ISO 27002
What is ISO 27002?
The companion standard to ISO 27001 that provides implementation guidance for the Annex A controls. Not a certifiable standard itself. It supports ISO 27001 implementation.
Related terms
Frameworks that govern iso 27002
What the standards actually require on iso 27002
Requirements naming iso 27002 across 6 standards, quoted from the control text.
Framework Alignment captures the cross-walk between IMO MSC-FAL.1/Circ.3/Rev.2 5 functional elements and parallel international standards + industry guidance for operational implementation.
IMO-MSC-FAL-FrameworkAlignment-NISTCSF-Identify-Protect-Detect-Respond-Recover-IndustryGuidelinesV4-IEC62443 · IMO MSC-FAL Framework Alignment - 5 Functional Elements Map to NIST CSF + Industry Guidelines on Cyber Security Onboard Ships v4 + IEC 62443 + ISO 27001 + USCG NVIC + EU NIS2 + Class Notations →HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encr...
HBNR-Crosswalk-NIST-CSF-ISO-HIPAA · Crosswalk to NIST CSF 2.0, NIST 800-66, ISO 27001/27701, SOC 2 and HIPAA →GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly;
GLI33-Crosswalk-PCI-NIST-ISO-StateStandards · GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards →HKMA C-RAF crosswalk to international + sectoral cybersecurity frameworks. (a) NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 - the 6 CSF functions (Govern + Identify + Protect + Detect + Respond + Recover) map directly to C-RAF 7 domains;
HKMA-CRAF-Crosswalk-NIST-CSF-ISO27001-FFIEC-CBEST-TIBER · HKMA C-RAF Crosswalk to NIST CSF, ISO 27001, FFIEC CAT, CBEST, TIBER-EU and Sectoral Frameworks →HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;
HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline →RBI AA Framework imposes strict IT and data protection controls reflecting the elevated trust and sensitivity of consolidating financial information.
RBI-AA-IT-DataProtection-Transience-NoStorage-E2EE-DataLocalisation-IS-PolicyFramework · RBI AA IT + Data Protection - Data Transience + No Storage at AA + End-to-End Encryption + Data Localisation in India + Information Security Policy + RBI IT Framework for NBFC-AA →Questions people ask about iso 27002
What is ISO 27002?
Why is ISO 27002 important for compliance?
What concepts are related to ISO 27002?
Which compliance frameworks address ISO 27002?
Where can I learn more about ISO 27002?
See how ISO 27002 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.