Standards & Frameworks
ISO/IEC 27002
Implementation guidance for the controls referenced in ISO/IEC 27001 Annex A.
ISO/IEC 27002:2022 reorganises information security controls into four themes — organisational, people, physical and technological — and provides purpose, attributes and implementation guidance for each. It is not certifiable on its own; it is the practitioner companion to ISO/IEC 27001.