What is ISO 27002 ?

ISO 27002 explained: implementation guidance for Annex A controls

ISO 27002 is the guidance document that explains how to implement each of the controls listed in ISO 27001 Annex A. You cannot be certified against it.

  • Glossary
  • ISO 27001

The short answer

ISO 27001 tells you which controls to consider. ISO 27002 tells you what each control means and how to implement it. Annex A of ISO 27001 lists the 93 controls in one line each; ISO 27002 devotes a page or more to every one of them. Certification is against ISO 27001 only. ISO 27002 is the reference book you keep open while doing the work.

Both were reissued in 2022 with the same restructure, so the control numbers in ISO 27002:2022 match Annex A exactly. If you are looking at a control reference like A.8.24, ISO 27002 has the corresponding section.

ISO 27001 or ISO 27002?

ISO 27001 The requirements standard Clauses 4 to 10, plus Annex A control list You get certified against this refers to ISO 27002 The implementation guidance A full explanation of all 93 controls Guidance only, no certification
Swipe to see the full diagram. Certificates say ISO 27001. Nobody issues an ISO 27002 certificate.

The practical relationship: ISO 27001 is what your auditor tests you against, and Annex A is the shortlist inside it. When a one-line control title is not enough to know what to build, ISO 27002 is where you look next.

What each control entry contains

SectionWhat it gives you
ControlThe same one-line statement that appears in Annex A
PurposeWhy the control exists and what risk it addresses
GuidanceThe substance: what implementing it involves, often across several pages
Other informationContext, related standards and edge cases worth knowing
AttributesFive tags that let you filter and group controls in other ways

Guidance, not a checklist

ISO 27002 says what to consider, not what you must do. An auditor will not fail you for departing from its guidance, provided your risk assessment supports the choice you made. What they will question is a control you claimed as applicable but never implemented, which is the same trap teams hit with SOC 2 controls.

The five attributes

New in the 2022 edition. Each control carries five tags, so the same 93 controls can be viewed through whichever lens suits the audience.

AttributeExample values
Control typePreventive, detective, corrective
Information security propertiesConfidentiality, integrity, availability
Cybersecurity conceptsIdentify, protect, detect, respond, recover
Operational capabilitiesIdentity and access management, application security, threat management
Security domainsGovernance and ecosystem, protection, defence, resilience

They are optional. Nothing in ISO 27001 requires you to use attributes, and no auditor will ask for them. They are useful mainly when you need to show coverage to a technical audience rather than a compliance one.

How to actually use it

Start from the risk

Assess risk first, decide which controls apply, then open ISO 27002 for the ones you kept.

Read the purpose line

When you cannot tell what a control is for, the purpose statement resolves it faster than the guidance does.

Write your own procedure

Do not paste the guidance into a policy. Auditors test what you actually do, not what the standard says.

How Osto implements the controls

Most Annex A controls in the technological theme need a tool behind them, not a document. Osto deploys those directly: access control and MFA, encryption, logging and monitoring, vulnerability testing, endpoint control and secure development testing. The platform maps each one to its Annex A reference and collects the evidence as the control runs, so your Statement of Applicability reflects what is genuinely in place.

Free security assessment

Controls that run, not controls on paper

Osto deploys the technical controls behind Annex A and maps the evidence to each reference, so implementation and documentation stay in step.

Get a free security assessment Book a platform walkthrough

200+ frameworks · Evidence from live controls · One platform, everything

Frequently asked questions

What is ISO 27002?

ISO 27002 is the implementation guidance standard for information security controls. It explains, in detail, each of the 93 controls listed in Annex A of ISO 27001. It is a reference document, not a certifiable standard.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 contains the requirements for a management system and lists controls in Annex A, and it is what you get certified against. ISO 27002 explains how to implement each of those controls and offers no certification.

Can you be certified to ISO 27002?

No. There is no ISO 27002 certification. Any claim of being ISO 27002 certified is a misunderstanding. Certification is issued against ISO 27001 by an accredited certification body.

Do you have to follow ISO 27002 guidance exactly?

No. It is guidance rather than requirement. You can implement a control differently if your risk assessment justifies the approach. What you cannot do is mark a control applicable and then not implement it in any form.

Do the ISO 27002:2022 control numbers match Annex A?

Yes. Both were revised in 2022 using the same structure of four themes and 93 controls, so a reference such as A.8.24 in Annex A corresponds directly to section 8.24 in ISO 27002.