Skip to main content
Category: Compliance Frameworks & Standards

ISO/IEC 27002

Also known as: ISO 27002, ISO/IEC 27002:2022, Information Security Controls Code of Practice
Simply put

ISO/IEC 27002 is an international standard that offers detailed guidance and best-practice recommendations for selecting and implementing information security controls. It is designed to help organizations of all types and sizes strengthen how they protect information, and it is often used alongside the related ISO/IEC 27001 standard. It provides reference guidance rather than serving as a certifiable requirement on its own.

Formal definition

ISO/IEC 27002 is an international standard that provides guidelines and a reference code of practice for determining, selecting, implementing, and improving information security controls within the context of an information security management system. It supplies best-practice recommendations for those responsible for initiating, implementing, or maintaining information security, and is applicable to organizations of all types and sizes. It functions as supporting guidance to the requirements-based ISO/IEC 27001; organizations are certified against ISO/IEC 27001, not ISO/IEC 27002, and a virtual CISO engagement referencing this standard typically supports control selection and readiness rather than guaranteeing certification. The current revision, ISO/IEC 27002:2022, updates the earlier ISO/IEC 27002:2013 guidance.

Why it matters

ISO/IEC 27002 matters because it translates high-level information security intentions into concrete, well-organized guidance for selecting and implementing controls. Where a requirements standard tells an organization what outcomes must be achieved, ISO/IEC 27002 provides the reference detail on how controls can be chosen and applied in practice. This makes it a practical companion for organizations of all types and sizes that are building or maturing an information security program and want an internationally recognized baseline rather than an ad hoc approach.

A common and important distinction is that organizations are certified against ISO/IEC 27001, not ISO/IEC 27002. ISO/IEC 27002 supplies supporting best-practice guidance on the controls themselves; it does not function as a certifiable requirements standard on its own. Confusing the two can lead buyers to assume that referencing ISO/IEC 27002 delivers certification, when in fact it supports the control selection and readiness work that precedes and underpins an ISO/IEC 27001 assessment.

For security leadership engagements, ISO/IEC 27002 is valuable precisely because it structures decisions that would otherwise be inconsistent or incomplete. A virtual CISO referencing this standard typically uses it to inform which controls are relevant, how they might be implemented, and where gaps exist. The value of that work depends heavily on organizational maturity, the accuracy of the risk context, and access to stakeholders who can validate and operationalize the recommended controls.

Who it's relevant to

Organizations pursuing or maintaining ISO/IEC 27001
Because organizations are certified against ISO/IEC 27001 rather than ISO/IEC 27002, teams working toward certification use ISO/IEC 27002 as the detailed reference for how to determine, select, and implement the controls that support their management system. It is especially useful when translating requirements into concrete control decisions, though its practical value depends on the organization's maturity and cooperation from control owners.
Security leaders and virtual CISOs
Those responsible for initiating, implementing, or maintaining information security use ISO/IEC 27002 as a structured basis for control selection and program improvement. A virtual CISO referencing this standard typically advises on and directs control selection and readiness rather than guaranteeing certification or performing hands-on operational tasks, and accountability for the resulting decisions remains with the client organization.
Organizations of all types and sizes building a security program
The standard is designed to be applicable across organizations of all types and sizes, making it a useful reference for smaller or less mature organizations that want an internationally recognized baseline for information security controls. Its usefulness increases where there is a defined scope, an understood risk context, and access to stakeholders who can validate and operationalize the recommended controls.
Buyers evaluating vCISO or advisory engagements
Executives and buyers assessing security leadership services benefit from understanding that referencing ISO/IEC 27002 supports control selection and readiness rather than asserting certification. This distinction helps set accurate expectations when scoping engagements, and clarifies that a vCISO advising against this standard is not a substitute for an entire security team or for the formal assessment conducted against ISO/IEC 27001.

Inside ISO/IEC 27002

Control catalog
ISO/IEC 27002 provides a detailed catalog of information security controls, offering guidance on implementation and best practices. It is a companion to ISO/IEC 27001, which specifies the requirements for an information security management system (ISMS).
Implementation guidance
Rather than stating certifiable requirements, the standard describes how controls can be implemented and the purpose each control serves, giving organizations context for applying them to their specific environment.
Control themes and attributes
Controls are organized into thematic groupings and, in the current revision, are supplemented with attributes that help organizations categorize and filter controls according to their needs. The precise structure may vary by edition of the standard.
Relationship to ISO/IEC 27001
ISO/IEC 27002 supports, but is distinct from, ISO/IEC 27001. Organizations certify against 27001; 27002 supplies the supporting detail on how controls referenced in 27001 can be operationalized.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27002.

