home / frameworks / iso-27002

// International standards

ISO/IEC 27002:2022

ISO/IEC 27002 gives guidance for the 93 information security controls listed in ISO/IEC 27001 Annex A. Each control has a purpose, implementation guidance, and optional attributes for sorting and mapping.

International

Overview

ISO/IEC 27002 is guidance, not requirements. Where ISO/IEC 27001 sets requirements for a management system, ISO/IEC 27002 explains each reference control in detail. The current text is the third edition, published in February 2022 with a corrected English version in March 2022, and it replaced the 2013 edition and its 2 corrigenda, which ISO has withdrawn.

The 2022 edition reorganized the controls into 4 themes, organizational, people, physical, and technological, and reduced the total from 114 to 93. According to the IAF transition document for ISO/IEC 27001:2022, 11 controls are new, 24 were merged from older ones, and 58 were updated. Every control now follows the same layout. It has a title, an attribute table, a short control statement, a purpose, implementation guidance, and other information where useful.

Attributes are the biggest structural change. They're tags in 5 categories that let an organization filter or group controls, for example by control type or by the identify, protect, detect, respond, and recover concepts. You can't be certified to ISO/IEC 27002. Organizations use it to design controls and to prepare for an ISO/IEC 27001 audit, where certification bodies accredited by the Standards Council of Canada expect the audit team, as a whole, to know every ISO/IEC 27002 control. It's also a common basis for mapping work against the NIST Cybersecurity Framework and Canadian Centre for Cyber Security guidance.

Who it applies to in Canada

Any organization choosing, building, or reviewing information security controls, whether or not it seeks ISO/IEC 27001 certification. Security teams, auditors, and suppliers use it as the reference text for each Annex A control.

Canadian organizations certified to ISO/IEC 27001 rely on ISO/IEC 27002 to interpret the 93 Annex A controls that auditors test. Many Canadian security questionnaires and policy templates also follow its control names and themes.

Controls at a glance

The 93 controls sit in 4 themes, and each control is tagged with values from 5 attribute categories.

Organizational controls (37)

  • Policies, roles, and segregation of duties
  • Threat intelligence and asset inventory
  • Access control and identity management
  • Supplier relationships and cloud service security
  • Incident management planning and response
  • ICT readiness for business continuity
  • Legal, contractual, and privacy requirements

Clause 5 of the standard.

People controls (8)

  • Screening before employment
  • Terms of employment and disciplinary process
  • Awareness, education, and training
  • Confidentiality agreements and remote working
  • Reporting information security events

Clause 6 of the standard.

Physical controls (14)

  • Perimeters, entry controls, and secure areas
  • Physical security monitoring
  • Environmental threat protection
  • Clear desk and clear screen
  • Equipment security, maintenance, and disposal
  • Storage media handling

Clause 7 of the standard.

Technological controls (34)

  • Endpoint devices and privileged access
  • Authentication, malware protection, and vulnerability management
  • Configuration management and information deletion
  • Data masking and data leakage prevention
  • Backups, logging, and monitoring activities
  • Network security and web filtering
  • Cryptography
  • Secure development and secure coding

Clause 8 of the standard.

Control attributes (5 categories)

  • Control type, preventive, detective, or corrective
  • Information security properties, confidentiality, integrity, and availability
  • Cybersecurity concepts, identify, protect, detect, respond, and recover
  • Operational capabilities, such as asset management or identity
  • Security domains, such as protection, defence, and resilience

Attributes are optional and can be extended by the organization.

Layout of each control

  • Control title and attribute table
  • Control statement saying what to do
  • Purpose explaining why the control exists
  • Implementation guidance
  • Other information and related standards

Certification and assessment

Organizations show they follow ISO/IEC 27002 by implementing the controls they select and recording them in an ISO/IEC 27001 Statement of Applicability. During ISO/IEC 27001 audits, certification bodies use ISO/IEC 27002 as the reference for what each control means. Some organizations also run internal gap assessments against it.

Dates to know

2022-02
ISO/IEC 27002:2022 (Edition 3) published, replacing the 2013 edition
2022-03
Corrected English version of ISO/IEC 27002:2022 issued
2022-10-25
ISO/IEC 27001:2022 published with Annex A aligned to ISO/IEC 27002:2022

Resources

Official texts and free tools for ISO 27002. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISO/IEC 27002:2022 Information security controls, ISO
  2. IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum