ISO/IEC 27001 and ISO/IEC 27002 - division of roles
ISO/IEC 27001 contains management-system requirements and Annex A with the control catalogue. ISO/IEC 27002 develops the same 93 controls by providing purpose, implementation guidance and supporting information.[1][3]
Numbering is a common source of confusion. In Annex A of ISO/IEC 27001, controls are labelled A.5-A.8. In ISO/IEC 27002 they correspond to clauses 5-8 without the A prefix. This article retains the A.5-A.8 notation because it maps directly to the Statement of Applicability.
The 2022 edition
The 2022 edition replaced the structure of 114 controls in 14 categories with 93 controls in four groups.[1] Some earlier controls were merged or reorganized, while 11 were added as new controls.
| Group | Label | Count |
|---|---|---|
| Organizational | A.5 | 37 |
| People | A.6 | 8 |
| Physical | A.7 | 14 |
| Technological | A.8 | 34 |
| Total | A.5-A.8 | 93 |
The new controls are A.5.7 Threat intelligence, A.5.23 Information security for use of cloud services, A.5.30 ICT readiness for business continuity, A.7.4 Physical security monitoring, A.8.9 Configuration management, A.8.10 Information deletion, A.8.11 Data masking, A.8.12 Data leakage prevention, A.8.16 Monitoring activities, A.8.23 Web filtering and A.8.28 Secure coding.[1]
Attributes
ISO/IEC 27002:2022 allows controls to be classified using attributes. The standard attribute set covers control type, information security properties, cybersecurity concepts, operational capabilities and security domains.[1]
Attributes help filter the catalogue, assign ownership and map controls to other models. They do not alter the substance of a control. The built-in cybersecurity-concepts attribute set predates NIST CSF 2.0 and includes Identify, Protect, Detect, Respond and Recover; mapping to the later Govern function requires a separate mapping.
How to read a control
A control description contains the control itself, its purpose, implementation guidance and other information. The guidance is not an identical recipe for every organization. It must be applied in the context of risk, technology, legal requirements and the responsibilities of the parties involved.
The four sections that follow list all 93 controls. Control names stay in the English wording of the standard, because that is what appears in the Statement of Applicability and in tooling; the text beside each name states its purpose.
A.5 Organizational controls - 37
The full list of controls in this group, each with a short statement of purpose.
- A.5.1 Policies for information security - establish and review information security policies.
- A.5.2 Information security roles and responsibilities - assign roles and responsibilities unambiguously.
- A.5.3 Segregation of duties - separate conflicting duties where doing so reduces the risk of error or abuse.
- A.5.4 Management responsibilities - management enforcement of security requirements.
- A.5.5 Contact with authorities - maintain appropriate contacts with relevant authorities.
- A.5.6 Contact with special interest groups - maintain relevant contacts with industry and specialist communities.
- A.5.7 Threat intelligence - acquire, analyse and use information about threats.
- A.5.8 Information security in project management - integrate security into project management.
- A.5.9 Inventory of information and other associated assets - maintain an up-to-date inventory with ownership.
- A.5.10 Acceptable use of information and other associated assets - establish acceptable-use rules.
- A.5.11 Return of assets - return assets when relationships change or end.
- A.5.12 Classification of information - classify information according to protection needs.
- A.5.13 Labelling of information - label information consistently with classification.
- A.5.14 Information transfer - protect transfers of information internally and externally.
- A.5.15 Access control - establish rules for access to information and assets.
- A.5.16 Identity management - manage the complete identity life cycle.
- A.5.17 Authentication information - securely allocate and manage authentication information.
- A.5.18 Access rights - grant, review, modify and revoke access rights.
- A.5.19 Information security in supplier relationships - manage security risk in supplier relationships.
- A.5.20 Addressing information security within supplier agreements - include appropriate security requirements in agreements.
- A.5.21 Managing information security in the ICT supply chain - manage security risk across the ICT supply chain.
