Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.5.36 Compliance with Policies, Rules and Standards for Information Security

Control Objective

Compliance with the organisation’s information security policy, topic-specific policies, rules and standards shall be regularly reviewed.

Policy Statement

anDREa enforces a multi-layered review structure to ensure continuous alignment with our overarching information security policy, topic-specific standards, and regulatory obligations. Compliance is evaluated through formal executive governance, automated and manual asset checks, and structured effectiveness metrics.


Compliance Review Framework

Compliance validation is executed across three distinct operational layers:

  • Executive Oversight: The Director annually drafts the Security Management Report. This comprehensive document assesses organizational compliance across all operational and technical domains. The Management Team must review and sign off on this document with an official Management Response, which is integrated directly into the final report.
  • Operational Asset Verification: Assigned Asset Owners periodically execute manual and automated compliance checks. These reviews validate access rights and configuration baselines in strict accordance with A.05.15 - Access control, A.06.07 - Remote working, and A.7 Physical Controls.
  • Control Performance Metrics: The operational performance of individual policies and security controls is continually tracked, analyzed, and measured for efficiency (see: Information Security Performance).