ISO/IEC 27002:2022 is the implementation guidance companion to ISO 27001. It describes in detail the 93 information security controls listed in Annex A of ISO 27001, explaining the purpose of each control and how to apply it. On its own, ISO 27002 is not a certifiable standard.
How ISO 27002 differs from ISO 27001
The simplest way to remember the split: ISO 27001 tells you what you must do, and ISO 27002 tells you how to do it. ISO 27001 is the certifiable management-system standard that sets requirements for establishing, operating and improving an information security management system (ISMS). ISO 27002 is a detailed guidance document that expands on every Annex A control.
Because ISO 27002 is guidance rather than a set of auditable requirements, you cannot be certified against it. You certify against ISO 27001 and use ISO 27002 as the reference manual your team reaches for when implementing each control. If you are new to the certifiable side, our ISO 27001 implementation guides walk through the management-system clauses in order.
The 93 controls across four themes
The 2022 revision reorganized the control set from the previous 14 domains into four intuitive themes and reduced the total from 114 controls to 93. The consolidation merged overlapping controls and removed outdated references rather than lowering the security bar.
- Organizational controls (37): policies, roles, supplier relationships, cloud services and governance, found in clause 5.
- People controls (8): screening, awareness, disciplinary process and remote working, found in clause 6.
- Physical controls (14): secure perimeters, entry controls, equipment protection and monitoring, found in clause 7.
- Technological controls (34): access control, cryptography, secure coding, logging and network security, found in clause 8.
The 2022 update cut the control count from 114 to 93, a net reduction of 21, by consolidating overlapping controls and adding 11 new ones for modern threats such as cloud services and data leakage prevention (ISO/IEC 27002:2022; Schellman, 2026).
The five attributes for filtering controls
A major addition in 2022 is a set of five attributes, or metadata tags, attached to every control. They let security managers filter, sort and report on the control set from different stakeholder perspectives rather than reading it as one flat list.
- Control type: preventive, detective or corrective.
- Information security properties: confidentiality, integrity or availability.
- Cybersecurity concepts: identify, protect, detect, respond or recover, aligning with the NIST Cybersecurity Framework.
- Operational capabilities: practical groupings such as governance, asset management, identity and access management, and continuity.
- Security domains: governance and ecosystem, protection, defense and resilience.
These tags are practical. A CISO can filter for every detective control, or map the estate against the NIST functions, without rebuilding a spreadsheet by hand. They also make board reporting easier because you can slice the same control set by the lens each audience cares about.
The 11 new controls in the 2022 update
Eleven controls were added to reflect cloud adoption, remote work and modern attack patterns. If you are migrating from the 2013 edition, these are the areas most likely to need fresh implementation work.
- 5.7 Threat intelligence
- 5.23 Information security for use of cloud services
- 5.30 ICT readiness for business continuity
- 7.4 Physical security monitoring
- 8.9 Configuration management
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
- 8.16 Monitoring activities
- 8.23 Web filtering
- 8.28 Secure coding
Several of these deserve early attention. Data masking and data leakage prevention matter for any team handling regulated data, and our data classification guidance pairs naturally with them because you cannot protect what you have not classified.
Using ISO 27002 with the Statement of Applicability
During an ISO 27001 project, the two standards work in tandem. You use ISO 27001 to make decisions: scope the ISMS, run the risk assessment, decide which Annex A controls apply, and record those choices in the Statement of Applicability (SoA). The SoA lists every selected control, justifies its inclusion or exclusion, and records its implementation status.
You then use ISO 27002 to implement and prove each control the SoA marks as applicable. When an auditor asks why a control is in scope and how it is operated, ISO 27002 gives you the detailed language to answer. Read alongside our Annex A controls and SoA articles, this is the difference between a checklist and a defensible ISMS.
In short, treat ISO 27002 as the field manual and ISO 27001 as the operating model. Keep them open side by side and both the implementation and the audit become far smoother.