Information Security

ISO 27002: The Complete Guide to the 93 Controls

Standarity Editorial Team·ISO/IEC 27001 lead implementers and ISMS practitioners
··6 min read

ISO/IEC 27002:2022 is the implementation guidance companion to ISO 27001. It describes in detail the 93 information security controls listed in Annex A of ISO 27001, explaining the purpose of each control and how to apply it. On its own, ISO 27002 is not a certifiable standard.

How ISO 27002 differs from ISO 27001

The simplest way to remember the split: ISO 27001 tells you what you must do, and ISO 27002 tells you how to do it. ISO 27001 is the certifiable management-system standard that sets requirements for establishing, operating and improving an information security management system (ISMS). ISO 27002 is a detailed guidance document that expands on every Annex A control.

Because ISO 27002 is guidance rather than a set of auditable requirements, you cannot be certified against it. You certify against ISO 27001 and use ISO 27002 as the reference manual your team reaches for when implementing each control. If you are new to the certifiable side, our ISO 27001 implementation guides walk through the management-system clauses in order.

The 93 controls across four themes

The 2022 revision reorganized the control set from the previous 14 domains into four intuitive themes and reduced the total from 114 controls to 93. The consolidation merged overlapping controls and removed outdated references rather than lowering the security bar.

  • Organizational controls (37): policies, roles, supplier relationships, cloud services and governance, found in clause 5.
  • People controls (8): screening, awareness, disciplinary process and remote working, found in clause 6.
  • Physical controls (14): secure perimeters, entry controls, equipment protection and monitoring, found in clause 7.
  • Technological controls (34): access control, cryptography, secure coding, logging and network security, found in clause 8.

The 2022 update cut the control count from 114 to 93, a net reduction of 21, by consolidating overlapping controls and adding 11 new ones for modern threats such as cloud services and data leakage prevention (ISO/IEC 27002:2022; Schellman, 2026).

The five attributes for filtering controls

A major addition in 2022 is a set of five attributes, or metadata tags, attached to every control. They let security managers filter, sort and report on the control set from different stakeholder perspectives rather than reading it as one flat list.

  • Control type: preventive, detective or corrective.
  • Information security properties: confidentiality, integrity or availability.
  • Cybersecurity concepts: identify, protect, detect, respond or recover, aligning with the NIST Cybersecurity Framework.
  • Operational capabilities: practical groupings such as governance, asset management, identity and access management, and continuity.
  • Security domains: governance and ecosystem, protection, defense and resilience.

These tags are practical. A CISO can filter for every detective control, or map the estate against the NIST functions, without rebuilding a spreadsheet by hand. They also make board reporting easier because you can slice the same control set by the lens each audience cares about.

The 11 new controls in the 2022 update

Eleven controls were added to reflect cloud adoption, remote work and modern attack patterns. If you are migrating from the 2013 edition, these are the areas most likely to need fresh implementation work.

  • 5.7 Threat intelligence
  • 5.23 Information security for use of cloud services
  • 5.30 ICT readiness for business continuity
  • 7.4 Physical security monitoring
  • 8.9 Configuration management
  • 8.10 Information deletion
  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.16 Monitoring activities
  • 8.23 Web filtering
  • 8.28 Secure coding

Several of these deserve early attention. Data masking and data leakage prevention matter for any team handling regulated data, and our data classification guidance pairs naturally with them because you cannot protect what you have not classified.

Using ISO 27002 with the Statement of Applicability

During an ISO 27001 project, the two standards work in tandem. You use ISO 27001 to make decisions: scope the ISMS, run the risk assessment, decide which Annex A controls apply, and record those choices in the Statement of Applicability (SoA). The SoA lists every selected control, justifies its inclusion or exclusion, and records its implementation status.

You then use ISO 27002 to implement and prove each control the SoA marks as applicable. When an auditor asks why a control is in scope and how it is operated, ISO 27002 gives you the detailed language to answer. Read alongside our Annex A controls and SoA articles, this is the difference between a checklist and a defensible ISMS.

In short, treat ISO 27002 as the field manual and ISO 27001 as the operating model. Keep them open side by side and both the implementation and the audit become far smoother.

Frequently Asked Questions

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable management-system standard that states what you must do to run an ISMS. ISO 27002 is guidance that explains how to implement the 93 Annex A controls in detail. You certify against 27001 and use 27002 as the reference manual for each control.

Can you be certified against ISO 27002?

No. ISO 27002 is a guidance document, not a set of auditable requirements, so no certificate is issued against it. Organizations achieve certification against ISO 27001 and rely on ISO 27002 to implement and evidence the controls that ISO 27001 requires.

How many controls are in ISO 27002:2022?

ISO 27002:2022 contains 93 controls, down from 114 in the 2013 edition. They are grouped into four themes: 37 organizational, 8 people, 14 physical and 34 technological. The reduction came from consolidating overlapping controls while adding 11 new ones.

What are the 11 new controls in ISO 27002:2022?

The 11 new controls are threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. They address cloud adoption and modern threats.

What are the five ISO 27002 attributes?

The five attributes are control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They are metadata tags on every control that let teams filter and report on the control set by different lenses, including alignment with the NIST Cybersecurity Framework.

How does ISO 27002 relate to the Statement of Applicability?

The Statement of Applicability lists which Annex A controls apply to your ISMS and justifies each inclusion or exclusion. You use ISO 27001 to select and document controls in the SoA, then use ISO 27002 to implement and prove each applicable control during the project and the audit.

Explore Courses on Udemy

Intermediate

ISO 27001:2022 Implementation Step by Step with Templates

Intermediate

ISO 27001:2022 Data Classification Step by Step

Intermediate

AI-Powered ISO 27001-2022 Implementation Step by Step