What Is ISO 27002?
ISO/IEC 27002 is the internationally recognized code of practice for information security controls. Where ISO 27001 defines the requirements for building and certifying an Information Security Management System (ISMS), ISO 27002 provides the detailed, practical guidance for implementing the controls listed in ISO 27001's Annex A. In short: ISO 27001 tells you what a compliant security program must achieve, and ISO 27002 shows you how to get there.
Organizations cannot certify against ISO 27002 itself — certification is against ISO 27001. But a security program built on ISO 27002 guidance is the most direct path to certification readiness, and the clearest way to demonstrate mature security practices to customers, partners, and regulators.
The 2022 Revision: 93 Controls, Four Themes
The 2022 update to ISO 27002 restructured the standard significantly, consolidating 114 controls across 14 domains into 93 controls organized under four themes:
Organizational
Policies, roles and responsibilities, supplier relationships, threat intelligence, and cloud service security.
People
Screening, security awareness and training, remote working, and disciplinary and reporting processes.
Physical
Secure areas, physical entry, equipment protection, and physical security monitoring.
Technological
Access control, cryptography, secure development, data leakage prevention, and activity monitoring.
The revision also introduced new controls that reflect how organizations actually operate today, including:
- Threat intelligence — collecting and analyzing information about emerging threats.
- Cloud services security — managing security across acquisition, use, and exit of cloud services.
- Data masking and data leakage prevention — protecting sensitive data in use and in motion.
- Configuration management — hardening and maintaining secure configurations for systems and software.
- Secure coding — building security into the software development lifecycle.
- ICT readiness for business continuity — ensuring technology can support recovery objectives.
ISO 27001 vs. ISO 27002
| ISO 27001 | ISO 27002 | |
|---|---|---|
| Purpose | Defines requirements for establishing and certifying an ISMS. | Provides implementation guidance for the security controls. |
| Certifiable | Yes — organizations certify against ISO 27001. | No — used as a supporting code of practice. |
| Focus | Risk management, governance, and the management system. | The practical "how" of applying each Annex A control. |
| Best Used For | Setting the scope and requirements of your security program. | Designing, implementing, and maturing your controls. |
Why Align with ISO 27002?
| Benefit | What It Means for Your Organization |
|---|---|
| Certification Readiness | Controls built on ISO 27002 guidance map directly to ISO 27001 Annex A, streamlining the path to certification. |
| Customer Trust | Demonstrates mature, internationally benchmarked security practices to clients, partners, and prospects. |
| Regulatory Alignment | Supports compliance obligations under frameworks such as GDPR and HIPAA through a common control baseline. |
| Risk Reduction | Identifies and closes control gaps before they become incidents, reducing the cost of breaches and downtime. |
| Modern Coverage | The 2022 controls address cloud services, threat intelligence, and secure development — not just legacy IT. |
Ascend's ISO 27002 Implementation Roadmap
Our program evaluates your current security program against the 93 controls of ISO 27002:2022 and gives you a clear, prioritized path forward. A typical engagement includes:
- Scoping — defining the systems, locations, and business units your ISMS will cover.
- Gap Analysis — assessing your existing policies, procedures, and technical controls against each applicable ISO 27002 control.
- Risk Assessment — identifying and rating the information security risks that matter most to your business, balanced across confidentiality, integrity, and availability.
- Remediation Roadmap — a prioritized, practical action plan to close the gaps, with guidance your team can actually execute.
- Readiness Validation — confirming your program is prepared for ISO 27001 certification or for demonstrating alignment to customers and regulators.
With 25 years of experience in regulatory guidance, privacy, and cloud architectures, Ascend puts consultation back into audit — we don't just identify gaps, we help you understand and close them.
Whether you are pursuing ISO 27001 certification or simply want your security program benchmarked against the leading international standard, an ISO 27002 implementation program is the right first step. Ask Ascend about ISO 27001 based risk reviews, penetration testing, and vulnerability assessments — contact us today.