What is the difference between ISO/IEC 27001 and ISO/IEC 27002, and which one can an organization be certified against?
answer
- requirements versus guidance
- shall versus should
- management system plus Annex A
- implementation detail per control
- only one carries a certificate
basics
~20 sISO/IEC 27001 states the requirements for an information security management system, including the Annex A control list, and is the standard organizations are certified against. ISO/IEC 27002 is guidance on implementing each of those controls and cannot be certified.
solid answer
~40 sISO/IEC 27001 is a **requirements** standard: its clauses 4 to 10 say what an information security management system (**ISMS**) *shall* do — context and scope, leadership, risk assessment and treatment, support, operation, performance evaluation, improvement — and its **Annex A** lists 93 controls in the 2022 edition that the organization compares its risk treatment against. Accredited certification bodies audit against 27001 and issue the certificate. ISO/IEC 27002 is a **guidance** standard: for the same 93 controls it explains purpose and implementation in *should* language, and adds attributes for filtering controls. It has no requirements to conform to, so there is no 27002 certificate; a company claiming one has misread the family. In practice teams read Annex A for *what* must be addressed and 27002 for *how* to implement it.
go deeper
Recall that 27001 holds the requirements and the certificate while 27002 is implementation guidance for the same controls. Know the 2022 edition has 93 Annex A controls.
Explain how Annex A, the Statement of Applicability and 27002 guidance fit together when a control is chosen and implemented.
Show how you use 27002 guidance and attributes to design controls an auditor will accept, while keeping every finding traceable to a 27001 requirement.
Discuss when extensions such as 27017, 27018 or 27701 are worth adding to a 27001 programme and what they cost to maintain.
## Two standards, two jobs The ISO/IEC 27000 family contains many documents, but two are confused more than any others. | | ISO/IEC 27001 | ISO/IEC 27002 | |---|---|---| | **Type** | Requirements standard | Guidance (code of practice) | | **Language** | *shall* | *should* | | **Scope** | The whole **ISMS**: context, leadership, planning, support, operation, evaluation, improvement | The controls: purpose and implementation guidance for each | | **Controls** | Annex A lists 93 controls with a one-line statement each | The same 93 controls, each with guidance and attributes | | **Certifiable?** | Yes, by an accredited certification body | No | The 2022 editions of both were aligned: Annex A of ISO/IEC 27001:2022 uses the control set and numbering of ISO/IEC 27002:2022. ## What ISO/IEC 27001 requires **ISO/IEC 27001** specifies a **management system**: a set of policies, processes, roles and records through which an organization manages information security risk continuously. Its mandatory clauses are 4 to 10: 1. **Context of the organization** — issues, interested parties, scope of the ISMS. 2. **Leadership** — top management commitment, the policy, roles. 3. **Planning** — risk assessment, risk treatment, the Statement of Applicability, objectives. 4. **Support** — resources, competence, awareness, communication, documented information. 5. **Operation** — running the planned processes and risk treatment. 6. **Performance evaluation** — monitoring, internal audit, management review. 7. **Improvement** — nonconformity, corrective action, continual improvement. **Annex A** is part of the standard. The organization determines the controls it needs from its risk treatment, then compares them with Annex A so no necessary control is overlooked, and records the result in the **Statement of Applicability**. ## What ISO/IEC 27002 adds **ISO/IEC 27002** takes each Annex A control and explains it: the purpose, detailed guidance, and other information. The 2022 edition groups the 93 controls into four themes — **organizational** (5.1–5.37, 37 controls), **people** (6.1–6.8, 8), **physical** (7.1–7.14, 14) and **technological** (8.1–8.34, 34) — and adds **attributes** such as control type and cybersecurity concepts, so a team can filter controls by how they work rather than by number. Because it contains no requirements, nothing can conform to it. An auditor may use 27002 to understand what a control is meant to achieve, but the finding is written against 27001. ## Example: a 250-person SaaS company The company's risk assessment finds that source-code leaks are a significant risk. - **ISO/IEC 27001** requires it to treat that risk, decide which controls apply, and record them — say Annex A 8.28 *Secure Coding* and 8.4 on source code access — in its Statement of Applicability with implementation status. - **ISO/IEC 27002** tells the engineers what a reasonable implementation of secure coding looks like. - The **certificate** says the ISMS conforms to ISO/IEC 27001:2022 for the stated scope. ## Other members of the family worth knowing - **ISO/IEC 27000** — overview and vocabulary. - **ISO/IEC 27005** — guidance on information security risk management. - **ISO/IEC 27017** and **27018** — cloud-specific control guidance and protection of personal data in public clouds. - **ISO/IEC 27701** — a privacy extension to the ISMS. None of these replaces 27001 as the basis of the core certificate. ## Common confusions - "We are 27002 certified" — no such certificate exists. - "Annex A is optional" — the comparison against Annex A and the Statement of Applicability are required; individual controls can be excluded only with justification. - "Implementing all 93 controls makes us compliant" — without the management-system clauses there is no conformity.
- If ISO/IEC 27002 is not certifiable, why would an ISO/IEC 27001 auditor care about it?Because it explains what each Annex A control is meant to achieve. An auditor may use it to judge whether an implementation is plausible, and an organization uses it to design controls that will stand up to that judgement. Any finding, though, is raised against a requirement of ISO/IEC 27001, such as the Statement of Applicability or risk treatment, not against 27002 guidance.
- What are ISO/IEC 27002:2022 control attributes used for?They tag each control with properties such as control type (preventive, detective, corrective) and cybersecurity concepts, so a team can view the 93 controls through different lenses: all detective controls, or everything relevant to a given capability. They help with control selection and with mapping to other frameworks, but they add no requirements.
saying these in an interview costs you the question
- An organization can be certified against ISO/IEC 27002.
- Implementing every Annex A control is the same as having an ISMS.
- ISO/IEC 27002 contains the mandatory requirements and 27001 is the guidance.
- Annex A is an optional appendix auditors ignore.