← All controls
A.5.36 · Organizational
Compliance with policies, rules and standards for information security
Why it matters
A policy nobody checks against reality is decoration, not control.
How a self-led small team implements it
Your internal audit (once you start one) is the natural evidence for this — don't build a separate compliance-checking process.
What auditors expect to see
Internal audit findings referencing policy compliance.
Track A.5.36 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS