Start a free trial
Menu

ISO 27002

ISO 27002 compliance software

Security and quality teams implementing the Annex A controls behind an ISO 27001 certificate.

ISO 27002 is the implementation guidance for the information-security controls listed in ISO 27001 Annex A. ComplyTrain holds each control as a requirement with the evidence that shows it is operating - which is what an auditor samples.

ComplyTrain fully supports this standard

What ISO 27002 is

ISO 27001 tells you that you need an information security management system and lists the controls you may select in Annex A. It does not tell you how to implement any of them. ISO/IEC 27002 is the companion that does: guidance, control by control, on what the control is for, how it is typically implemented and what to consider when you apply it.

The 2022 revision reorganised the controls into four themes - organisational, people, physical and technological - and gave each control a set of attributes you can filter by. That structure is the useful part: it lets you talk about your controls as a coherent set rather than a numbered list inherited from an annex.

It is guidance, not a certification

You are certified against ISO 27001. ISO 27002 is not a certifiable standard and there is no such thing as an ISO 27002 certificate. What it gives you is the reasoning behind each control, which is what an auditor is testing when they ask why you implemented one the way you did.

The four themes, and why the regrouping helps

The 2022 revision moved the controls from fourteen clauses into four themes. Organisational controls cover policy, roles, supplier relationships and incident management. People controls cover screening, terms of employment, awareness and what happens when someone leaves. Physical controls cover premises, equipment and media. Technological controls cover access, cryptography, logging, secure development and everything most people picture first.

The regrouping matters more than it sounds. A control set organised by theme can be assigned to the people who own that theme, which a numbered list inherited from an annex cannot. It also makes the gaps visible: an organisation with forty technological controls and three people controls has told you something about itself.

Each control also carries attributes - control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They exist so you can view the same set through whichever lens the conversation needs, which is useful when a customer asks a question framed differently from your documentation.

How ComplyTrain helps you apply it

A control is not implemented because a policy mentions it. It is implemented when something happens, someone is accountable for it, and there is a record. ComplyTrain holds all three against the control itself:

  • Each control held as a requirement, with its implementation guidance and the evidence that satisfies it.
  • The policies and procedures that carry the control, under version control with signed acknowledgement.
  • The risk assessment that justified selecting the control in the first place, kept as a living register rather than a document from last year.
  • Competence and awareness training assigned against the people the control depends on, with the record an auditor asks for.
  • Supplier controls assessed and recorded where the control extends beyond your own organisation.

The point is the trail. A control, the reason you selected it, the procedure that implements it, the people trained on it, and the evidence it ran. See requirements management and document control for the mechanics.

Questions

Is ComplyTrain ISO 27002 certified?

No, and neither is anyone else. ISO 27002 is guidance and carries no certification. You are certified against ISO 27001; ISO 27002 is how you implement the controls that certificate depends on. ComplyTrain is the system you run that work in.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the requirements standard - what your management system must do, and the Annex A list of controls you may select from. ISO 27002 is the implementation guidance for those controls. You get certified to the first using the second.

Do I need ISO 27002 if I already have ISO 27001?

You are already using it, whether or not you have read it. Every Annex A control you have implemented has guidance behind it, and an auditor asking why a control was implemented a particular way is asking a question ISO 27002 answers.

Does the 2022 revision change what I have already done?

It reorganised the controls into four themes and merged some, so the numbering moved. The substance of most controls did not. What changes is how you present the set, which is worth getting right because it is how your Statement of Applicability reads.

How many controls are there?

The 2022 revision lists 93, down from 114, because a number of overlapping controls were merged rather than removed. Eleven are new, and they are largely the ones that had become obvious in the intervening years: threat intelligence, cloud services, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

Do we have to implement all of them?

No, and an organisation that claims to has usually not thought about it. You select controls based on your risk assessment and record why each was included or excluded. That reasoning is the Statement of Applicability, and it is what an auditor reads first.

The process

Putting ISO 27002 to work

ISO 27002 is guidance rather than a certifiable standard, so there is no audit to pass against it. The work is applying its controls inside the ISMS you already run.

  1. Start from your Statement of Applicability

    ISO 27001 decides which controls apply to you. That decision is the entry point: ISO 27002 explains what each of those controls is for and what good implementation looks like.

  2. Read the control purpose, not just the title

    Each control comes with a stated purpose, implementation guidance and attributes you can filter by. The purpose is what an auditor asks about, and it is where most gaps are actually found.

  3. Implement it and write down what you did

    A control is only as good as the policy, procedure or configuration behind it. Record the decision and the reasoning, so the choice survives the person who made it.

  4. Evidence it and keep it current

    Attach the evidence that shows the control operating, review it on a cadence, and record the changes. This is the difference between a control that exists and one you can demonstrate.

Run your ISO 27002 controls in one system

See how ComplyTrain traces each control to its evidence on a 30-minute demo, walked through on your own controls. Or start a trial and we will set up a workspace to match your Statement of Applicability.