ISO/IEC 27002
Also known as: ISO 27002
International standard providing guidance on information security controls.
ISO/IEC 27002 is the international standard providing guidance on information security controls, descended from the British BS 7799-1 (1995, originating from work by the British Department of Trade and Industry and a consortium of UK firms in the early 1990s). BS 7799 was adopted as ISO/IEC 17799:2000, renumbered ISO/IEC 27002:2005 to align with the broader 27000-series Information Security Management System (ISMS) family, with subsequent revisions in 2013 and most recently 2022. The 2022 revision substantially restructured the controls catalog, reducing from 114 controls in 14 clauses to 93 controls in 4 themes: Organizational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34). ISO/IEC 27002 provides implementation guidance for the controls referenced in ISO/IEC 27001 (the certifiable management-system standard), with each control providing purpose, implementation guidance, and other information. Organizations seeking ISO 27001 certification typically use 27002 as the implementation reference for the controls they select through their ISMS process. The framework is widely adopted internationally — particularly in Europe, Asia-Pacific, and the UK where ISO certifications carry substantial weight — with substantial overlap and increasing harmonization with NIST 800-53 (US federal context). The 2022 revision substantially modernized the standard and improved alignment with cloud, DevSecOps, and contemporary practice.
Core components
- 93 controls (2022 revision) organized into 4 themes: Organizational, People, Physical, Technological
- Control structure: control statement, purpose, implementation guidance, other information
- Use with ISO/IEC 27001 (certifiable ISMS standard)
- Risk-based control selection through ISMS process
- International standard developed by ISO/IEC JTC 1/SC 27
- Connection to broader 27000-series family (27001 ISMS, 27005 risk management, 27017 cloud security, 27018 cloud privacy)
- Substantial international adoption particularly Europe and Asia-Pacific
- 2022 revision substantially modernized structure
Primary use case
International information-security control framework; foundation for ISO/IEC 27001 ISMS certification (the certifiable companion standard); reference framework in many regulatory and contractual contexts globally; basis for substantial cybersecurity consulting practice; integration with NIST controls through cross-walks; foundation for many enterprise security programs particularly in multinational organizations; pedagogical reference in international cybersecurity education.
Common criticisms
- Same checklist-compliance concerns as other regulatory-standard frameworks — controls can be documented as 'implemented' without substantive security improvement
- certification industry has substantial financial incentive to perpetuate compliance rather than security
- ISO certification carries reputational value but doesn't necessarily indicate strong security posture
- cost of certification is substantial, creating barriers for smaller organizations
- cross-walking with NIST 800-53 and other frameworks requires substantial effort
- commercial GRC platforms produce automated compliance tracking that can obscure substantive security
- the 2022 revision substantially restructured the standard, requiring re-certification and re-mapping efforts that generated industry friction
- integration with cloud and modern architecture patterns has improved but remains incomplete
- geographic variation in adoption (stronger in Europe and Asia-Pacific, weaker in US federal context) creates dual-framework burden for multinational organizations
- certification process quality varies across certification bodies.
Lineage
- Siblings
- NIST 800-53, CIS Controls