ISO/IEC 27002
ISO/IEC 27002 is an international standard that offers detailed guidance and best-practice recommendations for selecting and implementing information security controls. It is designed to help organizations of all types and sizes strengthen how they protect information, and it is often used alongside the related ISO/IEC 27001 standard. It provides reference guidance rather than serving as a certifiable requirement on its own.
ISO/IEC 27002 is an international standard that provides guidelines and a reference code of practice for determining, selecting, implementing, and improving information security controls within the context of an information security management system. It supplies best-practice recommendations for those responsible for initiating, implementing, or maintaining information security, and is applicable to organizations of all types and sizes. It functions as supporting guidance to the requirements-based ISO/IEC 27001; organizations are certified against ISO/IEC 27001, not ISO/IEC 27002, and a virtual CISO engagement referencing this standard typically supports control selection and readiness rather than guaranteeing certification. The current revision, ISO/IEC 27002:2022, updates the earlier ISO/IEC 27002:2013 guidance.
Why it matters
ISO/IEC 27002 matters because it translates high-level information security intentions into concrete, well-organized guidance for selecting and implementing controls. Where a requirements standard tells an organization what outcomes must be achieved, ISO/IEC 27002 provides the reference detail on how controls can be chosen and applied in practice. This makes it a practical companion for organizations of all types and sizes that are building or maturing an information security program and want an internationally recognized baseline rather than an ad hoc approach.
A common and important distinction is that organizations are certified against ISO/IEC 27001, not ISO/IEC 27002. ISO/IEC 27002 supplies supporting best-practice guidance on the controls themselves; it does not function as a certifiable requirements standard on its own. Confusing the two can lead buyers to assume that referencing ISO/IEC 27002 delivers certification, when in fact it supports the control selection and readiness work that precedes and underpins an ISO/IEC 27001 assessment.
For security leadership engagements, ISO/IEC 27002 is valuable precisely because it structures decisions that would otherwise be inconsistent or incomplete. A virtual CISO referencing this standard typically uses it to inform which controls are relevant, how they might be implemented, and where gaps exist. The value of that work depends heavily on organizational maturity, the accuracy of the risk context, and access to stakeholders who can validate and operationalize the recommended controls.
Who it's relevant to
Inside ISO/IEC 27002
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27002.