On this page
- How do ISO 27002 and ISO 27001 differ?
- Which document should you start with?
- Can an organization be certified to ISO 27002?
- Does ISO 27001 require every ISO 27002 control?
- What changed in the 2022 editions?
- How does ISO 27002 change control 5.23?
- What should you settle before buying help?
- Questions buyers ask
If a customer asks for an ISO 27001 certificate, ISO 27002 will not satisfy the request. ISO/IEC 27001:2022, Information security management systems — Requirements, is the standard a certification body assesses. ISO/IEC 27002:2022, Information security controls, is guidance for the 93 controls in Annex A of ISO 27001. It is not an alternative certificate.
The 2022 editions share that control list. Annex A names each control. ISO 27002 adds a purpose, guidance, and other information, and tags each control with five attributes, such as control type and security domain. Certification follows ISO/IEC 27001. Control design follows ISO/IEC 27002. Our compliance framework comparison lines ISO 27001 up against SOC 2 and the other frameworks.
How do ISO 27002 and ISO 27001 differ?
ISO/IEC 27001:2022 sets the information security management system (ISMS) requirements a certification body assesses. ISO/IEC 27002:2022 gives purpose, guidance, and other information for the same 93 controls. Only ISO 27001 produces a certificate.
| ISO/IEC 27001:2022 | ISO/IEC 27002:2022 | |
|---|---|---|
| Job | Requirements for an ISMS | Guidance for information security controls |
| Certification | A certification body can certify a defined ISMS scope | No certification scheme |
| Published | 25 October 2022 | 15 February 2022, with a corrected English version in March 2022 |
| Text a reader uses | Clauses 4–10, plus Annex A as the control reference | Control text, purpose, guidance, and other information |
| Control catalogue | Annex A lists 93 controls | The same 93 controls |
| 2013 edition | 114 Annex A controls in 14 domains | 114 controls in 14 clauses |
| 2022 edition | Annex A aligned to the four ISO 27002 themes | 37 organizational, 8 people, 14 physical, 34 technological |
| Buyer output | A certificate that names the ISMS scope | A control design. Not a certificate |
Organizational and technological controls account for 71 of those 93. In document order the themes are organizational (clause 5, 37 controls), people (clause 6, 8), physical (clause 7, 14), and technological (clause 8, 34). Sorted by size:
| Theme | Clause | Controls |
|---|---|---|
| Organizational | 5 | 37 |
| Technological | 8 | 34 |
| Physical | 7 | 14 |
| People | 6 | 8 |
The ISO/IEC 27002:2022 editors, writing in the ISO/IEC JTC 1/SC 27 journal, record the move from 114 controls to 93, the four theme counts, and the addition of a purpose, guidance, and other information on every control. ISO’s 25 October 2022 notice marks publication of ISO/IEC 27001:2022. The ISO 27002 page records publication on 15 February 2022. ANAB’s revision summary confirms that ISO/IEC 27001:2022 Annex A uses those same four themes and 93 controls.
Which document should you start with?
Start with ISO/IEC 27001 when the output is a certificate, ISO/IEC 27002 when the job is to design a control, and both when you are preparing the ISMS a certification body will assess.
| Your task | Start with | Output to expect |
|---|---|---|
| A contract requires an ISO 27001 certificate | ISO/IEC 27001:2022 | An ISMS within a defined scope, assessed by a certification body |
| Your team needs to design or improve security controls | ISO/IEC 27002:2022 | Control procedures suited to your risks and systems. No ISO 27002 certificate |
| You are preparing for ISO 27001 certification | Both | An ISO 27001 risk treatment and Statement of Applicability, using ISO 27002 where it helps implement the controls you selected |
Can an organization be certified to ISO 27002?
No. ISO/IEC 27002:2022 is guidance, and it has no certification scheme. An accredited certification body assesses an ISMS against ISO/IEC 27001:2022 for a defined scope.
The editors of ISO 27002 describe the document as standalone guidance or as support for an ISMS that meets ISO 27001. A control manual, a policy pack, or a completed checklist is not that certificate.
Confirm the scope before you compare providers. A certificate can cover one product, one legal entity, or a named set of sites. A narrow certificate can leave out the service a customer expects to see.
Does ISO 27001 require every ISO 27002 control?
No. ISO/IEC 27001 clause 6.1.3 requires the organization to determine the controls its risks need, compare that set with Annex A, and justify exclusions in the Statement of Applicability (SoA). Implementing every ISO 27002 control is not the requirement.
The Auditing Practices Group’s Annex A note describes that comparison as a check that necessary controls were not omitted. The companion SoA note describes the SoA as the record of necessary controls, why they are included, whether they are implemented, and why any Annex A control is excluded.
Annex A is a reference set. The SoA note says the list is not complete and not a recommendation that every organization implement every row. An organization can design its own controls or take them from another source, such as ISO/IEC 27017 or NIST. A control’s presence in Annex A does not, by itself, make that control necessary.
ISO 27002 can inform the design of a control the organization has selected. Its guidance is not a second mandatory checklist, and an auditor assesses the implemented ISMS against ISO 27001.
What changed in the 2022 editions?
