Overview
SIST EN ISO/IEC 27002:2022 (ISO/IEC 27002:2022) is the updated international guidance for information security controls, cybersecurity and privacy protection. Published in 2022 (third edition) and superseding the 2017 version, this standard provides a reference set of generic controls and implementation guidance designed to be used within an Information Security Management System (ISMS) based on ISO/IEC 27001, for implementing controls based on internationally recognized best practices, and for developing organisation‑specific information security guidelines.
Key Topics and Technical Requirements
The standard is organized into thematic control groups and includes implementation guidance rather than prescriptive requirements. Major topics covered include:
- Organizational controls: policies, roles and responsibilities, segregation of duties, management responsibilities, contact with authorities and special interest groups.
- Asset and information management: inventory of assets, classification, labelling, acceptable use, and information transfer.
- Access, identity and authentication: access control models, identity management, authentication information and access rights.
- Supplier and ICT supply chain security: managing supplier relationships, contractual controls, monitoring and cloud service security.
- Incident management and resilience: incident preparation, detection, response, evidence collection, lessons learned, business continuity and ICT readiness.
- Privacy and protection of personal data (PII): guidance to support privacy‑aware controls and integration with cybersecurity measures.
- People controls: screening, employment terms, training and awareness, disciplinary measures, remote working and termination processes.
- Physical controls: perimeters, physical entry, equipment protection, secure disposal and environmental threats.
- Compliance and governance: legal, statutory and contractual requirements, intellectual property, records protection and independent review.
The standard describes control attributes, layout and implementation guidance to help organisations select and apply appropriate controls based on risk.
Practical Applications and Who Uses It
ISO/IEC 27002:2022 is practical for:
- CISOs, security managers and ISMS implementers choosing controls for a risk treatment plan.
- IT, cybersecurity and privacy teams designing operational controls (access management, cloud security, incident response).
- Procurement and vendor managers drafting supplier/security clauses and managing ICT supply chains.
- Auditors and consultants advising on best‑practice controls and gaps relative to ISO/IEC 27001.
- SMEs and large enterprises building organisation‑specific security policies and procedures.
Note: ISO/IEC 27002 provides guidance; ISO/IEC 27001 defines ISMS requirements used for certification.
Related Standards
- ISO/IEC 27001 - ISMS requirements (used together with 27002 for control selection).
- Other members of the ISO/IEC 27000 family and national standards/regulations (e.g., data protection laws) for privacy compliance.
Keywords: ISO/IEC 27002:2022, information security controls, cybersecurity, privacy protection, ISMS, ISO/IEC 27001, access control, cloud security, incident management.