
Introduction
Organizations pursuing ISO 27001 certification inevitably encounter ISO 27002 — and the confusion that follows is predictable. Which standard governs the audit? Do you need both?
These aren't trivial questions. Misunderstanding how the two documents relate leads to real preparation failures — teams that study ISO 27002 extensively but have no coherent ISMS structure, or teams with a solid management framework that implement controls without the guidance the standard was designed to provide.
Here's the short version: ISO 27001 is the certifiable management standard that defines what your ISMS must do. ISO 27002 is the non-certifiable implementation guide that explains how to apply the controls ISO 27001 references. They're not alternatives. They're sequential tools in the same compliance workflow.
By the end, you'll know exactly how these standards interact, what changed in 2022, and which document to reach for at each stage of your ISMS build.
Key Takeaways
- ISO 27001 defines ISMS requirements — it's the only one you can certify against
- ISO 27002 provides implementation guidance for Annex A controls, with no certification pathway
- The 2022 revisions reduced controls from 114 to 93 and reorganized them into 4 thematic categories
- Most organizations need both documents at different stages of their compliance work
- Start with ISO 27001; move to ISO 27002 when you're ready to implement individual controls
ISO 27001 vs. ISO 27002: Quick Comparison
| Dimension | ISO/IEC 27001:2022 | ISO/IEC 27002:2022 |
|---|---|---|
| Primary Purpose | Specifies auditable ISMS requirements | Provides control implementation guidance |
| Certification Available | Yes — third-party certification | No — guidance document only |
| Standard Type | Management system standard | Reference/supplementary standard |
| Control Detail Level | One-sentence description per control | ~One page of implementation guidance per control |
| Governing Body | ISO/IEC JTC 1/SC 27 | ISO/IEC JTC 1/SC 27 |
| Normative Language | "Shall" (requirements) | "Should," "may," "can" (guidance) |
| When to Reference It | Scoping, risk assessment, audit prep | Control design and implementation |
Both standards are published jointly by ISO and IEC under the same technical committee. They share the same 93-control Annex A set — ISO 27002:2022 updated its structure specifically to align with ISO 27001:2022. These documents are intentionally designed to be read together.

What Is ISO 27001?
ISO 27001 is the international management standard for information security. It specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). ISO confirms more than 70,000 certificates across 150 countries and all economic sectors.
Structure: Clauses 4–10 and Annex A
The standard has two distinct parts:
- Clauses 4–10 — The mandatory ISMS requirements covering context, leadership, planning, support, operation, performance evaluation, and improvement
- Annex A — A reference set of 93 controls (post-2022) organized under four themes: Organizational, People, Physical, and Technological
Annex A is not a checklist where every control applies to every organization. The standard requires a systematic risk assessment to determine which controls are relevant, and organizations document those decisions in a Statement of Applicability (SoA) — a mandatory output required by Clause 6.1.3.
The SoA records which controls apply, their implementation status, why they were included, and the justification for excluding any Annex A control.
Who Benefits from ISO 27001 Certification
ISO 27001 is used across all sectors and organization sizes. Common contexts include:
- Defense contractors managing controlled unclassified information (CUI) alongside CMMC and NIST 800-171 requirements
- SaaS companies seeking enterprise customer trust
- Government suppliers required to demonstrate structured information security governance
- Any regulated organization that must show a formal approach to managing information security risk
Use Cases of ISO 27001
- Building a new ISMS — defining scope, policies, and governance for a new program
- Pursuing third-party certification — satisfying customer or regulatory requirements that require formal audit evidence
- Risk treatment documentation — formally recording which controls apply and why
- Internal audit programs — establishing audit cycles that satisfy registrar expectations
ISO 27001 is the governing document during an audit. Registrars evaluate conformance against clauses 4–10 and the selected Annex A controls. ISO 27002 is never the direct subject of an audit, though it shapes how controls are implemented.
What Is ISO 27002?
