{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://cmaintz.github.io/tech-atlas/)"},"id":"security/iso-27002","url":{"en":"https://cmaintz.github.io/tech-atlas/en/terms/security/iso-27002/","da":"https://cmaintz.github.io/tech-atlas/da/terms/security/iso-27002/"},"term":{"en":"ISO 27002","da":"ISO 27002"},"aka":{"en":["ISO/IEC 27002"],"da":["ISO/IEC 27002"]},"domain":["security"],"cluster":"compliance","layer":"governance","status":"current","era":2007,"summary":{"en":"A guidance standard describing each security control in detail - what it is for and how to put it in place.","da":"En vejledende standard, der beskriver hver sikkerhedskontrol i detaljer - hvad den skal og hvordan den indføres."},"body":{"formal":{"en":"A companion standard to ISO 27001, current edition 2022, that gives the purpose of the same 93 controls and guidance on putting them in place, grouped into four themes - organisational, people, physical and technological; it contains no requirements and cannot be certified against.","da":"En følgestandard til ISO 27001, nuværende udgave fra 2022, der giver formål og vejledning for de samme 93 kontroller, fordelt på fire temaer - organisatoriske, menneskelige, fysiske og teknologiske; den stiller ingen krav og kan ikke bruges til certificering."},"plain":{"en":"If the house rules say \"keep the house safe\", this is the handyman's manual explaining which locks, alarms and smoke detectors to fit and where.","da":"Hvis husordenen siger \"hold huset sikkert\", er det her håndværkerens manual, der forklarer, hvilke låse, alarmer og røgalarmer der skal sættes op, og hvor."},"inPractice":{"en":"The IT security lead at a Danish hospital drafts the rules for who may open patient records by working through the ISO 27002 guidance on access control and adapting each point to the hospital's systems.","da":"Den IT-sikkerhedsansvarlige på et dansk hospital skriver reglerne for, hvem der må åbne patientjournaler, ved at gå ISO 27002's vejledning om adgangskontrol igennem og tilpasse hvert punkt til hospitalets systemer."},"whyItMatters":{"en":"A one-line control title says what to achieve but not how; without the guidance each organisation would have to work out every control from scratch and would often miss key parts.","da":"En kontroloverskrift på én linje siger, hvad man skal opnå, men ikke hvordan; uden vejledningen skulle hver organisation selv udtænke hver kontrol fra bunden og ville ofte overse vigtige dele."}},"deepDive":{"en":"The 2022 edition, retitled \"Information security, cybersecurity and privacy protection - Information security controls\", replaced the 114 controls in 14 clauses of the 2013 edition with 93 controls in four themes: organisational (clause 5, 37 controls), people (clause 6, 8), physical (clause 7, 14) and technological (clause 8, 34). Every control follows the same template: a control statement, a purpose, guidance and other information. The control statements are the same short texts that appear in ISO/IEC 27001 Annex A, so the Annex A entry says what, and the 27002 entry explains why and how.\n\nEleven controls were new in 2022: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering and 8.28 secure coding. Many older controls were merged rather than removed; Annex B of the standard maps each 2022 control back to its 2013 predecessors, which is what organisations used when moving their SoA to the new edition.\n\nA second structural addition is attributes, hashtag-style tags that let the same controls be viewed in different ways: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts (#Identify, #Protect, #Detect, #Respond, #Recover, borrowed from the NIST CSF functions), operational capabilities and security domains. Annex A of 27002 explains how to filter by them, for example to list all detective controls that support availability, and organisations may define their own attributes.