ISO/IEC 27002:2022
Information security, cybersecurity and privacy protection — Information security controls
Information security, cybersecurity and privacy protection — Information security controls
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 152
- Дата публикации:
- 15 февраля 2022 г.
- Издание:
- ISO/IEC IS 27002 edition 3 version 1
- ICS:
- 03.100.70
This document provides a reference set of generic information security controls including implementation guidance. This document is designed to be used by organizations: a) within the context of an information security management system (ISMS) based on ISO/IEC27001; b) for implementing information security controls based on internationally recognized best practices; c) for developing organization-specific information security management guidelines.
Abstract
Overview - ISO/IEC 27002:2022 (Information security controls)
ISO/IEC 27002:2022 is an international guidance standard that provides a comprehensive reference set of information security controls and implementation guidance. It is designed to be used within an Information Security Management System (ISMS) based on ISO/IEC 27001, for implementing controls according to internationally recognized best practices, or for creating organization‑specific information security policies and procedures. The 2022 edition reorganizes controls into themes covering organizational, people, physical and technological controls.
Key topics and technical requirements
ISO/IEC 27002:2022 organizes controls and guidance across practical security domains. Major topics include:
- Organizational controls: policies, roles and responsibilities, asset inventory, classification, information transfer, supplier security, cloud services, legal and regulatory requirements, and incident management.
- People controls: screening, employment terms, awareness, training, remote working, reporting and disciplinary processes.
- Physical controls: perimeters, physical entry, secure areas, equipment protection, environmental threats, clear desk/screen, and secure disposal.
- Technological controls: endpoint security, privileged access, authentication, access restriction, malware protection, vulnerability management, configuration and patch management, cryptography, backups, logging and monitoring, network security, secure development lifecycle, and application security.
- Privacy and PII protection: controls for protecting personal data and aligning privacy measures with information security practices.
- Operational resilience: business continuity readiness, disruption management, evidence collection and learning from incidents.
The standard emphasizes implementation guidance rather than prescriptive technical specifications - helping organizations select and tailor controls to risk and context.
Applications - who uses it and why
ISO/IEC 27002 is used by:
- CISOs and security managers to design and benchmark controls within an ISMS.
- IT and cloud architects to apply secure architecture, cloud and network controls.
- Developers and DevSecOps teams for secure development practices and testing.
- Procurement and vendor managers to manage supplier and supply‑chain security.
- Compliance officers and auditors to assess control coverage against best practices.
- Consultants and implementers to map control sets to organizational risk profiles.
Practical uses include control selection for ISO/IEC 27001 certification, building control frameworks, preparing incident response playbooks, enforcing access and identity controls, and incorporating privacy protections.
Related standards
- ISO/IEC 27001 - ISMS requirements (primary companion standard)
- Other ISO/IEC 27000‑series guidance (risk management, audit and implementation guidance)
Keywords: ISO/IEC 27002:2022, information security controls, cybersecurity, privacy protection, ISMS, ISO/IEC 27001, control implementation, information security best practices.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27002:2022
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…