In short: ISO/IEC 27002:2022 provides guidance on information security controls. It reorganizes controls into four themes — organizational, people, physical and technological — merges many controls, adds 11 new ones and introduces attributes to filter and map controls.
What are the main changes?
- 93 controls instead of 114
- Four themes replace 14 domains
- 11 new controls, including threat intelligence and data masking
- Attributes such as control type and cybersecurity concepts
What does it mean for ISO/IEC 27001 users?
ISO/IEC 27001:2022 Annex A was aligned with these controls, so certified organizations must update their Statement of Applicability.
Key takeaways
- ISO/IEC 27002:2022 has 93 controls in four themes.
- New controls address modern threats.
- Annex A of ISO/IEC 27001:2022 follows this structure.
Frequently asked questions
Is ISO/IEC 27002 certifiable?
No. Organizations certify to ISO/IEC 27001, which references these controls.
What is a Statement of Applicability?
A document listing which controls apply and why.
What are control attributes?
Tags that help organizations view and select controls from different perspectives.