ISO/IEC 27002

ISO 27002,
the control catalogue explained

ISO/IEC 27002 is the reference set of information security controls, with guidance on how to implement each one. It is not a certificate, and nobody audits you against it directly. Here is what the 2022 edition contains: 93 controls in four themes, the eleven added ones, the attributes that let you filter and map them, and how teams turn the guidance into one control set that serves ISO/IEC 27001 and every framework after it.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The guidance

What ISO/IEC 27002 actually is

ISO/IEC 27002 is a code of practice: a catalogue of controls, each with a purpose and detailed implementation guidance, that organizations draw on when building an ISMS. It is the source of the ISO/IEC 27001 Annex A control set, and the layer you read when the question is not which control but how.

A catalogue, not a certificate

There is no ISO 27002 certificate. You certify against ISO/IEC 27001; 27002 is the reference you use to implement the controls that certification asks about.

Four themes, 93 controls

Organizational, people, physical and technological controls, each with a control statement, a purpose and implementation guidance written for the people doing the work.

Five attributes on every control

Control type, security properties, cybersecurity concepts, operational capabilities and security domains, so one catalogue can be filtered and mapped in several ways.

The base other standards build on

ISO/IEC 27017 and 27018 extend it for the cloud, and its cybersecurity concepts line up with NIST CSF, which is what makes one control set reusable across frameworks.

The full picture

ISO/IEC 27002, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What is ISO/IEC 27002?

ISO/IEC 27002 is the international reference for information security controls. Where ISO/IEC 27001 tells you that an information security management system must select and operate controls, 27002 is the book those controls come from: for each one it gives a short control statement, the purpose it serves, and several paragraphs of guidance on how to implement it in practice. The current edition is ISO/IEC 27002:2022.

It is a code of practice, not a requirements standard. That is the single fact that shapes everything else. Nobody is certified against ISO 27002, no accredited body audits against it, and a customer who asks whether you are 27002 certified is really asking about your ISO/IEC 27001 scope. What 27002 gives you is depth: the difference between knowing you need a control for information deletion and knowing what a defensible deletion practice looks like.

In daily use it is the layer engineers and security leads actually open. The management clauses of ISO/IEC 27001 are read once and written into a manual; the control guidance in 27002 is read again every time a control is designed, reviewed, questioned by an auditor or explained to a new hire. If Annex A is the table of contents, 27002 is the book.

02

What changed in the 2022 edition

The 2022 edition was the first full rewrite in almost a decade, and the change is structural rather than cosmetic. The 2013 edition listed 114 controls across 14 domains, organized by topic such as access control or supplier relationships. The 2022 edition consolidates those into 93 controls in four themes, and adds an attribute table to every control so the same list can be viewed from several angles.

Fewer controls does not mean less coverage. Most of the reduction comes from merging controls that had drifted into near duplicates, and from renaming others to say what they actually mean. A team that mapped its practice to the 2013 set will find nearly everything still present, just filed differently, which is why the transition mostly meant re-mapping rather than re-implementing.

The more interesting change is what was added. Eleven controls are genuinely new, and together they read like a list of what security practice learned in the intervening years: cloud services, threat intelligence, data leakage and secure coding were barely visible in 2013 and are unavoidable now.

The eleven new controls

The additions are threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. None of them will surprise a modern security team, but each one now has a formal home, a purpose statement and guidance, and each one appears in the ISO/IEC 27001 Annex A that certification audits check against.

03

The four themes

Every control in the 2022 edition sits in one of four themes. Organizational controls are the largest group at 37: policies, roles, supplier relationships, incident management, compliance and the other things that are decided rather than configured. People controls, eight in total, cover screening, terms of employment, awareness and training, disciplinary process and remote working. Physical controls, fourteen of them, cover perimeters, entry, equipment, cabling and clear desks. Technological controls, 34 in all, are where access, cryptography, logging, backups, network security and secure development live.

The themes replace the 2013 domains and are deliberately coarser. A domain like access control used to hold everything from policy to password management; in 2022 the policy piece sits under organizational controls and the technical enforcement under technological ones. It takes a little getting used to, but it maps more honestly onto who owns what: the organizational theme is usually the CISO and management, the technological theme is engineering and IT.

For a small team the practical value of the themes is prioritization. The technological theme is closest to the systems engineers already work in and tends to have the most evidence available automatically; the organizational theme is where policies and reviews have to be written and run. Knowing which theme a gap belongs to tells you who has to close it.

04

The five attributes, and why they matter

The quiet innovation of the 2022 edition is the attribute table on every control. Each control is tagged along five dimensions: control type (preventive, detective or corrective), the information security properties it protects (confidentiality, integrity, availability), the cybersecurity concept it serves (identify, protect, detect, respond, recover), the operational capability it belongs to (governance, asset management, identity and access management and so on), and the security domain (governance and ecosystem, protection, defence, resilience).

Attributes turn a flat list into something you can query. Want every detective control you run? Filter by control type. Need to show a board what covers availability? Filter by security property. The cybersecurity concepts are lifted directly from the NIST CSF functions, which is not an accident: it lets a team present the same control set to a US customer who thinks in NIST terms and to a European auditor who thinks in ISO terms without maintaining two lists.

Most teams ignore the attributes on first reading and come back to them later, when a second framework arrives or an auditor asks a cross-cutting question. Recording them from the start costs almost nothing, because the standard has already assigned them; it is a matter of keeping them next to the control in whatever system holds your control set.

