View Categories

A5.36 Compliance with policies, rules and standards for information security

3 min read

Ensuring compliance with information security policies, rules, and standards is critical for maintaining a secure and well-regulated IT environment. Organizations must enforce policies that align with ISO 27001, GDPR, NIST, PCI DSS, and other regulatory requirements to prevent security breaches and legal issues.

In ISO 27001 A5.36 Compliance with policies, rules and standards for information security control ensures that all employees, contractors, and third parties understand, follow, and comply with security policies while implementing proper monitoring and enforcement mechanisms.

Implementation Guide #

Step 1: Establish Clear Information Security Policies

  • Define organizational security policies covering:
    • Data protection (encryption, access control).
    • Acceptable use policies (internet, email, remote work).
    • Incident response and reporting procedures.
    • Access management (role-based access, MFA).
  • Ensure policies align with ISO 27001 Annex A controls and industry regulations.

Step 2: Communicate and Train Employees

  • Conduct regular security awareness training for employees and contractors.
  • Use learning management systems (LMS) to track compliance with security training.
  • Provide clear guidelines on policy violations and consequences.

Step 3: Implement Monitoring and Compliance Checks

  • Use SIEM solutions (Splunk, Microsoft Sentinel, IBM QRadar) to monitor policy violations.
  • Conduct regular audits and compliance assessments (ISO 27001 internal audits, SOC 2 audits).
  • Perform security gap analyses to identify non-compliance areas.

Step 4: Enforce Security Policies and Take Action

  • Implement automated access controls to enforce compliance.
  • Set up security alerts for policy violations (unauthorized access, data sharing).
  • Define disciplinary actions for non-compliance, including warnings or revocation of access.

Step 5: Continuous Improvement and Policy Updates

  • Update security policies annually or after major incidents.
  • Conduct feedback sessions with employees to address security concerns.
  • Stay updated with new compliance regulations and emerging security threats.

Example Scenario #

Case: An internal audit finds that several employees are sharing sensitive customer data via personal emails, violating the data protection policy.

Actions Taken:

  1. Strict email filtering policies are enforced to block unauthorized data sharing.
  2. Security awareness training is updated to emphasize data protection policies.
  3. SIEM solutions are configured to detect and alert security teams of policy violations.

Common Mistakes in Compliance Management #

  • Lack of enforcement – Policies exist, but no action is taken on violations.
  • Infrequent audits – Security reviews should be conducted at least annually.
  • No employee awareness – Training should be mandatory and ongoing.
  • Failure to adapt to regulatory updates – Compliance teams must track legal changes and update policies accordingly.

Templates for Implementation #

  • Security Policy Compliance Checklist
  • ISO 27001 Compliance Audit Report Template
  • Employee Security Acknowledgment Form

How to Pass an Audit #

Key Documents to Prepare:

  • Security policies, standards, and guidelines.
  • Employee training records and acknowledgment forms.
  • Incident logs and compliance monitoring reports.

What the Auditor Will Check:

  • Is there a documented information security policy?
  • Are employees aware of and following security policies?
  • Are security policies monitored, enforced, and regularly updated?

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.5.36 Compliance with Policies, Rules, and Standards for Information Security Preventive, Compliance, Detective
Purpose Ensure adherence to security policies and regulations
Applicability All employees, contractors, and third parties
ISO 27001 Domains Compliance, Security Awareness, Risk Management

 

Compliance is not just a checkbox exercise—it’s an ongoing process that protects organizations from legal risks, security breaches, and reputational damage. Organizations should enforce, monitor, and continuously improve their security policies to maintain a strong security posture.

Action Step:
Review your security policies today, conduct an internal audit, and ensure all employees are trained and following compliance requirements.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now