Governance. Risk. Compliance. Cybersecurity.

Standards & Frameworks

ISO/IEC 27002

Implementation guidance for the controls referenced in ISO/IEC 27001 Annex A.

ISO/IEC 27002:2022 reorganises information security controls into four themes — organisational, people, physical and technological — and provides purpose, attributes and implementation guidance for each. It is not certifiable on its own; it is the practitioner companion to ISO/IEC 27001.