- A.5.22 Monitoring, review and change management of supplier services - monitor supplier services and changes.
- A.5.23 Information security for use of cloud services - manage security when acquiring, using, changing and exiting cloud services; ISO/IEC 27017:2026 provides additional guidance [9].
- A.5.24 Information security incident management planning and preparation - prepare the incident-management process.
- A.5.25 Assessment and decision on information security events - assess events and decide whether they constitute incidents.
- A.5.26 Response to information security incidents - respond through an established process.
- A.5.27 Learning from information security incidents - use lessons learned to improve security.
- A.5.28 Collection of evidence - identify, collect, acquire and preserve evidence.
- A.5.29 Information security during disruption - maintain appropriate information protection during disruption.
- A.5.30 ICT readiness for business continuity - ensure ICT readiness aligned with continuity requirements.
- A.5.31 Legal, statutory, regulatory and contractual requirements - identify and maintain applicable legal, regulatory and contractual requirements.
- A.5.32 Intellectual property rights - protect intellectual property and maintain licensing compliance.
- A.5.33 Protection of records - protect records against loss, destruction, alteration and unauthorized access.
- A.5.34 Privacy and protection of PII - protect privacy and personal information; ISO/IEC 27018:2025 adds guidance for public-cloud processors [10].
- A.5.35 Independent review of information security - independently review the security approach and its implementation.
- A.5.36 Compliance with policies, rules and standards for information security - verify compliance with internal policies and standards.
- A.5.37 Documented operating procedures - document operating procedures where necessary.
A.6 People controls - 8
The full list of controls in this group, each with a short statement of purpose.
- A.6.1 Screening - conduct proportionate and lawful screening appropriate to the role.
- A.6.2 Terms and conditions of employment - specify security responsibilities in employment or engagement terms.
- A.6.3 Information security awareness, education and training - provide awareness, education and training appropriate to role and risk; the standard does not set one universal frequency.
- A.6.4 Disciplinary process - establish a formal process for security-policy violations.
- A.6.5 Responsibilities after termination or change of employment - maintain relevant obligations after a role changes or ends.
- A.6.6 Confidentiality or non-disclosure agreements - identify and maintain appropriate confidentiality obligations.
- A.6.7 Remote working - protect information during remote work.
- A.6.8 Information security event reporting - provide a simple, known channel for reporting security events.
A.7 Physical controls - 14
The full list of controls in this group, each with a short statement of purpose.
- A.7.1 Physical security perimeters - define and protect physical boundaries.
- A.7.2 Physical entry - control access to protected areas.
- A.7.3 Securing offices, rooms and facilities - secure offices, rooms and facilities.
- A.7.4 Physical security monitoring - monitor protected areas in proportion to risk.
- A.7.5 Protecting against physical and environmental threats - protect against physical and environmental threats.
- A.7.6 Working in secure areas - establish rules for working in secure areas.
- A.7.7 Clear desk and clear screen - reduce exposure of unattended information.
- A.7.8 Equipment siting and protection - position and protect equipment appropriately.
- A.7.9 Security of assets off-premises - protect assets outside organizational premises.
- A.7.10 Storage media - manage storage media throughout their life cycle.
- A.7.11 Supporting utilities - maintain resilience of supporting utilities such as power and cooling.
- A.7.12 Cabling security - protect power and telecommunications cabling.
- A.7.13 Equipment maintenance - maintain equipment securely.
- A.7.14 Secure disposal or re-use of equipment - securely dispose of or reuse equipment after removing information.
A.8 Technological controls - 34
The full list of controls in this group, each with a short statement of purpose.
- A.8.1 User endpoint devices - protect information processed and stored on endpoint devices.
- A.8.2 Privileged access rights - tightly manage privileged access rights.
- A.8.3 Information access restriction - enforce restrictions on access to information.
- A.8.4 Access to source code - control access to source code, development tools and libraries.
- A.8.5 Secure authentication - use secure authentication technologies and procedures.
