What is ISO/IEC 27002?
ISO/IEC 27002 is the international reference for information security controls. Where ISO/IEC 27001 tells you that an information security management system must select and operate controls, 27002 is the book those controls come from: for each one it gives a short control statement, the purpose it serves, and several paragraphs of guidance on how to implement it in practice. The current edition is ISO/IEC 27002:2022.
It is a code of practice, not a requirements standard. That is the single fact that shapes everything else. Nobody is certified against ISO 27002, no accredited body audits against it, and a customer who asks whether you are 27002 certified is really asking about your ISO/IEC 27001 scope. What 27002 gives you is depth: the difference between knowing you need a control for information deletion and knowing what a defensible deletion practice looks like.
In daily use it is the layer engineers and security leads actually open. The management clauses of ISO/IEC 27001 are read once and written into a manual; the control guidance in 27002 is read again every time a control is designed, reviewed, questioned by an auditor or explained to a new hire. If Annex A is the table of contents, 27002 is the book.