How it relates to ISO 27001
ISO 27001 sets the requirements for an information security management system and lists the reference controls in its Annex A, with one line for each. ISO 27002 takes the same controls and explains their purpose, how to implement them and what to consider. Auditors and implementers use it to interpret what a control really asks for.
The 2022 version
ISO 27002:2022 reorganised the controls from 114 in 14 domains into 93 grouped in four themes: organisational, people, physical and technological. It merged several controls and added 11 new ones, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities and secure coding.
Attributes
Each control now carries attributes, such as control type (preventive, detective, corrective) and the cybersecurity concepts it supports (identify, protect, detect, respond, recover). They help map controls to other frameworks like the NIST CSF or build views for different audiences.
How companies use it
It is the practical reference when writing policies, preparing the Statement of Applicability and checking that controls are implemented in a way an auditor will accept. The standard is sold by ISO and by national bodies such as UNE in Spain.




