Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 27002

Information Security, Cybersecurity and Privacy Protection - Security Controls

Management Systems Published: 2022

ISO 27002:2022 at a glance

Current edition
ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection — Information security controls
Published
2022
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/IEC 27002:2013
Official ISO page
View ISO 27002:2022 on iso.org
Last verified

Overview

The implementation guidance companion to ISO/IEC 27001. It describes 93 information security controls in four themes, each with purpose, guidance and attributes, and is not itself a certifiable standard.

ISO/IEC 27002:2022, Information security, cybersecurity and privacy protection — Information security controls, is the guidance companion to ISO/IEC 27001. It is the third edition and cancels and replaces ISO/IEC 27002:2013. Where ISO/IEC 27001 Annex A lists the controls by title, ISO/IEC 27002 explains each one: its purpose, what implementing it involves, and other information worth knowing.

The 2022 edition reorganised the control set into 93 controls under four themes — organizational, people, physical and technological — replacing the fourteen security clauses of the 2013 edition. The restructuring merged overlapping controls and introduced eleven new ones covering threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

A significant addition is the attribute table. Each control is tagged with attributes: control type (preventive, detective, corrective), the information security properties it protects (confidentiality, integrity, availability), the cybersecurity concept it relates to (identify, protect, detect, respond, recover), operational capability (such as governance, asset management, identity and access management, application security), and security domain (governance and ecosystem, protection, defence, resilience). Attributes let an organization filter and sort the control set to build views that match its own framework or reporting needs — for example, mapping to a cybersecurity framework, or producing a view of all detective controls.

Each control entry follows a consistent layout: the control statement itself, its purpose, guidance on implementation, and other information such as related standards or considerations. This makes it usable both as an implementation manual and as an audit reference when judging whether a control has been implemented meaningfully rather than nominally.

ISO/IEC 27002 is guidance and is not certifiable. Organizations certify to ISO/IEC 27001. ISO/IEC 27002 is not a requirements document, and controls in it are selected on the basis of the organization's own risk assessment, not adopted wholesale. The correct sequence is: assess risk, determine necessary controls, compare against ISO/IEC 27001 Annex A, then use ISO/IEC 27002 to implement the controls chosen.

The standard is also used independently of certification — by organizations that want a comprehensive, well-maintained control catalogue without operating a formal ISMS, and by those developing internal or sector-specific security guidelines. Related documents extend it for particular contexts, including ISO/IEC 27017 for cloud services and ISO/IEC 27018 for personally identifiable information in public clouds.

Purpose

To provide a reference set of generic information security controls with implementation guidance, for use by organizations implementing an information security management system based on ISO/IEC 27001, implementing commonly accepted information security controls, or developing their own control guidelines.

Key Benefits

  • Explains the purpose and implementation of every control referenced in ISO/IEC 27001 Annex A
  • Provides a comprehensive, maintained catalogue of generic information security controls
  • Attributes allow the control set to be filtered and mapped to other frameworks
  • Covers modern topics including cloud services, threat intelligence, data masking and secure coding
  • Supports consistent judgement about whether a control is genuinely implemented
  • Usable without certification by organizations building internal security guidelines
  • Provides a common reference for supplier security requirements and assessments
  • Extended for specific contexts by ISO/IEC 27017 (cloud) and ISO/IEC 27018 (PII in public clouds)

Key Requirements

  • Guidance only — ISO/IEC 27002 contains recommendations, not auditable requirements
  • Select controls on the basis of an information security risk assessment, not by adopting the catalogue wholesale
  • Implement organizational controls covering policies, roles, asset management, supplier relationships, incident management and compliance
  • Implement people controls covering screening, terms of employment, awareness, disciplinary process and remote working
  • Implement physical controls covering perimeters, entry, monitoring, equipment, media and clear desk and screen
  • Implement technological controls covering endpoints, privileged access, authentication, cryptography, logging, monitoring, network security, secure development and configuration
  • Use the control attributes to build views appropriate to the organization's reporting and framework needs
  • Document justification for controls implemented and not implemented in the Statement of Applicability under ISO/IEC 27001
  • Review controls periodically against changing threats, technology and business context

Who Needs This Standard?

Information security managers, CISOs, security architects and engineers implementing or reviewing controls; ISO/IEC 27001 implementers and internal auditors; IT and cloud operations teams; risk and compliance functions writing internal security policy; and consultants and assessors who need a common reference for what a control is supposed to achieve.

Where to get ISO 27002

The full text of ISO 27002 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27002 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 27002, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 27002 — it is guidance, and no accredited scheme exists for it. The closest standard you can certify against is ISO 27001 (Information Security Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with it. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards