ISO Certifications

ISO 27002:2022 — Information Security Controls

The reference catalogue of information security controls. Organisations don't certify to ISO 27002 directly — they implement its controls and certify to ISO 27001.

Book a consultation
ISO 27002 information security controls reference
10-14 weeks Indicative timeline — varies with scope, size, sites and shifts
ISO Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 27002Security ControlsISO 27001Information Security

What ISO 27002 covers

ISO 27002 is the international reference catalogue of information security controls. The 2022 revision reorganised the controls into four themes — organisational, people, physical and technological — and updated them for modern threats. It provides detailed guidance on what each control is and how to implement it.

Crucially, ISO 27002 is not a certifiable standard on its own. You do not “get certified to ISO 27002.” Instead, organisations implement the relevant controls from ISO 27002 and achieve certification to ISO 27001, which is the certifiable information security management system standard. ISO 27002 is the toolbox; ISO 27001 is the certificate.

How ISO 27002 is used

In practice, ISO 27002 is the controls reference that sits behind an ISO 27001 programme:

  • ISO 27001 requires you to select and implement appropriate controls
  • ISO 27002 describes those controls in detail — purpose, guidance and implementation
  • When implementing and preparing ISO 27001 programmes, ABS uses ISO 27002 as the reference for assessing how well each selected control is designed and operating

So if your goal is certifiable assurance over information security, the destination is ISO 27001 — and ISO 27002 is how you and the auditor reason about the controls along the way. It sits within the IT-security part of the ISO Certifications portfolio.

Timeline & process

Because certification is achieved through ISO 27001, the timeline follows that standard — typically around 10–14 weeks for an organisation with controls already in place, depending on scope and organisation size. ABS can also run a focused gap assessment of your controls against ISO 27002 as preparation. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.

Common questions

Can you get certified to ISO 27002?

No. ISO 27002 is a reference catalogue of information security controls, not a certifiable management system. Organisations implement the relevant controls and then certify to ISO 27001. ABS uses ISO 27002 as the controls reference when implementing and preparing ISO 27001 programmes.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 sets the requirements for an information security management system and is the standard you get certified to. ISO 27002 is the detailed guidance on the controls themselves. You certify to ISO 27001 using ISO 27002 as the control reference.

More services

Related services

ISO Certifications / 01 ISO 9001 quality management system documentation review

ISO 9001 — Quality Management

The world's most widely adopted standard for quality management systems.

ISO 9001QMSQuality Management
Get a quote
ISO Certifications / 02 ISO 27001 information security management implementation

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

ISO 27001ISMSInformation Security
Get a quote
ISO Certifications / 03 Industrial facility managing environmental impact under ISO 14001

ISO 14001 — Environmental Management

The international standard for environmental management systems and measurable sustainability.

ISO 14001EMSEnvironmental Management
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us