
ISO 27001 vs ISO 27002: the short answer
ISO/IEC 27001 is the certifiable requirements standard for an information security management system (ISMS). ISO/IEC 27002 is guidance for selecting and implementing information security controls. They are complementary, ISO 27001 tells you what your ISMS must address; ISO 27002 helps you think through how controls can be implemented.
The practical takeaway is simple: if your goal is certification, ISO/IEC 27001 is the certification target. ISO/IEC 27002 can guide implementation, but its recommendations are not automatically mandatory in full. Your organisation still needs risk-based decisions, a defensible Statement of Applicability, implemented controls, and evidence.
| Dimension | ISO 27001 | ISO 27002 |
|---|---|---|
| Primary purpose | Defines requirements for an ISMS | Provides guidance for information security controls |
| Certification status | Organisations may seek certification to ISO/IEC 27001 from an accredited certification body | Not a standard an organisation can be certified to |
| Main content | ISMS requirements, risk-based management system expectations, Annex A control reference set | Control objectives, implementation guidance, and best-practice considerations |
| Relationship to Annex A | Includes Annex A as a reference set for information security controls | Helps inform implementation of controls aligned with that reference set |
| Who uses it | Leadership, security, GRC, risk, compliance, and audit-readiness teams building or maintaining an ISMS | Control owners, security teams, GRC practitioners, and implementation teams designing or improving controls |
| Audit relevance | The basis for certification assessment | Useful implementation guidance, but not the certification standard |
| Main output | ISMS scope, risk assessment and treatment, Statement of Applicability, implemented controls, evidence | Better-informed control design and implementation decisions |
ISO describes ISO/IEC 27001:2022 as the ISMS requirements standard and ISO/IEC 27002:2022 as guidance for information security controls.
What ISO 27001 requires
ISO/IEC 27001 is concerned with the management system: how the organisation establishes, implements, maintains, and improves information security. It is not just — or, more accurately, not primarily — a list of technical controls. It requires the organisation to understand its context, assess information security risks, decide how to treat those risks, and maintain the ISMS over time.
For certification readiness, the important point is that ISO 27001 is risk-based. Controls are selected because they are necessary for risk treatment, not because every possible control must be implemented identically in every organisation.
Annex A supports that process by providing a reference set of information security controls. The 2022 editions use a 93-control set, described by ISO/IEC 27002 editors as the content for Annex A of the third edition of ISO/IEC 27001 in the ISO/IEC JTC 1/SC 27 journal. The organisation compares the controls it has determined are necessary with that Annex A reference set and documents the result in its Statement of Applicability.
What ISO 27002 provides
ISO/IEC 27002 provides guidance, best practices, and control objectives that can be applied within an ISMS. It basically helps teams interpret what a control can involve in practice: policy choices, technical measures, process design, ownership, monitoring, and supporting documentation.
That makes ISO 27002 useful even though it is not certifiable. A control owner implementing access management, logging, supplier security, or incident handling can use ISO 27002 to understand implementation options and avoid treating Annex A as a bare checklist.
The distinction matters because ISO 27002 does not replace ISO 27001. It can be used as standalone guidance or to support implementation of an ISMS conforming to ISO/IEC 27001, but certification is to ISO/IEC 27001, not ISO/IEC 27002, as reflected in ISO’s description of ISO/IEC 27002:2022.
How ISO 27001 and ISO 27002 work together in practice
In an ISO 27001 readiness effort, the two standards usually connect through a practical chain:
- Define the ISMS scope.
- Assess information security risks within that scope.
- Decide how those risks should be treated.
- Compare necessary controls with the Annex A reference set.
- Use ISO 27002 to inform how selected controls could be implemented.
- Record selected controls, exclusions, justifications, and implementation status in the Statement of Applicability.
- Keep documentation and operating evidence showing that selected controls work as described.
The Statement of Applicability is the bridge between the standards comparison and the audit-readiness work. ISO/IEC 27001 requires the organisation to compare necessary controls with Annex A, and the Statement of Applicability can document necessary controls, their implementation status, and reasons Annex A reference controls are unnecessary, as explained in the ISO/IEC JTC 1/SC 27 journal.
