ISO/IEC 27002
ISO/IEC 27002 is an international standard that offers guidance and best-practice recommendations to help organizations select, implement, and improve information security controls. It is designed for organizations of all types and sizes and serves as a reference rather than a strict certification requirement on its own. Readers should note that guidance content changes across revisions, so the current authoritative text should be verified against the applicable version.
ISO/IEC 27002, jointly published and maintained by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), provides guidelines and a code of practice for information security controls, including guidance on determining, selecting, and implementing controls within an information security management context. It is generally used as a companion reference to related standards in the ISO/IEC 27000 family and functions as advisory guidance rather than a directly auditable specification. The control set and its structure have changed across revisions (for example, the 2013 and 2022 editions), so practitioners should confirm which revision applies and consult the current official ISO/IEC text. This entry does not address certification, contractual, or mapping specifics to U.S. federal frameworks such as NIST SP 800-53, NIST SP 800-171, FedRAMP, or CMMC, which are issued and maintained by separate authorities and impose distinct requirements.
Why it matters
ISO/IEC 27002 matters because it gives organizations a common, internationally recognized vocabulary and reference for selecting and implementing information security controls. Rather than leaving each organization to invent its own control catalog, the standard offers best-practice guidance that can be adapted to organizations of all types and sizes. This shared foundation supports consistency across business units, supply chains, and international partners, and it complements the broader ISO/IEC 27000 family of standards used within an information security management context.
For compliance and security professionals, an important distinction is that ISO/IEC 27002 functions as advisory guidance and a code of practice rather than a directly auditable specification or a certification standard on its own. It helps practitioners determine and implement controls, but relying on it should not be confused with achieving certification or with satisfying the distinct, separately maintained requirements of U.S. federal frameworks. Treating adoption of ISO/IEC 27002 as automatic compliance with NIST SP 800-53, NIST SP 800-171, FedRAMP, or CMMC would be a mistake, because those frameworks are issued and maintained by different authorities and impose their own obligations.
Because the standard's control set and structure have changed across revisions, such as the 2013 and 2022 editions, professionals must confirm which revision applies to their engagement and consult the current official ISO/IEC text. Guidance content is not static, and mappings or crosswalks built against an older revision may no longer align with the current edition. Readers should verify the authoritative version before relying on specific control language.
Who it's relevant to
Inside ISO/IEC 27002
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27002.