ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.36: Compliance with policies, rules and standards for information security

How well the organization keeps to its security policy and to its topic policies, rules and standards is to be checked regularly. Purpose: confirm that security is put in place and operated the way the top policy and the topic policies, rules and standards demand. Guidance: managers and owners of services, products or information work out how to check that what the policies, rules, standards and any applicable regulations require is actually happening, and should consider automated measurement and reporting tools to make regular review efficient. When non-compliance is found they identify its causes, assess whether corrective action is needed, implement suitable action, and review that action to confirm it worked and to spot any remaining weaknesses. The results of reviews and corrective actions are recorded and the records kept, and managers pass them to independent reviewers (5.35) when an independent review covers their area. Corrective actions are completed promptly in proportion to risk, and any not finished by the next scheduled review are at least followed up there. Monitoring how systems are used day to day falls under 8.15 to 8.17.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 142 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 16 controls

ISO 22301:2019 · 13 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 4.4 Business continuity management system
  • 5.2.1 Establishing the business continuity policy
  • 6.1.1 Determining risks and opportunities
  • 6.2 Business continuity objectives and planning to achieve them
  • 7.5.3 Control of documented information
  • 8.3.1 General
  • 8.4.1 General
  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.2 Audit programme(s)
  • 9.3.2 Management review input

ISO 27701:2019 · 13 controls

  • 5.2.4 Information security management system
  • 5.4 Planning
  • 5.5 Support
  • 5.6 Operation
  • 5.6.3 Information security risk treatment
  • 5.7 Performance evaluation
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 6.6.3 User responsibilities
  • 8.5.4 Notification of PII disclosure requests

PCI DSS 4.0 · 11 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 5.1.1 5.1.1 Requirement 5 policies and procedures maintained and communicated
  • 6.1.1 6.1.1 Requirement 6 policies and procedures maintained and communicated
  • 9.1.1 9.1.1 Requirement 9 policies and procedures maintained
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

SOC 2 · 9 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-PI1.2 PI1.2 Controls over system inputs
  • SOC2-PI1.3 PI1.3 Controls over system processing
  • SOC2-PI1.4 PI1.4 Controls over output delivery

CIS Controls v8 · 6 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-18.4 Validate Security Measures
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure

FedRAMP High · 5 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SI-11 Error Handling

FedRAMP Moderate · 5 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SI-11 Error Handling

ISO/IEC 42001:2023 · 5 controls

  • 10.1 Continual improvement
  • 6.1.3 AI risk treatment
  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.4 AI system verification and validation
  • A.9.4 Intended use of the AI system

APRA CPS 234 · 4 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-28 Escalation of Unremediated Testing Deficiencies

MTCS (Singapore) · 4 controls

  • 10.3 Compliance with policies and standards
  • 10.7 Continuous compliance monitoring
  • 14.10 Enforcement checks
  • A.21 Disclosure: Security configuration enforcement checks
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • ISM-1478 Oversight of cyber security program and compliance
  • ISM-1526 Continuous security monitoring by system owners
  • ISM-1587 Annual reporting of system security status
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations

CMMC 2.0 · 3 controls

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities

C5 (Germany) · 2 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-SP-03 Exceptions from Existing Policies and Instructions

DORA · 2 controls

HIPAA Security Rule · 2 controls

NIS2 Directive · 2 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-171 Rev 3 · 2 controls

  • A.8.2 A.8.2 Periodic evaluation of compliance
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AEO-13 Measurement, Analyses and Improvement

GDPR · 1 control

  • TSA-SD-18 Performance based outcome measurement

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.36 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 142 it maps to, and the evidence behind each claim, over MCP and REST.