Secure Controls Framework
Download The SCF

What is ISO 27002?

Direct Answer

ISO/IEC 27002:2022 is the companion code of practice to ISO 27001. While ISO 27001 specifies what you must do (management system requirements), ISO 27002 provides guidance on how to implement the Annex A controls. ISO 27002 is not a certifiable standard - it is a reference for implementing controls. The 2022 update aligned ISO 27002 with the new 93-control Annex A structure.

Detailed Answer

ISO/IEC 27002:2022 gives implementation guidance for the 93 information security controls listed in ISO/IEC 27001:2022 Annex A. For each control it explains the purpose and offers guidance on how to put it in place.

The 2022 edition groups the controls into four themes: organizational (37), people (8), physical (14) and technological (34).

Organizations certify against ISO 27001, not ISO 27002; ISO 27002 helps decide how to implement the controls chosen in the Statement of Applicability. The SCF maps ISO 27002 to SCF controls, so the same implementation can support other frameworks.