\n\nBecause it is guidance, 27002 uses \"should\" throughout and cannot be certified against; an auditor assesses the organisation against 27001 and uses 27002 as a reference for what a reasonable implementation looks like. A common mistake is treating the guidance text as a checklist that must be followed word for word, when the actual obligation is the risk-based selection documented in the SoA. Sector documents such as ISO/IEC 27017 (cloud), 27018 (personal data in public clouds) and 27019 (energy utilities) extend the controls with sector-specific guidance, while the CIS Controls offer a more prescriptive, prioritised set of technical safeguards that can sit underneath the technological theme.","da":"2022-udgaven, med den nye titel \"Information security, cybersecurity and privacy protection - Information security controls\", erstattede 2013-udgavens 114 kontroller i 14 afsnit med 93 kontroller i fire temaer: organisatoriske (afsnit 5, 37 kontroller), menneskelige (afsnit 6, 8), fysiske (afsnit 7, 14) og teknologiske (afsnit 8, 34). Hver kontrol følger samme skabelon: en kontroltekst, et formål, vejledning og øvrig information. Kontrolteksterne er de samme korte formuleringer, som står i ISO/IEC 27001 anneks A, så anneks A siger hvad, mens 27002 forklarer hvorfor og hvordan.\n\nElleve kontroller var nye i 2022: 5.7 trusselsefterretninger, 5.23 informationssikkerhed ved brug af cloudtjenester, 5.30 IKT-parathed til driftskontinuitet, 7.4 overvågning af fysisk sikkerhed, 8.9 konfigurationsstyring, 8.10 sletning af information, 8.11 datamaskering, 8.12 forebyggelse af datalæk, 8.16 overvågningsaktiviteter, 8.23 webfiltrering og 8.28 sikker kodning. Mange ældre kontroller blev slået sammen frem for fjernet; standardens anneks B kobler hver 2022-kontrol til sine forgængere fra 2013, og det var den kobling, organisationerne brugte, da de flyttede deres SoA til den nye udgave.\n\nEn anden strukturel nyskabelse er attributter, tags i hashtag-form, der gør det muligt at se de samme kontroller fra forskellige vinkler: kontroltype (#Preventive, #Detective, #Corrective), informationssikkerhedsegenskaber (#Confidentiality, #Integrity, #Availability), cybersikkerhedsbegreber (#Identify, #Protect, #Detect, #Respond, #Recover, lånt fra funktionerne i NIST CSF), operationelle kapabiliteter og sikkerhedsdomæner. Anneks A i 27002 forklarer, hvordan man filtrerer på dem, fx for at finde alle detekterende kontroller, der understøtter tilgængelighed, og organisationer kan definere deres egne attributter.\n\nFordi det er vejledning, bruger 27002 \"bør\" hele vejen igennem og kan ikke bruges til certificering; auditoren vurderer organisationen efter 27001 og bruger 27002 som reference for, hvordan en rimelig implementering ser ud. En udbredt fejl er at behandle vejledningsteksten som en tjekliste, der skal følges ord for ord, når den egentlige forpligtelse er det risikobaserede valg, der dokumenteres i SoA'en. Sektordokumenter som ISO/IEC 27017 (cloud), 27018 (personoplysninger i offentlige clouds) og 27019 (energiforsyning) udvider kontrollerne med sektorspecifik vejledning, mens CIS Controls tilbyder et mere foreskrivende, prioriteret sæt tekniske sikringer, der kan ligge under det teknologiske tema."},"edges":[{"type":"requires","to":"security/control","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/security-framework","confidence":"high","strength":"normal"},{"type":"part-of","to":"security/iso-27000-series","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/risk-treatment","why":{"en":"When treating a risk, teams pick fitting controls and use the guidance to put them in place.","da":"Når en risiko skal håndteres, vælger man passende kontroller og bruger vejledningen til at indføre dem."},"confidence":"high","strength":"normal"},{"type":"used-with","to":"security/security-policy","confidence":"medium","strength":"minor"},{"type":"used-with","to":"security/statement-of-applicability","why":{"en":"The SoA lists the Annex A controls that ISO 27002 explains in detail.","da":"SoA'en gennemgår de kontroller i anneks A, som ISO 27002 forklarer i detaljer."},"confidence":"high","strength":"normal"}],"depth":5,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"ISO/IEC 27002:2022","tier":"standard","publisher":"ISO/IEC"}],"draft":true}