Security Controls
ISO/IEC 27002
Information Security Controls
The companion control catalogue to ISO/IEC 27001: for each control, what it is for, how to implement it, and what other guidance applies. The 2022 revision restructured 114 controls into 93 across organisational, people, physical and technological themes.
It introduced attributes (control type, security property, operational capability) so controls can be mapped to other frameworks mechanically instead of by hand.
At a glance
- Category
- Security Controls
- Jurisdiction
- Global
- Governance
- ISO/IEC JTC 1/SC 27
- Status
- ISO/IEC 27002:2022; 93 controls in four themes
- First released
- 2005
Links
Related frameworks
Other entries under Security Controls.
- NIST SP 800-53: Security and Privacy Controls for Information Systems
- CIS Controls: CIS Critical Security Controls
See ISO/IEC 27002 in context
Open the interactive Data Landscape for Regulation to compare ISO/IEC 27002 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.