GlossaryISO 27001

ISO 27002

Short answer

ISO 27002 is the companion standard to ISO 27001 that gives detailed guidance on how to implement each information security control. It cannot be certified on its own: organisations certify against ISO 27001 and use ISO 27002 to understand and apply its Annex A controls.

How it relates to ISO 27001

ISO 27001 sets the requirements for an information security management system and lists the reference controls in its Annex A, with one line for each. ISO 27002 takes the same controls and explains their purpose, how to implement them and what to consider. Auditors and implementers use it to interpret what a control really asks for.

The 2022 version

ISO 27002:2022 reorganised the controls from 114 in 14 domains into 93 grouped in four themes: organisational, people, physical and technological. It merged several controls and added 11 new ones, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities and secure coding.

Attributes

Each control now carries attributes, such as control type (preventive, detective, corrective) and the cybersecurity concepts it supports (identify, protect, detect, respond, recover). They help map controls to other frameworks like the NIST CSF or build views for different audiences.

How companies use it

It is the practical reference when writing policies, preparing the Statement of Applicability and checking that controls are implemented in a way an auditor will accept. The standard is sold by ISO and by national bodies such as UNE in Spain.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub