On this page

If a customer asks for an ISO 27001 certificate, ISO 27002 will not satisfy the request. ISO/IEC 27001:2022, Information security management systems — Requirements, is the standard a certification body assesses. ISO/IEC 27002:2022, Information security controls, is guidance for the 93 controls in Annex A of ISO 27001. It is not an alternative certificate.

The 2022 editions share that control list. Annex A names each control. ISO 27002 adds a purpose, guidance, and other information, and tags each control with five attributes, such as control type and security domain. Certification follows ISO/IEC 27001. Control design follows ISO/IEC 27002. Our compliance framework comparison lines ISO 27001 up against SOC 2 and the other frameworks.

How do ISO 27002 and ISO 27001 differ?

ISO/IEC 27001:2022 sets the information security management system (ISMS) requirements a certification body assesses. ISO/IEC 27002:2022 gives purpose, guidance, and other information for the same 93 controls. Only ISO 27001 produces a certificate.

ISO/IEC 27001:2022ISO/IEC 27002:2022
JobRequirements for an ISMSGuidance for information security controls
CertificationA certification body can certify a defined ISMS scopeNo certification scheme
Published25 October 202215 February 2022, with a corrected English version in March 2022
Text a reader usesClauses 4–10, plus Annex A as the control referenceControl text, purpose, guidance, and other information
Control catalogueAnnex A lists 93 controlsThe same 93 controls
2013 edition114 Annex A controls in 14 domains114 controls in 14 clauses
2022 editionAnnex A aligned to the four ISO 27002 themes37 organizational, 8 people, 14 physical, 34 technological
Buyer outputA certificate that names the ISMS scopeA control design. Not a certificate

Organizational and technological controls account for 71 of those 93. In document order the themes are organizational (clause 5, 37 controls), people (clause 6, 8), physical (clause 7, 14), and technological (clause 8, 34). Sorted by size:

ThemeClauseControls
Organizational537
Technological834
Physical714
People68

The ISO/IEC 27002:2022 editors, writing in the ISO/IEC JTC 1/SC 27 journal, record the move from 114 controls to 93, the four theme counts, and the addition of a purpose, guidance, and other information on every control. ISO’s 25 October 2022 notice marks publication of ISO/IEC 27001:2022. The ISO 27002 page records publication on 15 February 2022. ANAB’s revision summary confirms that ISO/IEC 27001:2022 Annex A uses those same four themes and 93 controls.

Which document should you start with?

Start with ISO/IEC 27001 when the output is a certificate, ISO/IEC 27002 when the job is to design a control, and both when you are preparing the ISMS a certification body will assess.

Your taskStart withOutput to expect
A contract requires an ISO 27001 certificateISO/IEC 27001:2022An ISMS within a defined scope, assessed by a certification body
Your team needs to design or improve security controlsISO/IEC 27002:2022Control procedures suited to your risks and systems. No ISO 27002 certificate
You are preparing for ISO 27001 certificationBothAn ISO 27001 risk treatment and Statement of Applicability, using ISO 27002 where it helps implement the controls you selected

Can an organization be certified to ISO 27002?

No. ISO/IEC 27002:2022 is guidance, and it has no certification scheme. An accredited certification body assesses an ISMS against ISO/IEC 27001:2022 for a defined scope.

The editors of ISO 27002 describe the document as standalone guidance or as support for an ISMS that meets ISO 27001. A control manual, a policy pack, or a completed checklist is not that certificate.

Confirm the scope before you compare providers. A certificate can cover one product, one legal entity, or a named set of sites. A narrow certificate can leave out the service a customer expects to see.

Does ISO 27001 require every ISO 27002 control?

No. ISO/IEC 27001 clause 6.1.3 requires the organization to determine the controls its risks need, compare that set with Annex A, and justify exclusions in the Statement of Applicability (SoA). Implementing every ISO 27002 control is not the requirement.

The Auditing Practices Group’s Annex A note describes that comparison as a check that necessary controls were not omitted. The companion SoA note describes the SoA as the record of necessary controls, why they are included, whether they are implemented, and why any Annex A control is excluded.

Annex A is a reference set. The SoA note says the list is not complete and not a recommendation that every organization implement every row. An organization can design its own controls or take them from another source, such as ISO/IEC 27017 or NIST. A control’s presence in Annex A does not, by itself, make that control necessary.

ISO 27002 can inform the design of a control the organization has selected. Its guidance is not a second mandatory checklist, and an auditor assesses the implemented ISMS against ISO 27001.

What changed in the 2022 editions?

ISO/IEC 27002:2022, published on 15 February 2022, replaced 114 controls in 14 groups with 93 controls in four themes and added 11 new controls. ISO/IEC 27001:2022, published on 25 October 2022, puts that same set in Annex A. To see where each 2013 domain went and how the four themes line up with SOC 2, read ISO 27001 domains and themes.

