isms.coach
← All controls

A.5.36 · Organizational

Compliance with policies, rules and standards for information security

Why it matters

A policy nobody checks against reality is decoration, not control.

How a self-led small team implements it

Your internal audit (once you start one) is the natural evidence for this — don't build a separate compliance-checking process.

What auditors expect to see

Internal audit findings referencing policy compliance.

Track A.5.36 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls