Overview - ISO/IEC 27002:2022 (Information security controls)
ISO/IEC 27002:2022 is an international guidance standard that provides a comprehensive reference set of information security controls and implementation guidance. It is designed to be used within an Information Security Management System (ISMS) based on ISO/IEC 27001, for implementing controls according to internationally recognized best practices, or for creating organization‑specific information security policies and procedures. The 2022 edition reorganizes controls into themes covering organizational, people, physical and technological controls.
Key topics and technical requirements
ISO/IEC 27002:2022 organizes controls and guidance across practical security domains. Major topics include:
- Organizational controls: policies, roles and responsibilities, asset inventory, classification, information transfer, supplier security, cloud services, legal and regulatory requirements, and incident management.
- People controls: screening, employment terms, awareness, training, remote working, reporting and disciplinary processes.
- Physical controls: perimeters, physical entry, secure areas, equipment protection, environmental threats, clear desk/screen, and secure disposal.
- Technological controls: endpoint security, privileged access, authentication, access restriction, malware protection, vulnerability management, configuration and patch management, cryptography, backups, logging and monitoring, network security, secure development lifecycle, and application security.
- Privacy and PII protection: controls for protecting personal data and aligning privacy measures with information security practices.
- Operational resilience: business continuity readiness, disruption management, evidence collection and learning from incidents.
The standard emphasizes implementation guidance rather than prescriptive technical specifications - helping organizations select and tailor controls to risk and context.
Applications - who uses it and why
ISO/IEC 27002 is used by:
- CISOs and security managers to design and benchmark controls within an ISMS.
- IT and cloud architects to apply secure architecture, cloud and network controls.
- Developers and DevSecOps teams for secure development practices and testing.
- Procurement and vendor managers to manage supplier and supply‑chain security.
- Compliance officers and auditors to assess control coverage against best practices.
- Consultants and implementers to map control sets to organizational risk profiles.
Practical uses include control selection for ISO/IEC 27001 certification, building control frameworks, preparing incident response playbooks, enforcing access and identity controls, and incorporating privacy protections.
Related standards
- ISO/IEC 27001 - ISMS requirements (primary companion standard)
- Other ISO/IEC 27000‑series guidance (risk management, audit and implementation guidance)
Keywords: ISO/IEC 27002:2022, information security controls, cybersecurity, privacy protection, ISMS, ISO/IEC 27001, control implementation, information security best practices.