Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Security Frameworks

ISO/IEC 27002

Also known as: ISO 27002, ISO/IEC 27002:2022
Simply put

ISO/IEC 27002 is an international standard that offers guidance on selecting and implementing information security controls, such as policies, processes, and organizational measures. It is a voluntary reference document rather than a law, and organizations typically use it to help put good security practices into place. It is often used alongside ISO/IEC 27001, which sets the requirements for an information security management system.

Formal definition

ISO/IEC 27002 is a voluntary international standard published jointly by ISO and IEC that provides guidance on information security controls, including policies, rules, processes, procedures, organizational structures, and related measures used to achieve information security. It functions as a reference catalogue and implementation guidance rather than a certifiable requirements standard: certification is assessed against ISO/IEC 27001, while ISO/IEC 27002 supports the selection and implementation of controls within an ISMS built to ISO/IEC 27001. As a standard, it carries no legal force in itself and applies only where an organization adopts it voluntarily or is bound to it by contract; it should not be conflated with binding regulation. Readers should verify the current edition and version, as the standard (most recently referenced here as the 2022 revision) is periodically revised.

Why it matters

Information security controls are only effective when they are chosen deliberately and implemented consistently. ISO/IEC 27002 matters because it provides a widely recognized reference catalogue of controls and implementation guidance, helping organizations move from the abstract requirement to "secure information" toward concrete measures such as policies, processes, and organizational structures. For compliance and security teams, this shared vocabulary reduces ambiguity and supports more consistent decision-making about which controls are appropriate to a given environment.

Its practical significance is closely tied to its relationship with ISO/IEC 27001. Certification is assessed against ISO/IEC 27001, which sets the requirements for an information security management system (ISMS); ISO/IEC 27002 supports that effort by guiding the selection and implementation of controls within the ISMS. Organizations pursuing certification, or simply seeking to demonstrate mature security practices to customers and partners, commonly draw on ISO/IEC 27002 to justify and document their control choices.

It is important to keep the standard's status in perspective: ISO/IEC 27002 is voluntary guidance and carries no legal force in itself. It becomes binding only where an organization adopts it or is contractually obligated to follow it, and it should not be treated as a substitute for applicable regulation. Readers should also verify the current edition, as the standard is periodically revised.

Who it's relevant to

Information security professionals
Security teams responsible for designing and implementing controls can use ISO/IEC 27002 as a reference for selecting commonly accepted measures and understanding how policies, processes, and organizational structures fit together within an information security program.
Organizations pursuing or maintaining ISO/IEC 27001 certification
Because certification is assessed against ISO/IEC 27001 rather than ISO/IEC 27002, organizations building or operating an ISMS often rely on ISO/IEC 27002's guidance to inform and document how they select and implement the controls required by ISO/IEC 27001.
Compliance officers and auditors
Those evaluating an organization's security posture can use ISO/IEC 27002 as a common reference for control expectations. They should keep in mind that it is voluntary guidance, distinct from binding regulation, and applicable only where adopted or contractually required.
Legal counsel and contract managers
Where contracts reference ISO/IEC 27002, counsel should be aware that the standard has no independent legal force and takes on obligations only through such agreements or voluntary adoption. Verifying the referenced edition against the current authoritative text is advisable, as the standard is periodically revised.

Inside ISO/IEC 27002

Information security controls catalogue
ISO/IEC 27002 provides a catalogue of information security controls together with implementation guidance. It functions as a companion to ISO/IEC 27001, elaborating on the controls that organizations may select to address identified risks.
Control themes and attributes
The current edition organizes controls into thematic groupings and introduces attributes (such as control type, security properties, and operational capabilities) intended to help practitioners filter and categorize controls. Readers should confirm the exact structure against the version of the standard they are using, as the organization of controls has changed across editions.
Implementation guidance
For each control the standard offers descriptive guidance on purpose and possible means of implementation. This guidance is advisory in nature and is meant to inform, not dictate, how a control is applied in a given context.
Relationship to ISO/IEC 27001
ISO/IEC 27002 supports the Annex A controls referenced in ISO/IEC 27001 by expanding on them. ISO/IEC 27001 is the standard against which an information security management system (ISMS) may be certified; ISO/IEC 27002 provides the supplementary detail but is not itself the certification standard.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27002.

