Skip to content
atlas

ISO 27002

Also known as: ISO/IEC 27002

A guidance standard describing each security control in detail - what it is for and how to put it in place.

Draft - this entry has not been reviewed yet.

Formal

A companion standard to ISO 27001, current edition 2022, that gives the purpose of the same 93 controls and guidance on putting them in place, grouped into four themes - organisational, people, physical and technological; it contains no requirements and cannot be certified against.

In plain English

If the house rules say "keep the house safe", this is the handyman's manual explaining which locks, alarms and smoke detectors to fit and where.

In practice

The IT security lead at a Danish hospital drafts the rules for who may open patient records by working through the ISO 27002 guidance on access control and adapting each point to the hospital's systems.

Why it matters

A one-line control title says what to achieve but not how; without the guidance each organisation would have to work out every control from scratch and would often miss key parts.

Technical deep dive

The 2022 edition, retitled "Information security, cybersecurity and privacy protection - Information security controls", replaced the 114 controls in 14 clauses of the 2013 edition with 93 controls in four themes: organisational (clause 5, 37 controls), people (clause 6, 8), physical (clause 7, 14) and technological (clause 8, 34). Every control follows the same template: a control statement, a purpose, guidance and other information. The control statements are the same short texts that appear in ISO/IEC 27001 Annex A, so the Annex A entry says what, and the 27002 entry explains why and how.

Eleven controls were new in 2022: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering and 8.28 secure coding. Many older controls were merged rather than removed; Annex B of the standard maps each 2022 control back to its 2013 predecessors, which is what organisations used when moving their SoA to the new edition.

A second structural addition is attributes, hashtag-style tags that let the same controls be viewed in different ways: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts (#Identify, #Protect, #Detect, #Respond, #Recover, borrowed from the NIST CSF functions), operational capabilities and security domains. Annex A of 27002 explains how to filter by them, for example to list all detective controls that support availability, and organisations may define their own attributes.

Because it is guidance, 27002 uses "should" throughout and cannot be certified against; an auditor assesses the organisation against 27001 and uses 27002 as a reference for what a reasonable implementation looks like. A common mistake is treating the guidance text as a checklist that must be followed word for word, when the actual obligation is the risk-based selection documented in the SoA. Sector documents such as ISO/IEC 27017 (cloud), 27018 (personal data in public clouds) and 27019 (energy utilities) extend the controls with sector-specific guidance, while the CIS Controls offer a more prescriptive, prioritised set of technical safeguards that can sit underneath the technological theme.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Security control
  9. →ISO 27002

Relationships

Alternative to
CIS Controls

Sources & further reading

Standards & official texts

  • ISO/IEC 27002:2022 · ISO/IEC

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.