ISO 27002

What Is ISO 27002?

ISO/IEC 27002 is the internationally recognized code of practice for information security controls. Where ISO 27001 defines the requirements for building and certifying an Information Security Management System (ISMS), ISO 27002 provides the detailed, practical guidance for implementing the controls listed in ISO 27001's Annex A. In short: ISO 27001 tells you what a compliant security program must achieve, and ISO 27002 shows you how to get there.

Organizations cannot certify against ISO 27002 itself — certification is against ISO 27001. But a security program built on ISO 27002 guidance is the most direct path to certification readiness, and the clearest way to demonstrate mature security practices to customers, partners, and regulators.

The 2022 Revision: 93 Controls, Four Themes

The 2022 update to ISO 27002 restructured the standard significantly, consolidating 114 controls across 14 domains into 93 controls organized under four themes:

37 CONTROLS

Organizational

Policies, roles and responsibilities, supplier relationships, threat intelligence, and cloud service security.

8 CONTROLS

People

Screening, security awareness and training, remote working, and disciplinary and reporting processes.

14 CONTROLS

Physical

Secure areas, physical entry, equipment protection, and physical security monitoring.

34 CONTROLS

Technological

Access control, cryptography, secure development, data leakage prevention, and activity monitoring.

The revision also introduced new controls that reflect how organizations actually operate today, including:

  • Threat intelligence — collecting and analyzing information about emerging threats.
  • Cloud services security — managing security across acquisition, use, and exit of cloud services.
  • Data masking and data leakage prevention — protecting sensitive data in use and in motion.
  • Configuration management — hardening and maintaining secure configurations for systems and software.
  • Secure coding — building security into the software development lifecycle.
  • ICT readiness for business continuity — ensuring technology can support recovery objectives.

ISO 27001 vs. ISO 27002

ISO 27001ISO 27002
PurposeDefines requirements for establishing and certifying an ISMS.Provides implementation guidance for the security controls.
CertifiableYes — organizations certify against ISO 27001.No — used as a supporting code of practice.
FocusRisk management, governance, and the management system.The practical "how" of applying each Annex A control.
Best Used ForSetting the scope and requirements of your security program.Designing, implementing, and maturing your controls.

Why Align with ISO 27002?

BenefitWhat It Means for Your Organization
Certification ReadinessControls built on ISO 27002 guidance map directly to ISO 27001 Annex A, streamlining the path to certification.
Customer TrustDemonstrates mature, internationally benchmarked security practices to clients, partners, and prospects.
Regulatory AlignmentSupports compliance obligations under frameworks such as GDPR and HIPAA through a common control baseline.
Risk ReductionIdentifies and closes control gaps before they become incidents, reducing the cost of breaches and downtime.
Modern CoverageThe 2022 controls address cloud services, threat intelligence, and secure development — not just legacy IT.

Ascend's ISO 27002 Implementation Roadmap

Our program evaluates your current security program against the 93 controls of ISO 27002:2022 and gives you a clear, prioritized path forward. A typical engagement includes:

  1. Scoping — defining the systems, locations, and business units your ISMS will cover.
  2. Gap Analysis — assessing your existing policies, procedures, and technical controls against each applicable ISO 27002 control.
  3. Risk Assessment — identifying and rating the information security risks that matter most to your business, balanced across confidentiality, integrity, and availability.
  4. Remediation Roadmap — a prioritized, practical action plan to close the gaps, with guidance your team can actually execute.
  5. Readiness Validation — confirming your program is prepared for ISO 27001 certification or for demonstrating alignment to customers and regulators.

With 25 years of experience in regulatory guidance, privacy, and cloud architectures, Ascend puts consultation back into audit — we don't just identify gaps, we help you understand and close them.

Whether you are pursuing ISO 27001 certification or simply want your security program benchmarked against the leading international standard, an ISO 27002 implementation program is the right first step. Ask Ascend about ISO 27001 based risk reviews, penetration testing, and vulnerability assessments — contact us today.