This is where many teams go wrong. They either treat Annex A as a fixed implementation checklist, or they treat ISO 27002 as background reading with no operational consequence. A better approach is to make each control decision traceable: risk, selected treatment, Annex A comparison, implementation approach, SoA entry, and evidence. The practical trail, basically.
Is ISO 27002 mandatory for ISO 27001 certification?
ISO/IEC 27002 is not itself a certifiable standard. ISO/IEC 27001 is the certification target. ISO 27002 can guide implementation, while ISO 27001 requires risk-based control decisions and documented applicability.
That does not mean ISO 27002 should be ignored. It provides a structured way to think about control implementation. If your organisation selects a control that relates to Annex A, ISO 27002 may help you understand implementation considerations and decide what is appropriate for your environment.
It also does not mean every ISO 27002 recommendation must be copied word for word into your control environment. Annex A controls are a reference set rather than requirements in themselves. An organisation may use tailored or additional controls if it can demonstrate conformity to ISO/IEC 27001 risk-treatment requirements and includes necessary controls in its Statement of Applicability, according to the ISO/IEC JTC 1/SC 27 interpretation.
For audit readiness, the safer question is not “Did we implement every sentence of ISO 27002?” It is: “Can we explain our risk-based decision, show how the control is implemented, and provide evidence that it operates as documented?” That is usually the point auditors are getting at.
Worked example: from Annex A control to audit evidence
The following access-control example is just illustrative. It does not quote a specific control statement and should be adapted to your ISMS scope, risk assessment, and reviewed control requirements.
| Step | What happens | Role of ISO 27001 | Role of ISO 27002 | Documentation/evidence |
|---|---|---|---|---|
| 1. Risk identified | The organisation identifies a risk that inappropriate access to production systems could expose sensitive customer data. | Requires risk assessment and treatment decisions within the ISMS. | Helps teams think through access-control implementation options. | Risk register entry describing the access risk, likelihood/impact assessment, and treatment decision. |
| 2. Control selected | The organisation decides that access to production systems should be restricted, approved, reviewed, and removed when no longer needed. | Annex A is used as a reference set when comparing necessary controls. | Provides guidance that can inform how access control is designed and operated. | Control description, control owner, access policy, role definitions, approval workflow. |
| 3. Implementation tailored | The team chooses role-based access for standard roles, separate approval for privileged access, and periodic access reviews for production systems. | Requires the selected control to support risk treatment and be included in the ISMS documentation where applicable. | Helps inform practical decisions such as approval, review, and privileged-access handling. | Access review procedure, privileged-access process, system configuration records. |
| 4. SoA entry written | The Statement of Applicability records the control as applicable, notes that it is implemented through role-based access and periodic review, and links it to the relevant risk. | The SoA documents necessary controls, implementation status, and justification. | Supports the implementation rationale but is not itself the certification target. | SoA entry with applicability, implementation status, justification, control owner, and linked risk. |
| 5. Evidence retained | The organisation keeps evidence that the control operates as described. | Certification readiness depends on showing the ISMS and selected controls are implemented and maintained. | Provides context for what implementation evidence may need to demonstrate. | Examples may include approved access requests, access review records, user removal records, privileged-access approvals, and screenshots or exports from identity systems. |
The exact evidence needed depends on the control design and the audit context. The main thing is alignment: the evidence should support the decision documented in the SoA and the way the control is described as operating.
Which standard should your organisation use?
Use ISO 27001 when your goal is to build, operate, or certify an ISMS. Use ISO 27002 when you need guidance for designing, improving, or interpreting information security controls.
Use both together when preparing for ISO 27001 certification: ISO 27001 defines the requirements and certification basis; ISO 27002 helps inform control implementation; the Statement of Applicability keeps risk decisions connected to Annex A; and evidence shows that selected controls operate as documented.
If your team needs to manage that work operationally, Ciphrix can help keep controls, risks, evidence, and framework mappings organised. The standard still requires judgement and ownership, but the work becomes easier to maintain when decisions and evidence stay connected.
