ISO 27002: Guide to Information Security Controls
ISO/IEC 27002 is the companion standard to ISO 27001, providing detailed implementation guidance for each of the 93 controls listed in Annex A. While ISO 27001 defines what an ISMS must achieve, ISO 27002 explains how to implement each control effectively.
What ISO 27002 Covers
The 2022 revision restructured controls from 14 domains into four themes: organizational, people, physical, and technological. Each control includes implementation guidance, explanatory notes, and attributes such as control type, cybersecurity concept, and operational capability. This attribute-based taxonomy makes it far easier to map controls to other frameworks and filter by relevance.
New controls added in the 2022 edition address modern threats including threat intelligence, cloud service security, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
Who Needs ISO 27002
ISO 27002 is essential for anyone implementing ISO 27001. Security teams use it as a practical reference when designing controls, writing policies, and building procedures. Risk managers reference it when evaluating whether selected controls adequately address identified risks.
Organizations not pursuing ISO 27001 certification still benefit from ISO 27002 as a comprehensive control catalogue. It serves as a best-practice reference for building security programs regardless of whether formal certification is the goal.
How to Use ISO 27002
- Start with your risk assessment — Identify threats and vulnerabilities relevant to your organization
- Select applicable controls — Use the Statement of Applicability to determine which of the 93 controls apply
- Review implementation guidance — ISO 27002 provides detailed how-to for each control
- Adapt to your context — Tailor implementation guidance to your size, industry, and risk appetite
- Document decisions — Record why controls were selected or excluded
Relationship to ISO 27001
ISO 27002 does not carry its own certification. Organizations certify against ISO 27001, using ISO 27002 as the implementation guide. Auditors frequently reference ISO 27002 when evaluating whether controls meet the intent of Annex A requirements.
The Four Control Themes in Detail
Organizational controls (37 controls) address governance, policy, and process-level requirements. This includes information security roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, information security in project management, asset inventory, classification and labeling, acceptable use, information transfer, supplier relationships, incident management, privacy, and review processes. Organizational controls are the scaffolding that makes the rest of the ISMS coherent.
People controls (8 controls) focus on the human factor: background screening, terms of employment, awareness education, training programs, disciplinary procedures, responsibilities upon termination, confidentiality agreements, and remote working security. People controls are frequently underestimated in implementation planning. Auditors probe them closely because people remain the most common vector for security incidents.
Physical controls (14 controls) cover physical perimeters, entry mechanisms, office and equipment security, clear desk and screen policies, physical security monitoring, maintenance, secure disposal of assets, and protection of equipment outside premises. Cloud-native organizations must still address remote worker environments and device handling under this theme.
Technological controls (34 controls) is the largest theme. It encompasses endpoint device management, privileged access rights, source code access, authentication (including MFA), capacity management, vulnerability management, configuration management, web filtering, logging and monitoring, data leakage prevention, backup and recovery, redundancy, cryptography, and secure coding. Most of the technical implementation work concentrates here.
New Controls Added in the 2022 Edition
The 2022 revision introduced 11 new controls not present in ISO 27001:2013's Annex A. Organizations transitioning from the 2013 standard should pay particular attention to:
- Threat intelligence — Systematically gathering and acting on threat information relevant to your environment
- Information security for use of cloud services — Managing security across cloud providers you use, not just your own infrastructure
- ICT readiness for business continuity — Explicit continuity requirements for technology systems
- Physical security monitoring — Surveillance and detection requirements for physical access
- Configuration management — Formal management of secure configurations for hardware, software, and services
- Information deletion — Controlled deletion of information at end of retention periods
- Data masking — Protecting PII and sensitive data through masking and pseudonymization
- Data leakage prevention — Tools and policies to detect and prevent unauthorized data exfiltration
- Monitoring activities — Enhanced continuous monitoring of systems and networks
- Web filtering — Restricting access to malicious or inappropriate web content
- Secure coding — Embedding security into software development processes
Audit and Compliance Considerations
Because ISO 27002 is not itself certifiable, compliance teams use it differently depending on context. During ISO 27001 readiness, use ISO 27002 implementation guidance section by section as you build each control. During audits, auditors may reference ISO 27002 when assessing whether your control implementation meets the intent of a given Annex A requirement.
When comparing frameworks, ISO 27002:2022 shows approximately 75% overlap with NIST SP 800-53 Revision 5 and approximately 70% overlap with the CIS Controls v8.1. This makes it an excellent bridge document for organizations building a multi-framework compliance program.
Costs and Implementation Timeline
| Activity | Low Estimate | High Estimate |
|---|---|---|
| ISO 27002 documentation purchase | $200 | $200 |
| Gap analysis against all 93 controls | $3,000 | $15,000 |
| Implementation consulting / advisory | $5,000 | $30,000 |
| Compliance automation platform | $4,000 | $20,000 |
| Total (implementation, no certification) | $12,000 | $65,000 |
Timeline: 2 to 8 months depending on organization size and starting posture. No certification audit cost applies because ISO 27002 is assessed as part of ISO 27001 audits.
How Automation Helps
Compliance automation platforms pre-map their integrations and evidence types to ISO 27002 control numbers, making it easy to see which controls have automated evidence coverage and which require manual documentation.
LowerPlane supports the full ISO 27001:2022 Annex A — which is the same control set described in ISO 27002 — as part of its 50-plus framework library. At $4,000/year entry pricing with a free tier, it covers both the ISO 27001 certification path and the underlying ISO 27002 implementation guidance in a single platform. AuditXYZ rates it 9.4/10. See Best Compliance Automation Platforms for alternatives.
Frequently Asked Questions
Can I get certified to ISO 27002 on its own? No. ISO 27002 is a guidance standard, not a requirements standard. You cannot obtain an ISO 27002 certificate. Certification is against ISO 27001, which references ISO 27002 as its control implementation guide.
Do I need to implement all 93 controls? No. Your Statement of Applicability (required under ISO 27001) documents which controls apply to your context and which are excluded. Exclusions must be justified based on your risk assessment. The 11 new 2022 controls warrant careful evaluation — most organizations will find several applicable.
How does ISO 27002:2022 differ from the 2013 version? The 2022 edition restructured controls from 14 domains into 4 themes, reduced total controls from 114 to 93 (through merging), added 11 new controls, and introduced an attribute tagging system that makes it easier to filter controls by type, cybersecurity concept, and operational capability.
Is ISO 27002 free to download? No. Like all ISO standards, it is a paid publication available from ISO or your national standards body. The current edition (ISO/IEC 27002:2022) typically costs $150 to $250 USD depending on the format and vendor.
How does ISO 27002 compare to the CIS Controls? Both are control catalogues, but they serve different audiences. ISO 27002 is comprehensive and international, requiring adaptation to your specific context. CIS Controls are prioritized and prescriptive, with specific safeguards organized by implementation complexity. Many organizations use CIS Controls as their primary implementation reference and cross-reference to ISO 27002 for alignment with ISO 27001 certification requirements.