Back to all 93 controls
    Annex A 5.36
    Organizational

    A.5.36 Compliance with policies, rules and standards for information security

    Compliance with policies is verified.

    What good looks like

    Monitoring/testing of policy adherence; non-compliance handled.

    Evidence an auditor will ask for

    Compliance check results, exception register.

    Document template for this control

    The Compliance Policy template gives you auditor-ready wording that fulfils Annex A 5.36. Preview the full document before you download the editable version.