AiVibe

Cybersecurity & Compliance

ISO/IEC 27002

The international standard that provides guidance on information security controls, describing the purpose of each control and how to implement it; it supports the Annex A controls of ISO/IEC 27001.

ISO/IEC 27002 is a code of practice rather than a certifiable requirements standard. The 2022 edition describes 93 controls in four themes, organisational, people, physical and technological, matching Annex A of ISO/IEC 27001:2022. Each control states its purpose and gives implementation guidance, and attributes such as control type, information security properties and cybersecurity concepts help organisations filter controls and map them to other frameworks.

Organisations use ISO/IEC 27002 when designing, implementing and documenting the controls selected through their ISMS risk assessment, and auditors use it as a reference for good practice. The 2022 revision introduced new controls including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

Organisations cannot be certified to ISO/IEC 27002; certification applies to ISO/IEC 27001. Controls should be selected according to risk rather than implemented wholesale, and their depth should match the organisation's size and threats. Related standards extend the guidance for specific contexts, such as ISO/IEC 27017 for cloud services and ISO/IEC 27018 for protecting personal data in public clouds.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain ISO/IEC 27002 for your plant, product or security programme, and draw how it fits.