The editors also record that 24 of the 93 controls resulted from merging earlier controls, and that each control now carries five attributes so a team can filter or sort the catalogue. ANAB’s summary of the revision names those attributes: control type (preventive, detective, or corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities (for example identity and access management), and security domains (for example protection). Organizations may ignore an attribute or add their own. Annex B of ISO 27002 maps the 2013 control numbers to the 2022 numbers.

IAF MD 26 required certification bodies to complete client transitions from ISO/IEC 27001:2013 by 31 October 2025. A certificate that still names the 2013 edition did not complete that transition.

The editors’ journal records 11 new controls and discusses 5.23 and 8.23 by number. Protiviti’s note on the 2022 Annex A lists the same eleven. Annex A writes the same numbers with an A. prefix, such as A.5.7.

ControlAdded in 2022
5.7Threat intelligence
5.23Information security for use of cloud services
5.30ICT readiness for business continuity
7.4Physical security monitoring
8.9Configuration management
8.10Information deletion
8.11Data masking
8.12Data leakage prevention
8.16Monitoring activities
8.23Web filtering
8.28Secure coding

How does ISO 27002 change control 5.23?

Control 5.23, information security for use of cloud services, is one of the 11 controls added in 2022. Annex A of ISO/IEC 27001 names the control. ISO/IEC 27002 adds the design guidance. In the 2013 edition, cloud use sat inside the supplier-relationship controls rather than in its own control.

Benoit Heynderickx’s note in the same SC 27 journal describes control 5.23 from the cloud customer’s side of the lifecycle: acquisition, use, management, and exit. Shared responsibility between the customer and the provider is the principle that runs through the control. The note says a customer typically keeps more of the controls when the service is infrastructure than when it is software, where access management and data protection remain with the customer. Supplier controls 5.19, 5.20, and 5.22 still apply to the provider as a supplier. They do not replace 5.23. Related cloud guidance sits in ISO/IEC 27017 and ISO/IEC 27018, not in a second certificate.

For a team that selects control 5.23, a useful working record covers the topics that note identifies:

RecordWhat to write down
Services in scopeWhich cloud services are in use, and whether each is infrastructure, platform, or software
Shared responsibilityWhich controls the provider operates, and which the company operates
Approval and riskWho approves use, and which risks the risk assessment treated
Contract and changeWhat the agreement requires, and how the company learns about a provider change such as location or infrastructure
Monitoring and exitWhat monitoring runs, and how the company would leave the service

The control 5.23 record is a planning aid. It is not a quotation of ISO/IEC 27002, and it does not decide a certification. The ISMS owner still connects the design to the risk assessment, the treatment decision, the SoA, and the operating evidence that ISO/IEC 27001 requires. If a different control design addresses the risk, the SoA states why.

Any selected control, not only control 5.23, needs one working record:

FieldWhat to record
Scope and riskWhich service, information, and risk this decision covers
TreatmentWhich control or other treatment was selected, and who owns it
Annex AWhether the related Annex A control is included. If excluded, the justification
ISO 27002Which guidance shaped the design, and where the team adapted it
EvidenceWhat happens, how often, who checks it, and which record proves it happened

The failure the working record makes visible: a control can appear in the SoA while nobody can show how it operates.

What should you settle before buying help?

Ask the customer which deliverable it will accept: an ISO/IEC 27001 certificate for a named scope, evidence of particular controls, or help building the ISMS. A guidance document cannot be sold as certification. Price implementation support separately from the certification body’s fee, and confirm the proposed scope before you compare sellers. Our guide to ISO certification consultants covers what an ISO adviser does and how it differs from the certification body.

If you need help building the ISMS and the control evidence, compare ISO 27001 consultants. If you are ready to select the certification body, compare ISO 27001 certification companies. Budget the certification lifecycle separately from implementation support. For a choice between a certificate and a SOC 2 report, see SOC 2 vs ISO 27001.

Questions buyers ask

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001:2022 sets requirements for an ISMS and is the standard a certification body assesses. ISO/IEC 27002:2022 is guidance for the same 93 controls. Annex A names each control. ISO 27002 adds purpose, guidance, and other information. Only ISO 27001 produces a certificate.

What is ISO 27002 used for?

Teams use ISO/IEC 27002:2022 to design and improve information security controls. Each entry has the control text, a purpose, guidance, and other information, plus five attributes for filtering the set. ISO 27002 does not certify an organization.

Is ISO 27001 still relevant?

Yes. The current edition is ISO/IEC 27001:2022, published on 25 October 2022. IAF MD 26 required certification bodies to complete client transitions from ISO/IEC 27001:2013 by 31 October 2025. A certificate that still names the 2013 edition did not complete that transition.