skip to content

ISO 27001 & 27002

How an ISMS is scoped, how Annex A controls are chosen in the Statement of Applicability, and what certification audits check. Interviewers use it to test management-system thinking.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

explore

questions

5

What is the difference between ISO/IEC 27001 and ISO/IEC 27002, and which one can an organization be certified against?

level: juniorimportance: must knowfreq 60%

answer

  1. requirements versus guidance
  2. shall versus should
  3. management system plus Annex A
  4. implementation detail per control
  5. only one carries a certificate

basics

~20 s

ISO/IEC 27001 states the requirements for an information security management system, including the Annex A control list, and is the standard organizations are certified against. ISO/IEC 27002 is guidance on implementing each of those controls and cannot be certified.

solid answer

~40 s

ISO/IEC 27001 is a **requirements** standard: its clauses 4 to 10 say what an information security management system (**ISMS**) *shall* do — context and scope, leadership, risk assessment and treatment, support, operation, performance evaluation, improvement — and its **Annex A** lists 93 controls in the 2022 edition that the organization compares its risk treatment against. Accredited certification bodies audit against 27001 and issue the certificate. ISO/IEC 27002 is a **guidance** standard: for the same 93 controls it explains purpose and implementation in *should* language, and adds attributes for filtering controls. It has no requirements to conform to, so there is no 27002 certificate; a company claiming one has misread the family. In practice teams read Annex A for *what* must be addressed and 27002 for *how* to implement it.

go deeper

for a junior

Recall that 27001 holds the requirements and the certificate while 27002 is implementation guidance for the same controls. Know the 2022 edition has 93 Annex A controls.

for a middle

Explain how Annex A, the Statement of Applicability and 27002 guidance fit together when a control is chosen and implemented.

for a senior

Show how you use 27002 guidance and attributes to design controls an auditor will accept, while keeping every finding traceable to a 27001 requirement.

for a principal

Discuss when extensions such as 27017, 27018 or 27701 are worth adding to a 27001 programme and what they cost to maintain.

## Two standards, two jobs The ISO/IEC 27000 family contains many documents, but two are confused more than any others. | | ISO/IEC 27001 | ISO/IEC 27002 | |---|---|---| | **Type** | Requirements standard | Guidance (code of practice) | | **Language** | *shall* | *should* | | **Scope** | The whole **ISMS**: context, leadership, planning, support, operation, evaluation, improvement | The controls: purpose and implementation guidance for each | | **Controls** | Annex A lists 93 controls with a one-line statement each | The same 93 controls, each with guidance and attributes | | **Certifiable?** | Yes, by an accredited certification body | No | The 2022 editions of both were aligned: Annex A of ISO/IEC 27001:2022 uses the control set and numbering of ISO/IEC 27002:2022. ## What ISO/IEC 27001 requires **ISO/IEC 27001** specifies a **management system**: a set of policies, processes, roles and records through which an organization manages information security risk continuously. Its mandatory clauses are 4 to 10: 1. **Context of the organization** — issues, interested parties, scope of the ISMS. 2. **Leadership** — top management commitment, the policy, roles. 3. **Planning** — risk assessment, risk treatment, the Statement of Applicability, objectives. 4. **Support** — resources, competence, awareness, communication, documented information. 5. **Operation** — running the planned processes and risk treatment. 6. **Performance evaluation** — monitoring, internal audit, management review. 7. **Improvement** — nonconformity, corrective action, continual improvement. **Annex A** is part of the standard. The organization determines the controls it needs from its risk treatment, then compares them with Annex A so no necessary control is overlooked, and records the result in the **Statement of Applicability**. ## What ISO/IEC 27002 adds **ISO/IEC 27002** takes each Annex A control and explains it: the purpose, detailed guidance, and other information. The 2022 edition groups the 93 controls into four themes — **organizational** (5.1–5.37, 37 controls), **people** (6.1–6.8, 8), **physical** (7.1–7.14, 14) and **technological** (8.1–8.34, 34) — and adds **attributes** such as control type and cybersecurity concepts, so a team can filter controls by how they work rather than by number. Because it contains no requirements, nothing can conform to it. An auditor may use 27002 to understand what a control is meant to achieve, but the finding is written against 27001. ## Example: a 250-person SaaS company The company's risk assessment finds that source-code leaks are a significant risk. - **ISO/IEC 27001** requires it to treat that risk, decide which controls apply, and record them — say Annex A 8.28 *Secure Coding* and 8.4 on source code access — in its Statement of Applicability with implementation status. - **ISO/IEC 27002** tells the engineers what a reasonable implementation of secure coding looks like. - The **certificate** says the ISMS conforms to ISO/IEC 27001:2022 for the stated scope. ## Other members of the family worth knowing - **ISO/IEC 27000** — overview and vocabulary. - **ISO/IEC 27005** — guidance on information security risk management. - **ISO/IEC 27017** and **27018** — cloud-specific control guidance and protection of personal data in public clouds. - **ISO/IEC 27701** — a privacy extension to the ISMS. None of these replaces 27001 as the basis of the core certificate. ## Common confusions - "We are 27002 certified" — no such certificate exists. - "Annex A is optional" — the comparison against Annex A and the Statement of Applicability are required; individual controls can be excluded only with justification. - "Implementing all 93 controls makes us compliant" — without the management-system clauses there is no conformity.

