ISO 27002:2022
What is ISO 27002:2022?
Information security, cybersecurity and privacy protection - Information security controls. It comprises 94 controls organised across 7 domains, published by ISO/IEC, and applies in International.
How ISO 27002:2022 maps to other frameworks
All 94 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains ISO 27002:2022 groups its controls into
Where ISO 27002:2022 overlaps with the standards you already hold
More ISO 27002:2022 comparisons
Training that covers ISO 27002:2022
Where to get trained on ISO 27002:2022
4 courses in the catalogue cover ISO 27002:2022 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO 27002:2022 means in your sector
What ISO 27002:2022 means for your job
Questions people ask about ISO 27002:2022
What is ISO 27002:2022?
How many controls does ISO 27002:2022 have?
Where does ISO 27002:2022 apply?
What frameworks does ISO 27002:2022 map to?
How do I get started with ISO 27002:2022 compliance?
Query ISO 27002:2022 programmatically
ISO 27002:2022, its 94 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 27002:2022 API reference and MCP config →What ISO 27002:2022 requires, control by control
Each page carries the requirement text for one ISO 27002:2022 control and what an assessor expects to see as evidence.
- 5-1 Policies for information security
- 5-10 Acceptable use of information and other associated assets
- 5-11 Return of assets
- 5-12 Classification of information
- 5-13 Labelling of information
- 5-14 Information transfer
- 5-15 Access control
- 5-16 Identity management
- 5-17 Authentication information
- 5-18 Access rights
How much of another standard ISO 27002:2022 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to ISO 27002:2022 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to ISO 27002:2022 crosswalk
- APRA CPS 230 Operational Risk Management to ISO 27002:2022 crosswalk
- APRA CPS 234 to ISO 27002:2022 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to ISO 27002:2022 crosswalk
- Australia Consumer Data Right - Banking (CDR) to ISO 27002:2022 crosswalk
- Australia My Health Records Act 2012 to ISO 27002:2022 crosswalk
- AWS Well-Architected Security Pillar to ISO 27002:2022 crosswalk
How ready are you for ISO 27002:2022?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.