Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
ISO 27002
ISO/IEC 27002 providing a reference set of information security controls and implementation guidance.
ISO/IEC 27002 is an international standard published jointly by ISO and IEC that provides a reference set of information security controls together with detailed implementation guidance. The 2022 edition reorganised the controls into four themes (organisational, people, physical and technological) and introduced attributes that help organisations map, filter and prioritise controls. It gives practical detail on how the controls referenced by ISO/IEC 27001 Annex A can be designed and operated.
Unlike ISO/IEC 27001, ISO/IEC 27002 is a code of practice and guidance document rather than a set of certifiable requirements, so organisations cannot be certified against it directly. Instead it underpins the selection, implementation and improvement of controls within an information security management system. The current edition is ISO/IEC 27002:2022, published in February 2022.
Use the detailed guidance to design and operate information security controls appropriate to the organisation's risks.
Apply controls across organisational, people, physical and technological themes as relevant to the environment.
Leverage attributes to map controls to concepts such as security properties and operational capabilities for filtering and reporting.
Align implemented controls with the Statement of Applicability and management system built under ISO/IEC 27001.
Read more
Anove scans your stack against ISO 27002 and 260+ other frameworks in minutes.