- A.8.6 Capacity management - monitor and manage resource capacity.
- A.8.7 Protection against malware - protect against malware together with appropriate user awareness.
- A.8.8 Management of technical vulnerabilities - obtain vulnerability information, assess exposure and take appropriate action.
- A.8.9 Configuration management - establish, document, implement and monitor configurations.
- A.8.10 Information deletion - delete information when it is no longer required under applicable requirements.
- A.8.11 Data masking - mask data according to access rules and business need.
- A.8.12 Data leakage prevention - use measures to reduce unauthorized disclosure or exfiltration of information.
- A.8.13 Information backup - create and regularly test backups in accordance with an agreed policy; the standard does not mandate a universal 3-2-1 scheme.
- A.8.14 Redundancy of information processing facilities - provide processing redundancy appropriate to availability requirements.
- A.8.15 Logging - generate, protect, retain and analyse appropriate logs.
- A.8.16 Monitoring activities - monitor networks, systems and applications for anomalous behaviour and respond appropriately.
- A.8.17 Clock synchronisation - synchronize system clocks with agreed time sources.
- A.8.18 Use of privileged utility programs - restrict and control utilities capable of bypassing security controls.
- A.8.19 Installation of software on operational systems - control software installation on operational systems.
- A.8.20 Networks security - secure and manage networks and network devices.
- A.8.21 Security of network services - define and monitor security mechanisms, service levels and requirements for network services.
- A.8.22 Segregation of networks - separate user groups, systems and services where risk requires it.
- A.8.23 Web filtering - control access to external resources to reduce exposure to malicious content.
- A.8.24 Use of cryptography - establish rules for effective use of cryptography, including key management.
- A.8.25 Secure development life cycle - apply security rules throughout system and software development.
- A.8.26 Application security requirements - identify and approve application security requirements.
- A.8.27 Secure system architecture and engineering principles - establish secure architecture and engineering principles.
- A.8.28 Secure coding - apply secure coding principles during development.
- A.8.29 Security testing in development and acceptance - define and perform security testing during development and acceptance.
- A.8.30 Outsourced development - direct, monitor and review the security of outsourced development.
- A.8.31 Separation of development, test and production environments - appropriately separate environments.
- A.8.32 Change management - control changes to systems and processing infrastructure.
- A.8.33 Test information - select and protect test information appropriately.
- A.8.34 Protection of information systems during audit testing - agree and control audit testing that can affect operational systems.
Relationship with other models
NIST CSF 2.0[4] works at a higher level and organizes outcomes around Govern, Identify, Protect, Detect, Respond and Recover. ISO/IEC 27002 goes deeper into individual controls. The two can be used together, but the attribute set built into the 2022 ISO/IEC 27002 edition does not include the later Govern function.
CIS Controls v8.1[5] are a more prescriptive, prioritized catalogue of actions. CIS publishes mappings to ISO/IEC 27001/27002 and other models.[5] Mapping can reduce duplicated work, but it does not make requirements equivalent.
OWASP Top 10:2025[6] is an awareness document about major web-application risk categories, not an alternative management system. More detailed application-security standards such as OWASP ASVS and WSTG are useful when implementing A.8.25-A.8.30.
NIST SP 800-53 Rev. 5[11] is a much larger security and privacy control catalogue. It can provide further detail, but its origin and context differ from ISO/IEC 27002. Technical testing methodology is covered instead by NIST SP 800-115.
Implementation in practice
There is no universal timetable and no requirement to implement all 93 controls. The starting point is the ISMS scope, risk assessment, legal and contractual requirements and the current state of security.
Dependencies should shape sequencing. Inventory, classification, identity management and accountability should exist before an organization tries to judge the effectiveness of advanced monitoring. Vulnerability management requires knowledge of assets, while incident response requires telemetry and clear decision authority.
Responsibility must extend beyond IT. People controls involve HR and management, physical controls involve facilities functions and site owners, supplier controls involve procurement and service owners, privacy involves legal functions and the DPO, and technological controls involve IT, security and development teams.
