Back to all 93 controls
Annex A 5.36
Organizational
A.5.36 Compliance with policies, rules and standards for information security
Compliance with policies is verified.
What good looks like
Monitoring/testing of policy adherence; non-compliance handled.
Evidence an auditor will ask for
Compliance check results, exception register.
Document template for this control
The Compliance Policy template gives you auditor-ready wording that fulfils Annex A 5.36. Preview the full document before you download the editable version.
