ISO/IEC 27002
ISO/IEC 27002 is an international standard that offers guidance on selecting and implementing information security controls, such as policies, processes, and organizational measures. It is a voluntary reference document rather than a law, and organizations typically use it to help put good security practices into place. It is often used alongside ISO/IEC 27001, which sets the requirements for an information security management system.
ISO/IEC 27002 is a voluntary international standard published jointly by ISO and IEC that provides guidance on information security controls, including policies, rules, processes, procedures, organizational structures, and related measures used to achieve information security. It functions as a reference catalogue and implementation guidance rather than a certifiable requirements standard: certification is assessed against ISO/IEC 27001, while ISO/IEC 27002 supports the selection and implementation of controls within an ISMS built to ISO/IEC 27001. As a standard, it carries no legal force in itself and applies only where an organization adopts it voluntarily or is bound to it by contract; it should not be conflated with binding regulation. Readers should verify the current edition and version, as the standard (most recently referenced here as the 2022 revision) is periodically revised.
Why it matters
Information security controls are only effective when they are chosen deliberately and implemented consistently. ISO/IEC 27002 matters because it provides a widely recognized reference catalogue of controls and implementation guidance, helping organizations move from the abstract requirement to "secure information" toward concrete measures such as policies, processes, and organizational structures. For compliance and security teams, this shared vocabulary reduces ambiguity and supports more consistent decision-making about which controls are appropriate to a given environment.
Its practical significance is closely tied to its relationship with ISO/IEC 27001. Certification is assessed against ISO/IEC 27001, which sets the requirements for an information security management system (ISMS); ISO/IEC 27002 supports that effort by guiding the selection and implementation of controls within the ISMS. Organizations pursuing certification, or simply seeking to demonstrate mature security practices to customers and partners, commonly draw on ISO/IEC 27002 to justify and document their control choices.
It is important to keep the standard's status in perspective: ISO/IEC 27002 is voluntary guidance and carries no legal force in itself. It becomes binding only where an organization adopts it or is contractually obligated to follow it, and it should not be treated as a substitute for applicable regulation. Readers should also verify the current edition, as the standard is periodically revised.
Who it's relevant to
Inside ISO/IEC 27002
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27002.

