Skip to content

ISO 27002

What is ISO 27002?

The companion standard to ISO 27001 that provides implementation guidance for the Annex A controls. Not a certifiable standard itself. It supports ISO 27001 implementation.

Information Security

What the standards actually require on iso 27002

Requirements naming iso 27002 across 6 standards, quoted from the control text.

HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encr...

HBNR-Crosswalk-NIST-CSF-ISO-HIPAA · Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA

GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly;

GLI33-Crosswalk-PCI-NIST-ISO-StateStandards · GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards

HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;

HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks
HKMA TM-G-11 control

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

Questions people ask about iso 27002

What is ISO 27002?
The companion standard to ISO 27001 that provides implementation guidance for the Annex A controls. Not a certifiable standard itself. It supports ISO 27001 implementation.
Why is ISO 27002 important for compliance?
ISO 27002 is a key concept in Information Security. Understanding iso 27002 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to ISO 27002?
Key concepts related to ISO 27002 include ISO 27001, Annex A. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address ISO 27002?
ISO 27002 appears in the requirement text of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), FTC Health Breach Notification Rule, GLI-33 - Gaming Laboratories International Event Wagering Systems, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA TM-G-1. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about ISO 27002?
Explore our compliance framework pages to see how iso 27002 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how ISO 27002 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.