shelf: I look for evidence of active monitoring, technical verification, and executive accountability. Follow these ten technical steps to formalise your compliance framework and satisfy rigorous audit requirements.

1. Formalise the Information Security Compliance Framework

Formalise a comprehensive framework that identifies all relevant legal, regulatory, and contractual obligations: result: establishes the legal and procedural baseline for all organisational security activities.

  • Identify specific regional laws, such as the UK GDPR or Data Protection Act 2018, and list them in your Legal Register.
  • Document all industry-specific standards, such as PCI DSS or SOC2, that apply to your technical operations.
  • Define clear ownership for the maintenance of this framework within the Information Security Management System (ISMS).

2. Provision Compliance Monitoring and Technical Verification Tools

Provision automated tools to monitor system configurations against established security baselines: result: provides real-time visibility into technical policy violations.

  • Deploy vulnerability scanners to identify unpatched software or non-compliant service configurations.
  • Implement Security Information and Event Management (SIEM) systems to alert on unauthorised configuration changes.
  • Utilise Data Loss Prevention (DLP) tools to monitor for the unauthorised movement of sensitive records.

3. Implement IAM Roles and MFA Enforcement

Implement strict Identity and Access Management (IAM) roles and mandate Multi-Factor Authentication (MFA) across all administrative interfaces: result: ensures that only authorised personnel can modify security-critical settings.

  • Apply the principle of least privilege to ensure staff only access resources necessary for their specific roles.
  • Enforce MFA for all remote access and cloud-based management consoles to mitigate credential theft.
  • Regularly audit account permissions to identify and revoke “privilege creep” or orphaned accounts.

4. Establish Technical Rules of Engagement (ROE) for Reviews

Establish a formal Rules of Engagement (ROE) document for all internal and external security reviews: result: prevents operational disruption and defines the legal boundaries for security testing.

  • Define the specific technical scope, including IP addresses and domains, that are subject to active testing.
  • Specify the time windows for technical reviews to avoid impacting critical business processes.
  • Document the escalation procedures for any critical vulnerabilities discovered during the testing process.

5. Provision the Asset Register for Compliance Mapping

Provision the Asset Register to map every technical asset to its relevant security policy and compliance requirement: result: ensures 100 per cent coverage of the technical estate during compliance audits.

  • Assign an “Asset Owner” to every hardware and software entity recorded in the register.
  • Identify the data classification level for information stored on or processed by each asset.
  • Link assets to specific Annex A controls to simplify the generation of a Statement of Applicability (SoA).

6. Conduct Periodic Technical Compliance Reviews

Conduct regular technical reviews of system hardening and configuration standards: result: verifies that security implementations match the theoretical policy requirements.

  • Compare current server configurations against industry-standard hardening guides, such as CIS Benchmarks.
  • Review firewall rule sets quarterly to ensure they remain relevant and do not contain overly permissive entries.
  • Perform annual penetration testing of public-facing infrastructure to validate the effectiveness of security controls.

7. Formalise Policy Acknowledgment and Awareness Training

Formalise a mandatory policy acknowledgment process and security awareness training programme: result: ensures that the human element of the organisation is informed of the rules and standards.

  • Capture digital signatures or timestamps to prove that 100 per cent of staff have read and accepted the security policy.
  • Deploy role-based training modules that address the specific compliance risks associated with different departments.
  • Conduct regular phishing simulations to test the practical application of the organisation’s security rules.

8. Audit Non-Conformance and Corrective Action (CAPA) Processes

Audit the log of security non-conformities and track the completion of corrective actions: result: ensures that identified gaps are closed and risks are mitigated in a timely manner.

  • Implement a formal process for performing Root Cause Analysis (RCA) on all major compliance failures.
  • Assign clear deadlines and remediation owners for every non-conformity discovered during reviews.
  • Maintain a permanent audit trail of all remediation activities for certification body inspection.

9. Review Third-Party and Supplier Compliance

Review the security posture of third-party suppliers to ensure they meet your organisational compliance standards: result: mitigates supply chain risks and ensures data remains protected when processed by external partners.

  • Audit the “Right to Audit” clauses in existing supplier contracts to ensure technical verification is possible.
  • Request and review annual security certifications, such as ISO 27001 or SOC 2 reports, from key vendors.
  • Establish technical integration standards for suppliers accessing organisational networks or data lakes.

10. Present Compliance Status Reports to Management

Present detailed compliance status reports to the Management Review Team at planned intervals: result: ensures executive-level visibility and secures the necessary resources for ISMS maintenance.

  • Synthesise technical scan results and audit findings into high-level Key Performance Indicators (KPIs).
  • Document management’s approval of remediation plans and their acceptance of residual risks.
  • Review the effectiveness of the compliance programme annually to drive continuous improvement.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.36 Compliance with Policies, Rules, and Standards Templates
ISO 27001 Templates

ISO 27001 Annex A 5.36 Templates

The ISO 27001 Gap Analysis, Review and Audit Toolkit provides everything you need to conduct a review from the templates, reports, detailed step by step guides and audit work sheets.

ISO 27001 Gap Analysis and Audit Toolkit - ISO 27001 Annex A 5.36 Templates

ISO 27001 Annex A 5.36 FAQ

Is a formal compliance review process mandatory?

Yes, a documented process for reviewing compliance is mandatory for ISO 27001 certification to prove that security rules are being consistently applied across the organisation.

Who is responsible for conducting compliance reviews?

Compliance reviews should be conducted by managers or system owners responsible for the specific business area or technical system, with oversight from the CISO.

How often should compliance reviews be performed?

Reviews must be performed at regular intervals, typically at least annually for policies and quarterly for high-risk technical systems.

What is the difference between an internal audit and a compliance review?

Auditors require review logs, configuration reports, meeting minutes, and records showing that corrective actions were taken when gaps were identified.

What happens if an employee is found to be non-compliant?

The organisation must document the deviation, determine the root cause, and apply corrective actions, which may include retraining or formal disciplinary measures.

Other applicable standards

ISO/IEC 27007 and ISO/IEC TS 27008 provide guidance for carrying out independent reviews.

Further Reading

ISO 27001 Controls and Attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveAvailability Confidentiality IntegrityIdentify ProtectLegal_and_compliance Information security assuranceGovernance and ecosystem

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top