ISO 27002 is the guidance document that explains how to implement each of the controls listed in ISO 27001 Annex A. You cannot be certified against it.
The short answer
ISO 27001 tells you which controls to consider. ISO 27002 tells you what each control means and how to implement it. Annex A of ISO 27001 lists the 93 controls in one line each; ISO 27002 devotes a page or more to every one of them. Certification is against ISO 27001 only. ISO 27002 is the reference book you keep open while doing the work.
Both were reissued in 2022 with the same restructure, so the control numbers in ISO 27002:2022 match Annex A exactly. If you are looking at a control reference like A.8.24, ISO 27002 has the corresponding section.
On this page
ISO 27001 or ISO 27002?
The practical relationship: ISO 27001 is what your auditor tests you against, and Annex A is the shortlist inside it. When a one-line control title is not enough to know what to build, ISO 27002 is where you look next.
What each control entry contains
| Section | What it gives you |
|---|---|
| Control | The same one-line statement that appears in Annex A |
| Purpose | Why the control exists and what risk it addresses |
| Guidance | The substance: what implementing it involves, often across several pages |
| Other information | Context, related standards and edge cases worth knowing |
| Attributes | Five tags that let you filter and group controls in other ways |
Guidance, not a checklist
ISO 27002 says what to consider, not what you must do. An auditor will not fail you for departing from its guidance, provided your risk assessment supports the choice you made. What they will question is a control you claimed as applicable but never implemented, which is the same trap teams hit with SOC 2 controls.
The five attributes
New in the 2022 edition. Each control carries five tags, so the same 93 controls can be viewed through whichever lens suits the audience.
| Attribute | Example values |
|---|---|
| Control type | Preventive, detective, corrective |
| Information security properties | Confidentiality, integrity, availability |
| Cybersecurity concepts | Identify, protect, detect, respond, recover |
| Operational capabilities | Identity and access management, application security, threat management |
| Security domains | Governance and ecosystem, protection, defence, resilience |
They are optional. Nothing in ISO 27001 requires you to use attributes, and no auditor will ask for them. They are useful mainly when you need to show coverage to a technical audience rather than a compliance one.
How to actually use it
Start from the risk
Assess risk first, decide which controls apply, then open ISO 27002 for the ones you kept.
Read the purpose line
When you cannot tell what a control is for, the purpose statement resolves it faster than the guidance does.
Write your own procedure
Do not paste the guidance into a policy. Auditors test what you actually do, not what the standard says.
How Osto implements the controls
Most Annex A controls in the technological theme need a tool behind them, not a document. Osto deploys those directly: access control and MFA, encryption, logging and monitoring, vulnerability testing, endpoint control and secure development testing. The platform maps each one to its Annex A reference and collects the evidence as the control runs, so your Statement of Applicability reflects what is genuinely in place.
Free security assessment
Controls that run, not controls on paper
Osto deploys the technical controls behind Annex A and maps the evidence to each reference, so implementation and documentation stay in step.
Get a free security assessment Book a platform walkthrough200+ frameworks · Evidence from live controls · One platform, everything
Frequently asked questions
What is ISO 27002?
ISO 27002 is the implementation guidance standard for information security controls. It explains, in detail, each of the 93 controls listed in Annex A of ISO 27001. It is a reference document, not a certifiable standard.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 contains the requirements for a management system and lists controls in Annex A, and it is what you get certified against. ISO 27002 explains how to implement each of those controls and offers no certification.
Can you be certified to ISO 27002?
No. There is no ISO 27002 certification. Any claim of being ISO 27002 certified is a misunderstanding. Certification is issued against ISO 27001 by an accredited certification body.
Do you have to follow ISO 27002 guidance exactly?
No. It is guidance rather than requirement. You can implement a control differently if your risk assessment justifies the approach. What you cannot do is mark a control applicable and then not implement it in any form.
Do the ISO 27002:2022 control numbers match Annex A?
Yes. Both were revised in 2022 using the same structure of four themes and 93 controls, so a reference such as A.8.24 in Annex A corresponds directly to section 8.24 in ISO 27002.