  • If ISO/IEC 27002 is not certifiable, why would an ISO/IEC 27001 auditor care about it?
    Because it explains what each Annex A control is meant to achieve. An auditor may use it to judge whether an implementation is plausible, and an organization uses it to design controls that will stand up to that judgement. Any finding, though, is raised against a requirement of ISO/IEC 27001, such as the Statement of Applicability or risk treatment, not against 27002 guidance.
  • What are ISO/IEC 27002:2022 control attributes used for?
    They tag each control with properties such as control type (preventive, detective, corrective) and cybersecurity concepts, so a team can view the 93 controls through different lenses: all detective controls, or everything relevant to a given capability. They help with control selection and with mapping to other frameworks, but they add no requirements.

saying these in an interview costs you the question

  • An organization can be certified against ISO/IEC 27002.
  • Implementing every Annex A control is the same as having an ISMS.
  • ISO/IEC 27002 contains the mandatory requirements and 27001 is the guidance.
  • Annex A is an optional appendix auditors ignore.
open as a page

In ISO/IEC 27001:2022, what do clauses 4 to 10 require, and why is implementing Annex A controls alone not enough for certification?

level: middleimportance: must knowfreq 55%

basics

~20 s

Clauses 4 to 10 require the management system itself: context and scope, leadership, risk-based planning, support, operation, performance evaluation and improvement. They cannot be excluded, so controls without a working, audited and reviewed ISMS do not conform.

open as a page

In ISO/IEC 27001:2022, what does the Statement of Applicability contain, and how do you justify excluding an Annex A control?

level: middleimportance: must knowfreq 55%

basics

~20 s

The Statement of Applicability lists the necessary controls, why each is included, whether it is implemented, and why any Annex A control is excluded. An exclusion is justified by the risk assessment or scope showing no risk the control would treat.

open as a page

In ISO/IEC 27001 certification, what do the stage 1 and stage 2 audits check, and how do nonconformities play out over the three-year cycle?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Stage 1 checks readiness: scope, documents, risk method, Statement of Applicability, and that internal audit and management review have run. Stage 2 checks the ISMS operates effectively. Major nonconformities block certification until closed; minors need an accepted plan. Surveillance audits follow, then recertification.

open as a page

Under ISO/IEC 27001:2022, how do internal audit and management review show continual improvement, and what does a certification auditor expect to see?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Internal audit checks at planned intervals, by objective auditors, that the ISMS conforms and works; management review has top management weigh performance, audit results, risks and changes and decide improvements. Auditors expect programmes, records, decisions and closed corrective actions.

open as a page