ISO 27002 is a supplementary control guidance document. It provides detailed implementation guidance for the 93 controls listed in ISO 27001's Annex A. It is not a management standard, contains no ISMS requirements, and has no certification process — organizations cannot be certified against it.
Where ISO 27001 describes each Annex A control in a sentence or two, ISO 27002 dedicates approximately one page per control, covering its purpose, implementation considerations, and how it reduces specific information security risks.
The 2022 Structural Update
The 2022 revision significantly reorganized ISO 27002. Controls were reduced from 114 to 93, and the previous 14-domain structure was replaced with 4 thematic categories:
| Theme | Control Count |
|---|---|
| Organizational Controls (5.1–5.37) | 37 |
| People Controls (6.1–6.8) | 8 |
| Physical Controls (7.1–7.14) | 14 |
| Technological Controls (8.1–8.34) | 34 |
The 2022 update introduced 11 new controls addressing modern threat environments:
- 5.7 Threat intelligence
- 5.23 Information security for use of cloud services
- 5.30 ICT readiness for business continuity
- 7.4 Physical security monitoring
- 8.9 Configuration management
- 8.10 Information deletion
- 8.11 Data masking
- 8.12 Data leakage prevention
- 8.16 Monitoring activities
- 8.23 Web filtering
- 8.28 Secure coding

Control Attributes
ISO 27002:2022 introduced five attribute groups that accompany each control. | Attribute | Values | |---|---| | Control type | Preventive, detective, corrective | | Information security properties | Confidentiality, integrity, availability | | Cybersecurity concepts | Identify, protect, detect, respond, recover | | Operational capabilities | Governance, asset management, physical security, and others | | Security domains | Governance and ecosystem, protection, defence, resilience |
These attributes make it easier to filter and sort controls — and to map them against other frameworks like NIST CSF or CMMC. Any such mapping is a separate exercise from ISO 27001 conformity itself.
Use Cases of ISO 27002
Pull out ISO 27002 after completing your risk assessment and identifying applicable Annex A controls. At that point, ISO 27002 is the reference practitioners use to understand exactly how to design and operate each selected control.
It's especially useful in three situations:
- Control design: teams deciding how to build a specific control from scratch
- Gap analysis: evaluating whether an existing control meets the standard's intent
- Staff guidance: giving security generalists enough implementation detail to work without outside consultants on every control
Key Differences Between ISO 27001 and ISO 27002
The most important distinction is also the simplest: one is certifiable, one is not. ISO 27001 governs the audit. ISO 27002 informs the work.
Scope of Content
- ISO 27001 covers the full ISMS lifecycle: scope definition, risk assessment, leadership, objectives, monitoring, internal audit, management review, and continual improvement
- ISO 27002 covers only the control dimension — it contains zero ISMS management requirements
Level of Control Detail
ISO 27001's Annex A provides a control name and a one-sentence description for each of its 93 controls. ISO 27002 expands each of those into a full page of implementation guidance. Organizations that implement controls using ISO 27001 alone — without referencing ISO 27002 — are making design decisions without the context the standard was built to provide.
Language and Obligation
ISO 27001 uses "shall" throughout its requirements (auditor-enforceable language under ISO drafting rules). ISO 27002 uses "should," "may," and "can" — the language of recommendations. Organizations are free to deviate from ISO 27002 guidance as long as their implemented controls satisfy the ISO 27001 requirements they're mapped to.
The practical effect: "shall" creates audit findings; "should" creates design choices.
The Common Misconception
ISO 27002 is not an older version of ISO 27001, and it is not an alternative. The confusion arises because ISO 27002 looks like a standalone control standard, but it exists specifically to support the controls ISO 27001 references. It supplements the management framework; it does not replace it.
The Practical Workflow
Follow this order:
- Use ISO 27001 to scope your ISMS, conduct your risk assessment, and determine which Annex A controls apply
- Document your decisions in the Statement of Applicability
- Use ISO 27002 to understand how to actually build and operate each applicable control
- Then go into your certification audit with both a defensible ISMS structure and controls that reflect the standard's intended design

Which Standard Should You Use and When?
