Skip to main content

Glossary category

Compliance Processes

The recurring processes that turn policy into evidence: the ISMS, the Statement of Applicability, internal audits, and management reviews.

Compliance is not a one-time exercise. It is a set of recurring processes that turn policy into evidence over a calendar year. The ISMS is the management system itself, the umbrella under which every compliance activity at your organisation gets scheduled, recorded, and reviewed. The Statement of Applicability is the document that ties each ISO 27001 Annex A control to your specific decision to use it or exclude it. Internal audits, management reviews, risk reassessments, and corrective actions all sit underneath. The shorthand "compliance work" is mostly these processes running on a cadence.

Terms in this category.

9 entries.