ISO/IEC 27002:2022, published on 15 February 2022, replaced 114 controls in 14 groups with 93 controls in four themes and added 11 new controls. ISO/IEC 27001:2022, published on 25 October 2022, puts that same set in Annex A. To see where each 2013 domain went and how the four themes line up with SOC 2, read ISO 27001 domains and themes.
The editors also record that 24 of the 93 controls resulted from merging earlier controls, and that each control now carries five attributes so a team can filter or sort the catalogue. ANAB’s summary of the revision names those attributes: control type (preventive, detective, or corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities (for example identity and access management), and security domains (for example protection). Organizations may ignore an attribute or add their own. Annex B of ISO 27002 maps the 2013 control numbers to the 2022 numbers.
IAF MD 26 required certification bodies to complete client transitions from ISO/IEC 27001:2013 by 31 October 2025. A certificate that still names the 2013 edition did not complete that transition.
The editors’ journal records 11 new controls and discusses 5.23 and 8.23 by number. Protiviti’s note on the 2022 Annex A lists the same eleven. Annex A writes the same numbers with an A. prefix, such as A.5.7.
| Control | Added in 2022 |
|---|---|
| 5.7 | Threat intelligence |
| 5.23 | Information security for use of cloud services |
| 5.30 | ICT readiness for business continuity |
| 7.4 | Physical security monitoring |
| 8.9 | Configuration management |
| 8.10 | Information deletion |
| 8.11 | Data masking |
| 8.12 | Data leakage prevention |
| 8.16 | Monitoring activities |
| 8.23 | Web filtering |
| 8.28 | Secure coding |
How does ISO 27002 change control 5.23?
Control 5.23, information security for use of cloud services, is one of the 11 controls added in 2022. Annex A of ISO/IEC 27001 names the control. ISO/IEC 27002 adds the design guidance. In the 2013 edition, cloud use sat inside the supplier-relationship controls rather than in its own control.
Benoit Heynderickx’s note in the same SC 27 journal describes control 5.23 from the cloud customer’s side of the lifecycle: acquisition, use, management, and exit. Shared responsibility between the customer and the provider is the principle that runs through the control. The note says a customer typically keeps more of the controls when the service is infrastructure than when it is software, where access management and data protection remain with the customer. Supplier controls 5.19, 5.20, and 5.22 still apply to the provider as a supplier. They do not replace 5.23. Related cloud guidance sits in ISO/IEC 27017 and ISO/IEC 27018, not in a second certificate.
For a team that selects control 5.23, a useful working record covers the topics that note identifies:
| Record | What to write down |
|---|---|
| Services in scope | Which cloud services are in use, and whether each is infrastructure, platform, or software |
| Shared responsibility | Which controls the provider operates, and which the company operates |
| Approval and risk | Who approves use, and which risks the risk assessment treated |
| Contract and change | What the agreement requires, and how the company learns about a provider change such as location or infrastructure |
| Monitoring and exit | What monitoring runs, and how the company would leave the service |
The control 5.23 record is a planning aid. It is not a quotation of ISO/IEC 27002, and it does not decide a certification. The ISMS owner still connects the design to the risk assessment, the treatment decision, the SoA, and the operating evidence that ISO/IEC 27001 requires. If a different control design addresses the risk, the SoA states why.
Any selected control, not only control 5.23, needs one working record:
| Field | What to record |
|---|---|
| Scope and risk | Which service, information, and risk this decision covers |
| Treatment | Which control or other treatment was selected, and who owns it |
| Annex A | Whether the related Annex A control is included. If excluded, the justification |
| ISO 27002 | Which guidance shaped the design, and where the team adapted it |
| Evidence | What happens, how often, who checks it, and which record proves it happened |
The failure the working record makes visible: a control can appear in the SoA while nobody can show how it operates.
What should you settle before buying help?
Ask the customer which deliverable it will accept: an ISO/IEC 27001 certificate for a named scope, evidence of particular controls, or help building the ISMS. A guidance document cannot be sold as certification. Price implementation support separately from the certification body’s fee, and confirm the proposed scope before you compare sellers. Our guide to ISO certification consultants covers what an ISO adviser does and how it differs from the certification body.
If you need help building the ISMS and the control evidence, compare ISO 27001 consultants. If you are ready to select the certification body, compare ISO 27001 certification companies. Budget the certification lifecycle separately from implementation support. For a choice between a certificate and a SOC 2 report, see SOC 2 vs ISO 27001.
Questions buyers ask
What is the difference between ISO 27001 and ISO 27002?
ISO/IEC 27001:2022 sets requirements for an ISMS and is the standard a certification body assesses. ISO/IEC 27002:2022 is guidance for the same 93 controls. Annex A names each control. ISO 27002 adds purpose, guidance, and other information. Only ISO 27001 produces a certificate.
What is ISO 27002 used for?
Teams use ISO/IEC 27002:2022 to design and improve information security controls. Each entry has the control text, a purpose, guidance, and other information, plus five attributes for filtering the set. ISO 27002 does not certify an organization.
Is ISO 27001 still relevant?
Yes. The current edition is ISO/IEC 27001:2022, published on 25 October 2022. IAF MD 26 required certification bodies to complete client transitions from ISO/IEC 27001:2013 by 31 October 2025. A certificate that still names the 2013 edition did not complete that transition.
More in Framework Comparisons