ISO/IEC 27002

Also known as: ISO 27002

framework · cybersecurity · regulatory-standard

International standard providing guidance on information security controls.

ISO/IEC 27002 is the international standard providing guidance on information security controls, descended from the British BS 7799-1 (1995, originating from work by the British Department of Trade and Industry and a consortium of UK firms in the early 1990s). BS 7799 was adopted as ISO/IEC 17799:2000, renumbered ISO/IEC 27002:2005 to align with the broader 27000-series Information Security Management System (ISMS) family, with subsequent revisions in 2013 and most recently 2022. The 2022 revision substantially restructured the controls catalog, reducing from 114 controls in 14 clauses to 93 controls in 4 themes: Organizational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34). ISO/IEC 27002 provides implementation guidance for the controls referenced in ISO/IEC 27001 (the certifiable management-system standard), with each control providing purpose, implementation guidance, and other information. Organizations seeking ISO 27001 certification typically use 27002 as the implementation reference for the controls they select through their ISMS process. The framework is widely adopted internationally — particularly in Europe, Asia-Pacific, and the UK where ISO certifications carry substantial weight — with substantial overlap and increasing harmonization with NIST 800-53 (US federal context). The 2022 revision substantially modernized the standard and improved alignment with cloud, DevSecOps, and contemporary practice.

Originators

British Standards Institution (BS 7799 origin, early 1990s); ISO/IEC Joint Technical Committee 1, Subcommittee 27 (subsequent international development) high

Year / Decade

Early 1990s (BS 7799 origin); 1995 (BS 7799-1); 2000 (ISO 17799); 2005, 2013, 2022 (ISO 27002 revisions) high

Primary sources

ISO/IEC (2022). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls, ISO/IEC (2022). ISO/IEC 27001:2022 Information security management systems — Requirements, BS 7799-1:1995 (BSI historical antecedent) high

Core components

Primary use case

International information-security control framework; foundation for ISO/IEC 27001 ISMS certification (the certifiable companion standard); reference framework in many regulatory and contractual contexts globally; basis for substantial cybersecurity consulting practice; integration with NIST controls through cross-walks; foundation for many enterprise security programs particularly in multinational organizations; pedagogical reference in international cybersecurity education.

Common criticisms

Lineage

Siblings
NIST 800-53, CIS Controls