ISO 27002 Compliance
International code of practice providing detailed implementation guidance for information security controls referenced in ISO 27001 Annex A.
Overview
ISO 27002:2022 provides detailed implementation guidance for 93 information security controls organised across four themes. Organisational controls (37) cover governance, asset management, access control, and supplier management. People controls (8) address human resource security. Physical controls (14) cover premises and equipment security. Technological controls (34) span endpoint, network, application, and data security.
A key innovation in the 2022 edition is the attribute taxonomy, which tags each control with five attribute types. This allows organisations to view and filter controls by cybersecurity concept (identify, protect, detect, respond, recover), information security property (confidentiality, integrity, availability), control type (preventive, detective, corrective), operational capability, and security domain.
Each control entry includes a control title, attribute table, control description, purpose statement, guidance on implementation, and other information. This structured format provides consistent, actionable information for security practitioners implementing or reviewing controls.
ISO 27002 is designed to be used alongside ISO 27001 but is also valuable as a standalone reference. Organisations that are not pursuing certification can use it to benchmark their security practices, identify improvement areas, and implement controls based on international best practice.
Key Areas
- Organisational Controls - policies, roles, asset management, access control, supplier relationships, and compliance (37 controls)
- People Controls - screening, terms of employment, awareness, training, and disciplinary processes (8 controls)
- Physical Controls - physical security perimeters, entry controls, equipment security, and secure disposal (14 controls)
- Technological Controls - endpoint security, access rights, cryptography, secure development, and vulnerability management (34 controls)
- Threat Intelligence - gathering and analysing information about threats to inform security decisions
- Cloud Services Security - managing information security for cloud service use and provision
- Data Masking and Data Leakage Prevention - protecting sensitive data through masking and monitoring
- Monitoring Activities - detecting anomalous behaviour and potential security events across systems and networks
Who It's For
- Security practitioners responsible for implementing and managing information security controls
- Organisations implementing ISO 27001 seeking detailed guidance on Annex A controls
- IT managers and architects designing security architectures based on international best practice
- Auditors and assessors evaluating control implementation against ISO 27001 requirements
Core Requirements
- Policies and Governance
- Organisations should establish a suite of information security policies covering topics such as access control, data classification, acceptable use, and supplier management. Policies must be approved by management, communicated to relevant parties, and reviewed at planned intervals.
- Risk Management
- Controls should be selected based on a formal risk assessment as part of the ISO 27001 ISMS process. ISO 27002 provides guidance on evaluating control necessity based on identified risks, business requirements, and legal and contractual obligations.
- Security Controls
- The 93 controls span organisational, people, physical, and technological domains. Detailed implementation guidance covers areas including identity management, cryptography, network security, application security, supplier assurance, physical security, and incident management.
- Incident Response
- Controls address incident management planning, detection and reporting, assessment and decision-making, response activities, learning from incidents, and evidence collection. Organisations should establish clear roles and communication channels for incident handling.
- Evidence and Reporting
- Control implementation should be documented and evidenced. ISO 27002 recommends maintaining records of control operation, testing results, and reviews. Evidence supports both internal management reviews and external ISO 27001 certification audits.
Implementation Steps
- Scope and objectives - Identify the controls needed based on your ISO 27001 risk assessment and Statement of Applicability. Define the scope of implementation and establish objectives for each control area aligned with your organisation's risk profile and business requirements.
- Gap assessment - Evaluate your current implementation of the 93 controls against the guidance in ISO 27002. Identify gaps in policy coverage, technical implementation, staff awareness, physical security, and documentation. Prioritise remediation by risk level.
- Control implementation - Implement controls following the detailed guidance provided for each. Draft policies and procedures, configure technical controls, deliver training, secure physical premises, and establish supplier management processes. Use the attribute taxonomy to ensure comprehensive coverage.
- Evidence and documentation - Document control implementations, including rationale for design decisions. Collect operational evidence such as access review records, vulnerability scan reports, training completion records, and physical security logs. Maintain this evidence for audit purposes.
- Review and continuous improvement - Regularly review control effectiveness through testing, internal audits, and management reviews. Update controls as threats evolve, technology changes, or business requirements shift. Use the attribute taxonomy to identify areas needing attention across cybersecurity concepts.
Frequently Asked Questions
- Is ISO 27002 certifiable?
- No. ISO 27002 is a guidance standard, not a requirements standard. Organisations cannot be certified against ISO 27002. Certification is achieved against ISO 27001, with ISO 27002 providing the implementation guidance for Annex A controls.
- What changed in ISO 27002:2022?
- The 2022 revision reorganised controls from 14 domains into four themes (Organisational, People, Physical, Technological), reduced the count from 114 to 93 through merging, and added 11 new controls. An attribute taxonomy was introduced for filtering controls by cybersecurity concepts and operational capabilities.
- Do I need ISO 27002 if I am implementing ISO 27001?
- While not strictly mandatory, ISO 27002 is highly recommended. It provides the detailed guidance needed to understand, implement, and manage the controls referenced in ISO 27001 Annex A. Most implementation teams treat it as essential reading.
- What are the 11 new controls in the 2022 edition?
- New controls include threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
- How does the attribute taxonomy work?
- Each control is tagged with five attribute types: control type (preventive, detective, corrective), information security property (CIA), cybersecurity concept (identify, protect, detect, respond, recover), operational capability, and security domain. These attributes help organisations filter and analyse controls from different perspectives.
- Can ISO 27002 be used without ISO 27001?
- Yes. Organisations can use ISO 27002 as a standalone reference for improving their security practices without pursuing formal ISMS certification. The detailed control guidance is valuable as a benchmark or checklist regardless of certification status.
Why It Matters
- Organisations implementing ISO 27001 often struggle to translate the brief control statements in Annex A into practical, operational controls. ISO 27002 bridges this gap by providing detailed guidance, purpose statements, and implementation advice for each control. This reduces ambiguity and helps organisations implement controls consistently and effectively.
- The 2022 revision of ISO 27002 introduced attribute tagging for controls, allowing organisations to filter and view controls by cybersecurity concept (identify, protect, detect, respond, recover), security property (confidentiality, integrity, availability), and operational capability. This makes the standard more usable and supports mapping to other frameworks.
- ISO 27002 also serves as a standalone reference for organisations that want to improve their security posture without pursuing formal ISO 27001 certification. The detailed control descriptions can be used as a checklist or benchmark for evaluating and improving security practices across any organisation.
Common Challenges
- Translating the guidance into actionable procedures that fit the organisation's specific technology environment and operational context
- Managing the breadth of 93 controls across four themes without losing focus on the highest-risk areas
- Ensuring people controls (awareness, training, disciplinary processes) receive adequate attention alongside technical controls
- Keeping documentation current as controls are modified or the organisational environment changes
- Aligning ISO 27002 control implementations with overlapping requirements from other frameworks the organisation must satisfy
- Demonstrating the effectiveness of preventive and detective controls through meaningful metrics and evidence