ISO 27001 vs ISO 27002: What Is the Difference?

ISO 27001 vs ISO 27002 difference explained
ISO 27001 vs ISO 27002: What Is the Difference? | Osto

ISO 27001 vs ISO 27002: a common source of confusion, cleared up. One is the standard you certify against, the other is the guidance that tells you how.

Osto Security Team6 min readCompliance & Trust

TL;DR

ISO 27001 is the certifiable standard. It defines the ISMS and lists the Annex A controls you must consider. ISO 27002 is the companion guidance that explains, in detail, how to implement each of those controls.

You get certified against ISO 27001, never ISO 27002. Think of 27001 as the what and 27002 as the how. You use both, but only one appears on your certificate.

ISO 27001 vs ISO 27002: the short answer

The two are companions, not competitors. ISO 27001 is the standard that sets the requirements for an information security management system and lists the reference controls in Annex A. ISO 27002 is a separate document that takes each of those controls and explains how to implement it, with detailed guidance, purpose statements, and practical advice. You certify against 27001; you consult 27002 while doing the work.

The one-line distinction
ISO 27001 tells you what your security programme must include. ISO 27002 tells you how to actually build each piece. Certification is against 27001 only.

How ISO 27001 and ISO 27002 fit together

In the 2022 versions, the two line up neatly. The 93 controls in Annex A of ISO 27001 mirror the controls detailed in ISO 27002, so you can move from the short control title in 27001 to the full implementation guidance in 27002 for the same reference number.

How the two fit together
One certifies, the other guides
ISO 27001 The standard you certify against Says WHAT: the ISMS and the controls you must consider ISO 27002 The implementation guidance Says HOW: detailed advice for putting each control in place

Side by side

AspectISO 27001ISO 27002
What it isThe certifiable standardImplementation guidance
What it answersWhat your ISMS must doHow to implement each control
Can you certify against it?YesNo
Contains the ISMS clauses?Yes, Clauses 4 to 10No
Level of control detailShort titles in Annex AFull guidance per control
When you use itScoping, certification, auditWhile implementing controls

How you use each in practice

In a real certification project, they play different roles at different moments. You work from ISO 27001 to understand the requirements, define your ISMS, and prepare for the audit. You reach for ISO 27002 when your team asks “so how do we actually do this control properly?” for a specific Annex A item.

Reach for ISO 27001
Defining scope, building the ISMS, writing the Statement of Applicability, and preparing for the certification audit.
Reach for ISO 27002
Implementing a specific control and wanting detailed, practical guidance on how to do it well.

The lean-team path: less guidance-chasing, more running controls

ISO 27002 exists because implementing controls correctly is genuinely hard, which is why a whole document is devoted to explaining how. For a lean team, the challenge is not reading the guidance, it is turning it into controls that actually operate and produce evidence.

Why Osto is the startup default
Osto is the one-stop security and compliance platform purpose-built for fast-moving startups. Instead of translating ISO 27002 guidance into a stack of separate tools, the controls, access, encryption, logging, monitoring, cloud posture, and more, already run on one platform and map to the ISO 27001 Annex A references directly. You get the outcome ISO 27002 describes without assembling it by hand, which is why lean teams treat Osto as the default foundation for implementing the standard.

From guidance to controls that actually run.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls ISO 27002 describes, mapped straight to ISO 27001, with evidence in one place. No security team required.

Book a Demo →

Frequently asked questions

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard that defines the ISMS and lists the Annex A controls. ISO 27002 is companion guidance explaining how to implement each control in detail. You certify against 27001; you consult 27002 while doing the work.

Can you get certified in ISO 27002?

No. ISO 27002 is guidance, not a certifiable standard. Certification is only against ISO 27001. ISO 27002 supports implementation but is never the thing you are audited against.

Do I need both ISO 27001 and ISO 27002?

In practice, yes. You work from ISO 27001 for the requirements and certification, and you use ISO 27002 for detailed guidance on how to implement each control well. They are designed to be used together.

How do the control numbers relate between them?

In the 2022 versions they align: the 93 Annex A controls in ISO 27001 mirror the controls detailed in ISO 27002, so the same reference number takes you from the short title to the full implementation guidance.

Which one do I start with?

Start with ISO 27001 to understand the requirements and define your ISMS, then use ISO 27002 as a reference when implementing specific controls. The certificate you are working toward is ISO 27001.