Overview
ISO/IEC 27002 is guidance, not requirements. Where ISO/IEC 27001 sets requirements for a management system, ISO/IEC 27002 explains each reference control in detail. The current text is the third edition, published in February 2022 with a corrected English version in March 2022, and it replaced the 2013 edition and its 2 corrigenda, which ISO has withdrawn.
The 2022 edition reorganized the controls into 4 themes, organizational, people, physical, and technological, and reduced the total from 114 to 93. According to the IAF transition document for ISO/IEC 27001:2022, 11 controls are new, 24 were merged from older ones, and 58 were updated. Every control now follows the same layout. It has a title, an attribute table, a short control statement, a purpose, implementation guidance, and other information where useful.
Attributes are the biggest structural change. They're tags in 5 categories that let an organization filter or group controls, for example by control type or by the identify, protect, detect, respond, and recover concepts. You can't be certified to ISO/IEC 27002. Organizations use it to design controls and to prepare for an ISO/IEC 27001 audit, where certification bodies accredited by the Standards Council of Canada expect the audit team, as a whole, to know every ISO/IEC 27002 control. It's also a common basis for mapping work against the NIST Cybersecurity Framework and Canadian Centre for Cyber Security guidance.
Who it applies to in Canada
Any organization choosing, building, or reviewing information security controls, whether or not it seeks ISO/IEC 27001 certification. Security teams, auditors, and suppliers use it as the reference text for each Annex A control.
Canadian organizations certified to ISO/IEC 27001 rely on ISO/IEC 27002 to interpret the 93 Annex A controls that auditors test. Many Canadian security questionnaires and policy templates also follow its control names and themes.
Controls at a glance
The 93 controls sit in 4 themes, and each control is tagged with values from 5 attribute categories.
Organizational controls (37)
- Policies, roles, and segregation of duties
- Threat intelligence and asset inventory
- Access control and identity management
- Supplier relationships and cloud service security
- Incident management planning and response
- ICT readiness for business continuity
- Legal, contractual, and privacy requirements
Clause 5 of the standard.
People controls (8)
- Screening before employment
- Terms of employment and disciplinary process
- Awareness, education, and training
- Confidentiality agreements and remote working
- Reporting information security events
Clause 6 of the standard.
Physical controls (14)
- Perimeters, entry controls, and secure areas
- Physical security monitoring
- Environmental threat protection
- Clear desk and clear screen
- Equipment security, maintenance, and disposal
- Storage media handling
Clause 7 of the standard.
Technological controls (34)
- Endpoint devices and privileged access
- Authentication, malware protection, and vulnerability management
- Configuration management and information deletion
- Data masking and data leakage prevention
- Backups, logging, and monitoring activities
- Network security and web filtering
- Cryptography
- Secure development and secure coding
Clause 8 of the standard.
Control attributes (5 categories)
- Control type, preventive, detective, or corrective
- Information security properties, confidentiality, integrity, and availability
- Cybersecurity concepts, identify, protect, detect, respond, and recover
- Operational capabilities, such as asset management or identity
- Security domains, such as protection, defence, and resilience
Attributes are optional and can be extended by the organization.
Layout of each control
- Control title and attribute table
- Control statement saying what to do
- Purpose explaining why the control exists
- Implementation guidance
- Other information and related standards
Certification and assessment
Organizations show they follow ISO/IEC 27002 by implementing the controls they select and recording them in an ISO/IEC 27001 Statement of Applicability. During ISO/IEC 27001 audits, certification bodies use ISO/IEC 27002 as the reference for what each control means. Some organizations also run internal gap assessments against it.
Dates to know
- 2022-02
- ISO/IEC 27002:2022 (Edition 3) published, replacing the 2013 edition
- 2022-03
- Corrected English version of ISO/IEC 27002:2022 issued
- 2022-10-25
- ISO/IEC 27001:2022 published with Annex A aligned to ISO/IEC 27002:2022
Resources
Official texts and free tools for ISO 27002. Links open the publisher’s site.
- ISO/IEC 27002:2022 Information security controls, ISO
- ISO/IEC 27001:2022 Information security management systems, ISO
- ISO Online Browsing Platform, ISOtool
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- ISO/IEC 27002:2022 Information security controls, ISO
- IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.