A.5.36 Organizational
Compliance with policies, rules and standards for information security
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CA-2mostlyaligns with — Both controls require periodic assessment of security controls against defined requirements and the documentation of findings.
- CA-5mostlyaligns with — Both controls mandate the identification, tracking, and timely completion of corrective actions to address deficiencies discovered during reviews.
- AU-6partialaligns with — Both controls require the review and analysis of evidence to determine whether security requirements are being met and to report results.
- CA-7partialaligns with — Both controls emphasize ongoing monitoring and review of security control effectiveness, including the use of automated mechanisms where feasible.
- SI-2partialaligns with — Both controls require the identification of non-conformities, determination of root causes, and implementation of corrective actions to restore compliance.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.OV-03mostlyaligns with — The ISO control's requirement to review policy compliance, identify root causes of deviations, and implement corrective actions directly supports evaluating and adjusting organizational cybersecurity risk management performance.
- ID.IM-01mostlyaligns with — By mandating regular reviews of policy adherence and follow-up corrective actions, the control provides a structured mechanism for identifying improvements from evaluations of security controls.
- GV.PO-02partialaligns with — The control's emphasis on reviewing compliance with policies and enforcing corrective actions when deviations occur helps ensure policies remain effective and are updated to reflect changing requirements.
- GV.RR-02partialaligns with — Assigning managers and owners the responsibility to review compliance and drive corrective actions reinforces the establishment and communication of clear roles for cybersecurity risk management.
- ID.IM-03partialaligns with — The ISO requirement to detect non-compliance during operational reviews and apply corrective actions aligns with identifying improvements from the execution of day-to-day security processes and procedures.
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (11)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1076partialfinds — Directly requires compliance with rules and standards, which include coding and documentation conventions.
- CWE-284partialfinds — Periodic compliance reviews and corrective-action tracking detect and close gaps where access-control rules are not enforced, reducing the window in which improper access control can be exploited.
- CWE-285partialfinds — By requiring managers to verify that authorization decisions match policy and to remediate deviations, the control limits the persistence of incorrect or missing authorization checks.
- CWE-693partialfinds — Systematic verification that security mechanisms operate according to defined standards reduces the likelihood that protection mechanisms are bypassed or disabled.
- CWE-695partialfinds — Compliance monitoring verifies adherence to coding rules but does not prevent the weakness itself.
- CWE-710partialfinds — Enforces adherence to coding standards as part of policy compliance.
- CWE-732partialfinds — Regular policy-compliance audits surface incorrect or overly permissive file and resource permissions, prompting timely correction before they can be abused.
- CWE-507nonenone — Compliance monitoring can detect policy violations caused by Trojan Horse code but does not prevent it.
- CWE-778nonenone — Mandating documented reviews and recorded corrective actions ensures that security-relevant events and deviations are logged and retained, preventing insufficient logging.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialfinds — Ongoing policy-compliance reviews and corrective-action tracking surface and fix configuration drift or rule violations that would otherwise leave systems in an insecure state.
- A09partialfinds — The requirement to record review results and report them to independent reviewers directly supports the creation and retention of security-relevant logs needed for detection and response.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.