Skip to main content
Category: NIST Standards & Publications

ISO/IEC 27002

Also known as: ISO 27002, ISO/IEC 27002:2022, Code of practice for information security controls
Simply put

ISO/IEC 27002 is an international standard that offers guidance and best-practice recommendations to help organizations select, implement, and improve information security controls. It is designed for organizations of all types and sizes and serves as a reference rather than a strict certification requirement on its own. Readers should note that guidance content changes across revisions, so the current authoritative text should be verified against the applicable version.

Formal definition

ISO/IEC 27002, jointly published and maintained by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), provides guidelines and a code of practice for information security controls, including guidance on determining, selecting, and implementing controls within an information security management context. It is generally used as a companion reference to related standards in the ISO/IEC 27000 family and functions as advisory guidance rather than a directly auditable specification. The control set and its structure have changed across revisions (for example, the 2013 and 2022 editions), so practitioners should confirm which revision applies and consult the current official ISO/IEC text. This entry does not address certification, contractual, or mapping specifics to U.S. federal frameworks such as NIST SP 800-53, NIST SP 800-171, FedRAMP, or CMMC, which are issued and maintained by separate authorities and impose distinct requirements.

Why it matters

ISO/IEC 27002 matters because it gives organizations a common, internationally recognized vocabulary and reference for selecting and implementing information security controls. Rather than leaving each organization to invent its own control catalog, the standard offers best-practice guidance that can be adapted to organizations of all types and sizes. This shared foundation supports consistency across business units, supply chains, and international partners, and it complements the broader ISO/IEC 27000 family of standards used within an information security management context.

For compliance and security professionals, an important distinction is that ISO/IEC 27002 functions as advisory guidance and a code of practice rather than a directly auditable specification or a certification standard on its own. It helps practitioners determine and implement controls, but relying on it should not be confused with achieving certification or with satisfying the distinct, separately maintained requirements of U.S. federal frameworks. Treating adoption of ISO/IEC 27002 as automatic compliance with NIST SP 800-53, NIST SP 800-171, FedRAMP, or CMMC would be a mistake, because those frameworks are issued and maintained by different authorities and impose their own obligations.

Because the standard's control set and structure have changed across revisions, such as the 2013 and 2022 editions, professionals must confirm which revision applies to their engagement and consult the current official ISO/IEC text. Guidance content is not static, and mappings or crosswalks built against an older revision may no longer align with the current edition. Readers should verify the authoritative version before relying on specific control language.

Who it's relevant to

Information Security and ISMS Practitioners
Those responsible for initiating, implementing, or maintaining an information security management program can use ISO/IEC 27002 as a reference for selecting and implementing controls. Practitioners should treat it as best-practice guidance to be tailored to their organization, and confirm which revision applies before relying on specific control language.
Compliance Officers and Auditors
Compliance and audit personnel benefit from ISO/IEC 27002 as a shared reference vocabulary, but should recognize it is a code of practice and advisory guidance rather than a directly auditable specification on its own. They should not assume it substitutes for the distinct requirements of separately maintained federal frameworks such as NIST SP 800-53, NIST SP 800-171, FedRAMP, or CMMC.
Government Contractors Operating Internationally
Contractors that work across international partners or supply chains may encounter ISO/IEC 27002 as a common control reference. They should verify that adoption of the standard is not conflated with satisfying U.S. federal obligations, which are issued and maintained by separate authorities and carry their own requirements that must be confirmed against current official sources.
Organizations of All Types and Sizes
The standard is explicitly designed to be used as a reference by organizations regardless of type or size. Smaller organizations without a mature security program can use its guidance to determine and implement appropriate controls, adapting recommendations to their own risk context and verifying the applicable revision.

Inside ISO/IEC 27002

Implementation Guidance for Controls
ISO/IEC 27002 provides detailed guidance and recommended practices for information security controls. It generally functions as a companion to ISO/IEC 27001, elaborating on how controls may be implemented rather than serving as the certifiable requirements standard itself. Readers should confirm the current edition against the official ISO/IEC text, as the standard has been revised over time.
Control Themes and Categories
The standard organizes security controls into thematic groupings covering areas such as organizational, people, physical, and technological measures in more recent editions. The specific structure and categorization have changed between revisions, so practitioners should verify which edition applies to their program.
Advisory (Non-Certifiable) Nature
ISO/IEC 27002 is generally treated as a code of practice or guidance document. Certification is typically pursued against ISO/IEC 27001, not 27002. This entry does not cover certification procedures, which readers must confirm against current ISO and accreditation body sources.
Relationship to an ISMS
The guidance is intended to support the selection and implementation of controls within an Information Security Management System (ISMS). It informs, but does not by itself constitute, the management system requirements defined elsewhere in the ISO/IEC 27000 family.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27002.

