ISO 27002 vs ISO 27001: what's the difference

The short answer: ISO 27001 is the standard you certify against; ISO 27002 is the manual that explains how to implement its controls. ISO 27001 defines the management system — scope, risk assessment, leadership, audit — and lists 93 reference controls in its Annex A. ISO 27002 takes those same 93 controls and expands each into implementation guidance: purpose, how to do it, what good looks like. You certify against 27001. You read 27002 while doing it. There is no ISO 27002 certificate, and anyone selling you one is confused.

What ISO 27001 is

ISO/IEC 27001 is the international standard for an information security management system — an ISMS. Its mandatory clauses (4–10) define the system itself: context, leadership, risk-based planning, support, operation, performance evaluation and improvement. Annex A supplies the reference control set that your risk treatment draws from, documented in the Statement of Applicability. Accredited certification bodies audit against it, which is why "ISO 27001 certified" is a claim customers can verify.

What ISO 27002 is

ISO/IEC 27002 is a guidance standard: one chapter per control, each with a purpose statement, implementation guidance and other useful context. Where Annex A of 27001 gives you a control in one sentence, 27002 gives you the two pages on what implementing it actually involves. It also carries the attribute taxonomy — each control tagged by type (preventive, detective, corrective), security properties, cybersecurity concepts and operational capabilities — which is useful for mapping controls across frameworks.

Why you cannot be certified against ISO 27002

Certification requires auditable requirements — "shall" statements. ISO 27002 contains guidance, not requirements; there is nothing in it to pass or fail. The certifiable requirements live in ISO 27001's clauses, plus your justified selection from Annex A. Practical consequence: if a supplier claims an "ISO 27002 certification," what they usually mean is that they aligned to the guidance — a self-claim, not an audited one. Worth knowing when you are the one reviewing vendors.

What changed in the 2022 revision

The 2022 editions of both standards reorganized the control landscape substantially:

2013 edition2022 edition
Controls11493
Structure14 domains4 themes
New controls11 added
AttributesTagging taxonomy introduced

The count dropped because controls were merged, not weakened. The 11 genuinely new controls track how companies actually operate now: threat intelligence, security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Transition deadlines for the 2022 edition have passed — new certifications run on 2022, so if you are starting now, ignore 2013-era templates entirely.

How the 93 Annex A controls map to ISO 27002 guidance

One to one. Annex A control 5.1 (policies for information security) is chapter 5.1 of ISO 27002; A.8.24 (use of cryptography) is chapter 8.24. Annex A is effectively the table of contents of ISO 27002, restated as requirements-by-reference. That mapping is what makes the pair usable: your Statement of Applicability lists the controls; 27002 tells whoever implements each one what an auditor will expect behind it.

What the attribute taxonomy is actually for

The 2022 attributes look bureaucratic until you have to answer a mapping question. Because every control is tagged — preventive/detective/corrective, by security property (confidentiality, integrity, availability), by cybersecurity concept (identify, protect, detect, respond, recover) and by operational capability — you can slice the control set the way a stakeholder asks about it: "show me our detective controls," "which controls serve availability," "map our controls to an NIST-style respond function." For teams juggling ISO 27001 alongside SOC 2, NIS2 or DORA, the attributes are the closest thing the standard offers to a built-in crosswalk, and good tooling uses them to reuse one implemented control across every framework that recognizes it.

A worked example: one control, both documents

Take access rights. In ISO 27001's Annex A, control 5.18 is a single sentence: access rights shall be provisioned, reviewed, modified and removed in line with the access control policy. That is the requirement — auditable, pass/fail, and silent on method. Open chapter 5.18 of ISO 27002 and you get the manual: provision access on joiner events, modify on role change, remove on exit; review at planned intervals and after privilege changes; treat privileged rights separately; keep records of every grant and revocation.

Now the audit consequence. Against 27001, the auditor asks "show me": the policy, this quarter's access review with a date and a reviewer, the leaver from last month whose accounts were closed, and the ticket trail proving it. Against 27002 they ask nothing, because nobody audits guidance — but the auditor's mental checklist of what "provisioned, reviewed, modified and removed" should look like comes straight from the 27002 chapter. Reading it is the closest legal thing to seeing the exam answers in advance.

Multiply that by 93 and you have the whole relationship between the two standards.

The four control themes

  • Organizational (37 controls) — policies, roles, supplier relationships, incident management, compliance. The governance layer.
  • People (8 controls) — screening, terms of employment, awareness, disciplinary process, responsibilities after termination.
  • Physical (14 controls) — premises, equipment, media, clear desk. (If you operate no premises, several become not-applicable — with justification.)
  • Technological (34 controls) — access, cryptography, logging, backups, development security, and most of the 2022 additions.

Which one you actually need

Buy both documents if you are implementing seriously — they are designed as a pair. But the decision-relevant version: customers, auditors and regulators care about ISO 27001. That is the certificate, the contractual requirement, the RFP checkbox. ISO 27002 is how your implementers avoid reinventing what each control means. If a customer contract says "ISO 27002 compliant," push back for clarity — they almost certainly mean 27001.

Three common situations, resolved

  • "A customer requires ISO 27001." You need the certificate: build the ISMS against 27001, use 27002 as the implementation manual, engage an accredited certification body. Nothing about 27002 alone will satisfy the contract.
  • "We want the discipline but not the audit." Implement against 27001's structure anyway (it is the useful part) and mine 27002 for control guidance; you can state "aligned to ISO 27001" honestly as long as you never say certified.
  • "A vendor claims ISO 27002 compliance." Treat it as a self-assessment claim. Ask for their 27001 certificate — and read the scope statement on it, because a certificate scoped to "the London office's HR system" says little about the product you are buying.

Buying and reading them, practically

Both documents are sold, not free — ISO and national bodies charge per copy (roughly €100–200 each), which surprises teams used to NIST publications. Buy official copies; paraphrased summaries circulating online are frequently 2013-era or subtly wrong. Reading order for a team starting out: 27001 clauses 4–10 first (they are short — the certifiable core is under thirty pages), then Annex A as a checklist, then 27002 chapter-by-chapter only for the controls your Statement of Applicability marks applicable. Nobody reads 27002 cover to cover, and nothing requires you to: it is a reference manual, and the fastest implementations treat it as one — opened at the chapter matching the control currently being built, closed again after.

Where ISO 27003, 27004 and 27701 fit

The same family has three more members worth knowing. ISO 27003 is implementation guidance for the management-system clauses — the how-to for building the ISMS itself, complementing 27002's control guidance. ISO 27004 covers measurement: what to monitor and how to evaluate ISMS performance, feeding clause 9. ISO 27701 extends the ISMS into privacy management (a PIMS), bolting GDPR-shaped privacy controls onto an existing 27001 system — the natural next step for companies whose customers ask about both security and privacy.

If ISO 27001 is on your roadmap, the practical first step is knowing your distance from it. ZeroRisk's agent maps your current state against the full 2022 control set — pre-filled from what it can already observe, drafted where you have gaps, signed by you — starting with a free gap report that takes about ten minutes.