Start with ISO 27001. Always. Control implementation guidance is meaningless without the scoping and risk assessment decisions ISO 27001 requires upfront — knowing how to implement a control that doesn't apply to your risk profile adds no compliance value.
Situational Guide
| Situation | Standard to Use |
|---|---|
| Defining ISMS scope | ISO 27001 |
| Conducting risk assessment | ISO 27001 |
| Assigning internal ISMS responsibilities | ISO 27001 |
| Preparing the Statement of Applicability | ISO 27001 |
| Preparing for a certification audit | ISO 27001 |
| Implementing a specific Annex A control | ISO 27002 |
| Understanding a control's purpose and risk reduction | ISO 27002 |
| Training teams on control design decisions | ISO 27002 |
For defense contractors, this sequencing intersects with CMMC and NIST 800-171 requirements in ways that create additional complexity. ISO 27001 certification is not a substitute for a CMMC assessment — NIST's mapping to ISO 27001 is informal, and the CMMC rule independently assesses its own requirements. Meaningful control overlap does exist, and teams that understand both frameworks avoid duplicating implementation work.
QMS Learning's Defense Cybersecurity Readiness pathway (pilot cohort opening Q3 2026) addresses this directly. The pathway bundles three courses into a single program:
- ISO 27001 ISMS — risk assessment, Annex A controls, Statement of Applicability, and certification audit preparation
- CMMC & NIST 800-171 — control implementation and assessment readiness for defense contractors
- SOC 2 — trust service criteria and audit evidence requirements
The QMS Workbench AI tool, included in the pathway, is trained on ISO 27001 Annex A, NIST SP 800-171, and CMMC assessment guides — giving compliance teams a cross-framework environment to draft SSP sections and build POA&M entries. The pilot cohort is limited to five organizations, with early-access pricing for teams that join before public launch.
Conclusion
ISO 27001 and ISO 27002 are sequential tools with different jobs. ISO 27001 establishes and governs your ISMS. ISO 27002 tells you how to implement the controls that ISMS requires.
Teams that treat them as interchangeable end up in one of two failure states: a documented framework built around poorly implemented controls, or well-implemented controls sitting inside no coherent management system. Neither holds up under a registrar review.
Knowing where each standard begins and ends stops teams from misallocating audit effort. Walk into your certification audit with both: a defensible ISMS structure anchored to ISO 27001 clauses 4–10, and controls implemented with the rigor ISO 27002 was designed to provide.
Frequently Asked Questions
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable management standard that defines what your ISMS must do — it's what auditors assess conformance against. ISO 27002 is a non-certifiable implementation guide that expands each Annex A control with practical design guidance. They're complementary, not interchangeable.
Is ISO 27001 better than SOC 2?
They serve different purposes. ISO 27001 is an internationally recognized ISMS certification suited for global markets and regulated industries; SOC 2 is an AICPA-defined attestation examination used primarily by US-based service organizations. The right framework depends on where your customers and regulators are.
Can you get certified to ISO 27002?
No. ISO 27002 has no certification pathway. Only management system standards — like ISO 27001 — support third-party certification. ISO 27002 is a guidance document that organizations reference internally when implementing controls, but registrars never audit it.
Do I need both ISO 27001 and ISO 27002?
In practice, yes. ISO 27001 structures and governs your ISMS; ISO 27002 provides the implementation detail needed to build each applicable control with enough rigor to satisfy an auditor reviewing the evidence. Using only one leaves a meaningful gap.
What are the 4 control themes in ISO 27001:2022 Annex A?
The 2022 revision introduced four thematic categories: Organizational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34). This replaced the previous 14-domain structure.
How many controls does ISO 27001 have after the 2022 update?
ISO 27001:2022 Annex A contains 93 controls, reduced from 114 in the 2013 version. The revision merged redundant controls and added 11 new ones covering threat intelligence, cloud services, data masking, and secure coding. The remainder were updated for clarity.