Is ISO/IEC 27002 a standard you can get certified against?
No, and this is a common point of confusion. ISO/IEC 27002 is a guidance document that provides a catalog of information security controls and implementation advice. Organizations pursue certification against ISO/IEC 27001, which specifies the requirements for an information security management system (ISMS). ISO/IEC 27002 supports that effort by offering detailed explanations of controls referenced in ISO/IEC 27001, but you are not certified to 27002 itself. A virtual CISO can help clarify this distinction and align a control set to the certifiable standard where certification is a goal.
Does adopting ISO/IEC 27002 mean an organization must implement every control it lists?
Not typically. ISO/IEC 27002 functions as a reference catalog rather than a mandatory checklist. Control selection is generally driven by an organization's risk assessment, business context, and applicable obligations, so the controls chosen and how deeply they are implemented may vary considerably. Treating the document as an all-or-nothing mandate is a frequent mistake. A virtual CISO usually advises on which controls are relevant and proportionate, while the decision and accountability for adoption rest with the client organization.
How does a virtual CISO typically use ISO/IEC 27002 in an engagement?
In many engagements, a virtual CISO uses ISO/IEC 27002 as a reference to inform control selection, assess current practices against recognized guidance, and develop or refine policies and program structure. The vCISO generally advises and directs this work at a strategy and governance level, rather than performing hands-on control configuration or tool administration unless explicitly contracted. The value of this work often depends on organizational maturity, stakeholder access, and a clearly defined engagement scope.
Can ISO/IEC 27002 be used alongside other frameworks like NIST CSF?
Yes, it often is. Organizations frequently map controls across multiple references, and a virtual CISO may cross-reference ISO/IEC 27002 guidance with frameworks such as NIST CSF or requirements from standards like SOC 2 to avoid duplicated effort. The approach may vary by provider and by the client's obligations. It is worth noting that mapping supports coherence and readiness but does not by itself guarantee compliance or certification under any given standard.
What should an organization have in place before using ISO/IEC 27002 to guide its program?
In most cases, a meaningful risk assessment and an understanding of business context and applicable obligations are helpful before applying the control guidance, since these inform which controls are relevant. Access to stakeholders and reasonable clarity on organizational objectives also matter. Where these are immature or absent, a virtual CISO often addresses them first, because control selection driven by guidance alone, without risk context, tends to produce a poorly prioritized program.
Does following ISO/IEC 27002 make an organization secure or prevent breaches?
No single reference or control catalog can guarantee security or prevent breaches. ISO/IEC 27002 provides implementation guidance that can strengthen a control environment when applied thoughtfully, but outcomes depend on how controls are selected, implemented, operated, and maintained over time. A virtual CISO advises and directs on this, while accountability for security decisions and their outcomes generally remains with the client organization and its officers.

Common misconceptions

An organization can be certified against ISO/IEC 27002.
Certification is issued against ISO/IEC 27001, which defines the ISMS requirements. ISO/IEC 27002 is a guidance document providing implementation detail for controls and is not itself a certifiable standard. A virtual CISO can help clarify this distinction and support readiness efforts, but engaging a vCISO does not itself confer or guarantee certification.
Implementing every control in ISO/IEC 27002 is required and guarantees strong security.
The standard is a catalog of guidance from which organizations select and tailor controls based on their risk assessment and context. Not all controls apply to every organization, and adopting controls does not guarantee breach prevention. The value of applying the standard depends on organizational maturity, accurate risk assessment, and consistent operation of the chosen controls.
A virtual CISO applying ISO/IEC 27002 assumes accountability for the organization's compliance and security outcomes.
A vCISO typically advises on and directs how controls from the standard can be interpreted and implemented, but legal and organizational accountability for security decisions generally remains with the client organization and its officers unless a contract specifies otherwise. The vCISO usually does not perform hands-on operational tasks such as tool administration unless explicitly contracted.

Best practices

Use ISO/IEC 27002 as implementation guidance alongside ISO/IEC 27001, and be clear internally that any certification effort targets 27001, not 27002.
Select and tailor controls based on a documented risk assessment rather than attempting to implement the entire catalog, so effort aligns with the organization's actual risk profile and maturity.
Define engagement scope explicitly when using a virtual CISO to guide control adoption, distinguishing advisory and governance work from any hands-on operational tasks, which are often out of scope unless contracted.
Confirm where accountability for security decisions sits, keeping legal and organizational accountability with client officers unless a contract states otherwise, while the vCISO provides direction and guidance.
Map selected controls to their intended purpose and, where the edition supports it, use control themes and attributes to organize and prioritize implementation.
Treat control adoption as ongoing operational work rather than a one-time exercise, since sustained value depends on client cooperation, stakeholder access, and consistent operation of the controls over time.