Does implementing ISO/IEC 27002 mean my organization is certified against it?
No. ISO/IEC 27002 is a guidance document offering a catalog of information security controls and implementation advice; it is not itself a certifiable standard. Certification within the ISO/IEC 27000 family is generally issued against ISO/IEC 27001, which specifies requirements for an information security management system (ISMS). ISO/IEC 27002 supports the selection and implementation of controls but does not confer certification on its own. Confirm current certification scope against the official standards text, as the relationship between the documents has been updated across revisions.
Is ISO/IEC 27002 the same as ISO/IEC 27001, or interchangeable with it?
They are distinct documents with different purposes and should not be treated as interchangeable. ISO/IEC 27001 sets out the requirements an organization must meet to establish and maintain an ISMS and is the basis for certification. ISO/IEC 27002 provides more detailed guidance and implementation considerations for the controls referenced in the ISMS context. In most implementations, organizations use ISO/IEC 27002 as a reference to help operationalize the controls, while conformance is assessed against ISO/IEC 27001. Verify the precise scope of each against the current authoritative editions.
How does ISO/IEC 27002 relate to U.S. federal control frameworks such as NIST SP 800-53?
ISO/IEC 27002 is an international guidance document maintained by ISO and IEC, while NIST SP 800-53 is a control catalog maintained by NIST for U.S. federal information systems. They are separate frameworks issued by different bodies and are not directly substitutable. NIST has historically published control mappings between its catalog and international standards to help organizations relate the two, but such mappings are cross-references rather than statements of equivalence. Organizations subject to FISMA, RMF, or CUI-related requirements should confirm which framework their specific obligations mandate, as adopting ISO/IEC 27002 does not by itself satisfy those federal requirements.
Can an organization use ISO/IEC 27002 to help select controls for an ISMS?
Yes. A common use of ISO/IEC 27002 is as a reference during control selection and implementation, providing detailed guidance on how controls can be applied. In most implementations, organizations tailor the guidance to their own risk profile, operating environment, and applicable regulatory obligations rather than adopting every control uniformly. The document is intended to inform decisions rather than to prescribe a fixed baseline, so implementation choices should be documented and justified against the organization's risk assessment.
How should an organization handle differences between ISO/IEC 27002 revisions when updating its control set?
Because ISO/IEC 27002 has been revised over time, including restructuring of how controls are organized, organizations should confirm which edition applies to their program and reconcile any structural or content changes when updating. Prefer working from the current authoritative text rather than relying on summaries, and treat any internal crosswalks between editions as items to verify. Do not assume control identifiers or groupings remain stable across revisions; check the applicable version before making mapping decisions.
Does adopting ISO/IEC 27002 guidance demonstrate that an organization is secure?
No. Following ISO/IEC 27002 guidance supports a structured approach to information security controls, but implementing a control set is not equivalent to being secure. Security depends on how controls are operated, monitored, and maintained over time, as well as on ongoing risk management. Compliance with a guidance document or conformance to a related standard should be understood as one input to a security program, not as a guarantee of protection against threats.

Common misconceptions

You can be certified against ISO/IEC 27002.
Certification is generally pursued against ISO/IEC 27001, which contains the auditable management system requirements. ISO/IEC 27002 typically serves as advisory implementation guidance rather than a certifiable standard. Readers should verify the certification scope against current ISO sources.
ISO/IEC 27002 is a U.S. federal control baseline comparable to NIST SP 800-53 or a mandated requirement for federal or defense systems.
ISO/IEC 27002 is an international standard issued by ISO and IEC, distinct from NIST publications and from FISMA, FedRAMP, RMF, or CMMC requirements. Alignment with ISO/IEC 27002 does not by itself satisfy DoD, federal civilian, or CUI-related obligations, which are governed by separate authorities and must be confirmed against the applicable regulation.
Implementing every control in ISO/IEC 27002 makes an organization secure and compliant.
The standard provides guidance, not a guarantee of security, and compliance is not equivalent to security. Controls generally require tailoring to organizational risk, and their applicability and effectiveness depend on implementation, which is out of scope for the guidance document itself.

Best practices

Use ISO/IEC 27002 as implementation guidance in conjunction with ISO/IEC 27001, keeping the distinction between advisory guidance and certifiable requirements clear in program documentation.
Confirm which edition of ISO/IEC 27002 applies to your program, since the control structure and categories have changed across revisions.
Do not assume alignment with ISO/IEC 27002 satisfies U.S. federal, defense, or CUI requirements; map obligations separately against the governing authorities such as NIST, FedRAMP, RMF, or CMMC and verify against current official sources.
Tailor control selection to organizational risk rather than adopting all guidance uniformly, and document the rationale for inclusion or exclusion.
Treat the standard as one input into an ISMS, coordinating it with the management system requirements defined in the broader ISO/IEC 27000 family.
Periodically review implementations against the current authoritative ISO/IEC text, as guidance and terminology continue to evolve across editions.