ISO/IEC 27003[7] can additionally support the design of the ISMS itself, while ISO/IEC 27005:2022[8] develops the process for identifying, assessing and treating information-security risk. ISO/IEC 27002 does not replace either role.
Common mistakes
- Implementing all 93 controls without a link to risk.
- Working only from one-line Annex A statements without reading ISO/IEC 27002 guidance.
- Policies without evidence that controls operate.
- An SoA that does not reflect reality.
- Assessing suppliers only through contractual clauses.
- Backups without credible restore testing.
- Monitoring without a defined responder and escalation path.
- Configuration without baselines and drift control.
- Vulnerability management without ownership and risk-based deadlines.
- Treating privacy as only A.5.34 while ignoring separate GDPR obligations.
10 review questions
- Does every applicable control have an owner?
- Is there evidence of operation rather than only documentation?
- Are exclusions justified by risk or context?
- Do configurations have defined baselines and drift monitoring?
- Are privileged rights restricted and monitored?
- Do vulnerability findings lead to decisions and actions?
- Has recovery from backup actually been tested?
- Are logs complete, time-synchronized and analysed?
- Are supplier requirements verified after contract signature?
- Do development controls cover requirements, coding, testing and change?
Frequently asked questions
- Can ISO/IEC 27002 be certified?
- No. It is a guidance standard. Management-system certification is against ISO/IEC 27001.
- Must all 93 controls be implemented?
- No. Organizations select controls based on risk and requirements and then use Annex A as a completeness check. In an ISO/IEC 27001 ISMS, these decisions are documented in the Statement of Applicability.
- Is ISO/IEC 27002 legally mandatory?
- Generally, it is voluntary. It has a specific status under the Polish KRI: section 19(3) refers to Polish Standards from the 27000 family as one route for requirements to be deemed met. That is not a universal obligation to use the standard or obtain certification.
- ISO/IEC 27002 or NIST CSF?
- They operate at different levels. CSF helps describe and communicate desired cybersecurity outcomes, while ISO/IEC 27002 provides a more detailed control catalogue. They can be mapped and used together.
- Is ISO/IEC 27002 enough to implement every control?
- Not always. It gives general guidance. Cloud, application security, cryptography, incident response and business continuity often require specialist standards, technology documentation and sector-specific requirements.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KRI compliance audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Sources checked as of 29 August 2026. Standards link to the ISO catalogue, Polish adoptions to PKN.
- [1] standardISO/IEC (2022). ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls. · ISO
- [2] standardPolish Committee for Standardization (2023). PN-EN ISO/IEC 27002:2023-01. Polish adoption of the standard · PKN
- [3] standardISO/IEC (2022). ISO/IEC 27001:2022 - Information security management systems - Requirements. · ISO
- [4] standardNational Institute of Standards and Technology (NIST) (2024). Cybersecurity Framework (CSF) 2.0. · NIST
- [5] standardCenter for Internet Security (2024). CIS Critical Security Controls v8.1 and mappings to ISO/IEC. · CIS
- [6] guidelineOWASP Foundation (2025). OWASP Top 10:2025. · OWASP
- [7] standardISO/IEC (2017). ISO/IEC 27003:2017 - Information security management systems - Guidance. Under revision in 2026 · ISO
- [8] standardISO/IEC (2022). ISO/IEC 27005:2022 - Guidance on managing information security risks. · ISO
- [9] standardISO/IEC (2026). ISO/IEC 27017:2026 - Information security controls based on ISO/IEC 27002 for cloud services. · ISO
- [10] standardISO/IEC (2025). ISO/IEC 27018:2025 - Guidelines for protection of PII in public clouds acting as PII processors. · ISO
- [11] standardNational Institute of Standards and Technology (NIST) (2020). NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations. DOI: 10.6028/NIST.SP.800-53r5 · DOI