A.5.36Compliance with policies, rules and standards for information security
Regularly check that staff and systems actually comply with your security policies and standards, and follow up where they fall short. Written rules only protect you if they are followed.
Mapping at a glance
A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Internal audit report
The output of the internal reviews the company runs on its own security controls, with findings and improvement actions.
Audit evidence and corrective actions log
The file where proof that controls work is kept, plus the tracking of audit findings through to closure.
From the Sekit evidence catalog
In practice
In practice this control functions as the company's checking layer: a recurring cycle of internal audits, control tests and configuration reviews that catches drift between written policy and what people do day to day. Auditors ask for the internal audit report and the corrective action log together, then trace one finding from discovery to closure. The common failure mode is a compliance programme that produces findings nobody tracks to resolution, so the same gap reappears at every review because nothing forces it shut.
Common gaps
Internal audit findings are logged but nobody owns closing them, so the same finding reappears in the next audit cycle unresolved.
Policy exceptions get approved once and never revisited, so expired exceptions quietly become permanent unwritten changes to the rule.
The regulatory mapping register lists which law applies but nobody rechecked it against the current control set in over a year.
Questions your auditor will ask
How do you track an audit finding from discovery to closure?
The audit evidence and corrective actions log names an owner and a deadline for each finding, and overdue items escalate to leadership.
Who signs off when a security control test finds a failure?
The control testing program assigns a named owner and target date to every failed test, tracked in the corrective action log until closed.
How current is the mapping between regulations and internal controls?
The regulatory mapping register is reworked whenever a regulation or the business changes, and a live tool flags any obligation without a covering control.
What happens when staff do not follow an approved security policy?
Compliance monitoring routines flag the deviation, and it is logged as an issue with an owner until either the practice or the policy is corrected.
Where regulation demands it
NIS2 2.2 requires ongoing compliance monitoring, the exact discipline this control's audits, control tests and configuration reviews carry out.
ENS org.3 requires documented security procedures, the baseline this control verifies are followed across the company.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.