A.5.36 Compliance with Policies, Rules and Standards for Information Security
Control Objective
Compliance with the organisation’s information security policy, topic-specific policies, rules and standards shall be regularly reviewed.
Policy Statement
anDREa enforces a multi-layered review structure to ensure continuous alignment with our overarching information security policy, topic-specific standards, and regulatory obligations. Compliance is evaluated through formal executive governance, automated and manual asset checks, and structured effectiveness metrics.
Compliance Review Framework
Compliance validation is executed across three distinct operational layers:
- Executive Oversight: The Director annually drafts the Security Management Report. This comprehensive document assesses organizational compliance across all operational and technical domains. The Management Team must review and sign off on this document with an official Management Response, which is integrated directly into the final report.
- Operational Asset Verification: Assigned Asset Owners periodically execute manual and automated compliance checks. These reviews validate access rights and configuration baselines in strict accordance with A.05.15 - Access control, A.06.07 - Remote working, and A.7 Physical Controls.
- Control Performance Metrics: The operational performance of individual policies and security controls is continually tracked, analyzed, and measured for efficiency (see: Information Security Performance).