05

How to use ISO 27002 in practice

The most common use is as the how-to layer behind an ISO/IEC 27001 Statement of Applicability. Annex A lists the controls; 27002 explains them. When you decide a control applies, the 27002 guidance is what you turn into a policy, a procedure or a technical configuration, and it is what you compare your implementation against when you ask whether it is good enough.

The second use is as a control catalogue in its own right. Teams that are not yet pursuing certification, or that need a structured baseline before deciding which framework to adopt, often take 27002 as the starting control set: it is comprehensive, vendor-neutral, and every control comes with enough guidance to implement without a consultant. Because Annex A is derived from it, that work carries straight into certification later.

The third use is translation. Because 27002 controls are well defined and widely referenced, other frameworks map onto them: SOC 2 criteria, NIST CSF subcategories, the NIS2 risk-management measures and the cloud extensions in ISO/IEC 27017 and 27018 all cross-reference the 27002 set. A team that maintains its controls at 27002 granularity can answer most of those frameworks from one place.

06

ISO 27002 and the other frameworks

ISO/IEC 27001 is the obvious neighbour: its Annex A is the 27002 control list with the guidance removed, and the two editions are published together. ISO/IEC 27017 and 27018 are the cloud extensions, taking the 27002 controls and adding cloud-specific guidance and a few cloud-only controls; you cannot read either without 27002 underneath.

Beyond the ISO family the overlaps are looser but real. SOC 2 Trust Services Criteria cover most of the same ground from an attestation angle. NIST CSF organizes outcomes rather than controls, but the 2022 cybersecurity concepts were chosen to line up with its five original functions. The NIS2 Directive names ten risk-management measures that each correspond to a cluster of 27002 controls.

The practical consequence is that 27002 makes a good spine. Maintain one control set at that level of detail, record which control satisfies which requirement in each framework you adopt, and the evidence you keep for one serves the others. That is the difference between running four frameworks and running one control set with four views.

07

Moving from the 2013 control set

Organizations certified against ISO/IEC 27001:2013 had until the end of October 2025 to transition to the 2022 edition, which means moving their Statement of Applicability and control implementation onto the 93-control set. Most of that work is a mapping exercise: the standard itself includes a correspondence between old and new controls, and the merges are documented.

The eleven new controls are where the real effort sits. Each needs a decision on applicability, and where it applies, an implementation and evidence. Teams that had already adopted cloud security, threat intelligence or data loss prevention in practice mostly needed to write down what they were doing; teams that had not found the new controls to be genuine gaps.

08

Keeping a control set current

A control catalogue is only useful while it matches reality. Controls get implemented, changed, partly retired or quietly replaced by a new tool, and the description in the policy drifts away from what actually runs. The 27002 guidance does not stop that drift; a review cadence does. Each control needs an owner, a review date and a place where the current evidence lives.

The teams that find 27002 easy are the ones that treat it as a living index rather than a document they read once. Keep the control set, the policies that implement it, the risks that justify it and the evidence that proves it in one place, and the catalogue becomes the map of your security programme instead of a standard on a shelf.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your ISO 27002 control set, in one workspace

Adopt the 93 controls as a catalogue, decide what applies, and connect each one to the policies, risks and evidence that implement it. Pick one to see it.

All 93 controls, with their attributes

See every ISO/IEC 27002 control by theme, filter by control type or cybersecurity concept, and record what applies and what is implemented, so the answer to what covers availability is a filter rather than a spreadsheet.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO/IEC 27002 is the control set most other frameworks cross-reference. Implement a control once in devguard, keep its evidence current, and the same policy and proof satisfy ISO/IEC 27001 Annex A, the cloud extensions and the frameworks you add later.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already running a control set? Move it across

If you already maintain your controls against ISO/IEC 27002, in a spreadsheet, a wiki or another tool, you do not want to re-enter 93 controls and their history. In a scoped conversation we agree exactly what moves (your control set, applicability decisions, policies, risk links and evidence) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO/IEC 27002 FAQ

ISO/IEC 27002, answered plainly.

Can I get certified against ISO 27002?

No. ISO/IEC 27002 is a code of practice, a catalogue of controls with implementation guidance, and there is no certificate for it. Certification is against ISO/IEC 27001, whose Annex A lists the same controls. When a customer asks about ISO 27002, the honest answer is your ISO 27001 scope and how you implement the controls in it.

How many controls are in ISO 27002:2022?

93, in four themes: 37 organizational, eight people, fourteen physical and 34 technological. The 2013 edition had 114 controls in 14 domains; the reduction comes from merging and renaming, plus eleven controls that are new in 2022.

What are the eleven new controls?

Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Each one also appears in the ISO/IEC 27001 Annex A control set.

What are the attributes on each control?

Five tags the 2022 edition assigns to every control: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They let you filter and group the catalogue, and the cybersecurity concepts line up with the NIST CSF functions, which makes cross-framework mapping much easier.

Do I need ISO 27002 if I am pursuing ISO 27001?

In practice, yes. Annex A gives you the list of controls but not how to implement them; 27002 is the guidance you read when designing each one and the reference an auditor expects your implementation to resemble. Many teams work from 27002 first and let the Statement of Applicability follow.

Can I use ISO 27002 without pursuing certification?

Yes, and many teams do. It is a complete, vendor-neutral control baseline that stands on its own as a way to structure a security programme. Because ISO/IEC 27001 Annex A is derived from it, the work carries straight into certification if you decide to pursue it later.

See how your ISO 27002 control set would look in devguard.

The fastest way to know if this fits is a short conversation about how you maintain your controls today: where the catalogue lives, how applicability is decided, and what moving it would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free