Is ISO/IEC 27002 a certifiable standard like ISO/IEC 27001?
No. Organizations are not certified against ISO/IEC 27002. It serves as a reference that provides guidance on information security controls, offering implementation advice and explanatory detail. Certification, where sought, is pursued against ISO/IEC 27001, which specifies the requirements for an information security management system. ISO/IEC 27002 supports the selection and implementation of controls but is not itself the basis for an accredited certificate. As with all standards, versions are periodically revised, so verify the current edition against the official ISO source.
Does adopting ISO/IEC 27002 make an organization legally compliant with data protection regulations such as the GDPR?
Not on its own. ISO/IEC 27002 is a voluntary standard, not a law, and adopting it does not by itself establish compliance with any binding regulation. Regulations such as the GDPR carry legal force independently of any standard, and their requirements are not satisfied merely by reference to a control framework unless a specific obligation is met in fact. In practice, aligning with ISO/IEC 27002 may support an organization's efforts to demonstrate appropriate security measures, but whether legal obligations are met is a fact-specific question that requires separate assessment. Application to particular circumstances calls for professional judgment.
How does ISO/IEC 27002 relate to ISO/IEC 27001 in practice?
The two standards are complementary and generally used together. ISO/IEC 27001 sets out the requirements for an information security management system and references a set of controls, while ISO/IEC 27002 provides detailed guidance on how those controls may be implemented and operated. In most cases, organizations use ISO/IEC 27001 to define what must be in place and ISO/IEC 27002 as a source of implementation guidance for individual controls. Because both documents are periodically amended and their control sets have been restructured across editions, confirm that the versions you rely on are aligned and current.
Do organizations need to implement every control described in ISO/IEC 27002?
Generally not. The standard presents a catalogue of controls with associated guidance, but selection is expected to be driven by an organization's risk assessment, context, and applicable obligations. Controls that are not relevant to identified risks may be excluded, and such decisions are typically documented and justified where an ISO/IEC 27001 management system is in place. The appropriate scope depends on factors such as the nature of the data, the threat environment, and organizational size, so implementation choices should be assessed against your specific circumstances.
How should ISO/IEC 27002 guidance be documented within a management system?
In practice, the guidance in ISO/IEC 27002 informs how controls are described, justified, and operated, but the documentation structure is typically governed by the requirements of ISO/IEC 27001 rather than by ISO/IEC 27002 itself. Organizations commonly record which controls apply, the rationale for inclusion or exclusion, and how each is implemented. Because documentation expectations and control references have changed across editions of the standards, verify the mapping against the current official texts and adapt records to the version in use.
How do organizations keep their use of ISO/IEC 27002 current as the standard changes?
Standards are periodically revised, and editions of ISO/IEC 27002 have restructured and renumbered controls, so ongoing alignment is a maintenance activity rather than a one-time exercise. Organizations generally monitor for new editions, reassess their control selection and implementation guidance against the updated text, and update related documentation and any linked ISO/IEC 27001 arrangements accordingly. To avoid relying on superseded content, confirm the edition you are working from against the latest authoritative source from ISO.

Common misconceptions

Organizations can be certified against ISO/IEC 27002.
Certification of an ISMS is generally pursued against ISO/IEC 27001, which contains the auditable requirements. ISO/IEC 27002 is a guidance document providing detail on controls and is not, on its own, the basis for certification. Practitioners should verify current scheme details with an accredited certification body.
ISO/IEC 27002 is a legal regulation that must be complied with.
ISO/IEC 27002 is a voluntary international standard, not a binding law. It carries no legal force in itself unless it is incorporated by contract or referenced by an applicable regulation. Any legal obligation depends on the relevant jurisdiction and agreements, which readers should assess separately.
All controls in ISO/IEC 27002 must be implemented in full.
The controls are intended to be selected and applied based on an organization's risk assessment and context. Not every control will be relevant, and the associated guidance describes possible approaches rather than mandatory steps. Applicability is fact-specific and requires professional judgment.

Best practices

Use ISO/IEC 27002 as guidance to inform control selection and implementation, while treating ISO/IEC 27001 as the standard containing the requirements relevant to establishing and certifying an ISMS.
Confirm which edition of ISO/IEC 27002 you are working from, since the structure, groupings, and attributes of controls have changed across versions; verify against the latest authoritative published text.
Drive control selection from a documented risk assessment rather than adopting the full catalogue, tailoring the chosen controls to your organization's context, risk level, and data categories.
Distinguish the advisory implementation guidance in ISO/IEC 27002 from the auditable requirements in ISO/IEC 27001 when preparing for assessment or certification, and coordinate with an accredited certification body on current scheme details.
Assess separately whether any legal or contractual obligations apply, since the standard is voluntary unless incorporated by regulation or agreement in the relevant jurisdiction.
Document the rationale for including or excluding specific controls so that decisions can be reviewed, and revisit selections periodically as standards are amended or superseded and as organizational risk changes.
Application Security Isn’t Optional Anymore.