ISO 27002:2022 5.36: Compliance with policies, rules and standards for information security
How well the organization keeps to its security policy and to its topic policies, rules and standards is to be checked regularly. Purpose: confirm that security is put in place and operated the way the top policy and the topic policies, rules and standards demand. Guidance: managers and owners of services, products or information work out how to check that what the policies, rules, standards and any applicable regulations require is actually happening, and should consider automated measurement and reporting tools to make regular review efficient. When non-compliance is found they identify its causes, assess whether corrective action is needed, implement suitable action, and review that action to confirm it worked and to spot any remaining weaknesses. The results of reviews and corrective actions are recorded and the records kept, and managers pass them to independent reviewers (5.35) when an independent review covers their area. Corrective actions are completed promptly in proportion to risk, and any not finished by the next scheduled review are at least followed up there. Monitoring how systems are used day to day falls under 8.15 to 8.17.
This control maps to 142 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.36 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.