Companion standard to ISO 27001 providing detailed guidance on security controls implementation.
ISO 27002 provides detailed guidance on implementing information security controls. While ISO 27001 specifies what an ISMS must include, ISO 27002 explains how to implement specific controls—from access control to cryptography to physical security. The 2022 revision reorganised controls into four themes: organisational, people, physical, and technological. ISO 27002 is a reference guide, not a certification standard—organisations certify to ISO 27001.
Why It Matters
The DSC Perspective:
ISO 27002 is your implementation guide for ISO 27001 controls. Use it to understand what good looks like for each control area. The 2022 version includes updated guidance relevant to cloud and modern threats.
