ISO/IEC 27002
The international standard that provides guidance on information security controls, describing the purpose of each control and how to implement it; it supports the Annex A controls of ISO/IEC 27001.
ISO/IEC 27002 is a code of practice rather than a certifiable requirements standard. The 2022 edition describes 93 controls in four themes, organisational, people, physical and technological, matching Annex A of ISO/IEC 27001:2022. Each control states its purpose and gives implementation guidance, and attributes such as control type, information security properties and cybersecurity concepts help organisations filter controls and map them to other frameworks.
Organisations use ISO/IEC 27002 when designing, implementing and documenting the controls selected through their ISMS risk assessment, and auditors use it as a reference for good practice. The 2022 revision introduced new controls including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
Organisations cannot be certified to ISO/IEC 27002; certification applies to ISO/IEC 27001. Controls should be selected according to risk rather than implemented wholesale, and their depth should match the organisation's size and threats. Related standards extend the guidance for specific contexts, such as ISO/IEC 27017 for cloud services and ISO/IEC 27018 for protecting personal data in public clouds.
Key points
- Provides implementation guidance for information security controls.
- The 2022 edition has 93 controls in four themes, aligned with ISO/IEC 27001 Annex A.
- Not certifiable; certification is to ISO/IEC 27001.
- Control attributes help map controls to other frameworks.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.