ISO 27001 and ISO 27002 are two closely related standards within the ISO/IEC 27000 family of information security standards. Because they have similar names and both address information security, they are often confused.
However, they serve different purposes.
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It is also the standard against which organizations can pursue certification.
ISO/IEC 27002 provides guidance on information security controls and helps organizations understand how controls can be implemented and managed within their information security framework.
Understanding the difference can help organizations and professionals choose the right standard for their objectives.
What Is ISO 27001?
ISO/IEC 27001 is the international standard for Information Security Management Systems.
It provides requirements that organizations can use to establish a systematic and risk-based approach to information security.
An ISMS based on ISO 27001 helps organizations identify information security risks, determine appropriate treatment, implement relevant controls, monitor performance, and continually improve their information security processes.
ISO 27001 can be applied to organizations of different sizes and across different industries.
What Is ISO 27002?
ISO/IEC 27002 is a guidance standard focused on information security controls.
It provides additional guidance that can help organizations understand and implement appropriate information security controls as part of their ISMS.
The guidance covers areas such as access control, physical security, human resource security, cryptography, supplier relationships, incident management, and other information security practices.
ISO 27002 is therefore useful as a supporting resource when an organization is implementing and improving its information security controls.
ISO 27001 vs ISO 27002: The Main Difference
The simplest way to understand the difference is:
ISO 27001 = Requirements for the ISMS
ISO 27002 = Guidance for information security controls
ISO 27001 addresses the broader management system, including requirements related to organizational context, leadership, planning, risk assessment, operation, performance evaluation, and continual improvement.
ISO 27002 focuses more specifically on information security controls and provides guidance for their implementation.
Can an Organization Get ISO 27001 Certification?
Yes.
Organizations can undergo an independent certification audit against ISO/IEC 27001 requirements.
Certification provides a way for an organization to demonstrate to customers, business partners, and other interested parties that its information security management system has been independently assessed against the applicable requirements.
Organizations can also implement ISO 27001 without pursuing certification if certification is not part of their objectives.
Can You Get ISO 27002 Certification?
No.
ISO 27002 is a guidance standard and is not used as the certification standard for an organization’s ISMS.
Organizations seeking certification generally pursue certification against ISO 27001.
ISO 27002 can instead be used as supporting guidance when selecting, understanding, and implementing information security controls.
How Do ISO 27001 and ISO 27002 Work Together?
The two standards can complement each other.
An organization can use ISO 27001 to establish the requirements and framework for its ISMS while using ISO 27002 to obtain additional guidance on information security controls.
A simplified approach could look like this:
- Establish the ISMS based on ISO 27001 requirements.
- Identify and assess information security risks.
- Determine appropriate risk treatment.
- Select relevant information security controls.
- Use ISO 27002 guidance to support control implementation.
- Monitor and evaluate the effectiveness of the ISMS.
- Continually improve the system.
This allows organizations to combine the management-system requirements of ISO 27001 with the practical control guidance provided by ISO 27002.
What Are Information Security Controls?
Information security controls are measures used to help an organization manage information security risks.
Depending on the organization’s circumstances, controls may address areas such as:
- Access management
- Information security awareness
- Asset management
- Physical security
- Cryptography
- Supplier security
- Incident management
- Business continuity
- Monitoring and logging
- Secure development
The appropriate controls depend on the organization’s risks, objectives, scope, and business environment.
Organizations should not simply implement every available control without considering their specific circumstances. A risk-based approach is central to ISO 27001.
ISO 27001 and the Statement of Applicability
The Statement of Applicability (SoA) is an important part of an ISO 27001 implementation.
It documents the organization’s selected controls, their implementation status, and the justification for including or excluding controls within the ISMS.
This helps demonstrate how the organization’s information security controls relate to its identified risks and requirements.
ISO 27002 can provide useful implementation guidance when organizations are considering how selected controls can be applied in practice.
ISO 27001 vs ISO 27002: Which One Should You Use?
The answer depends on your objective.
If you want to establish an ISMS
ISO 27001 should be the primary standard because it defines the requirements for the Information Security Management System.
If you want guidance on security controls
ISO 27002 can provide additional guidance for understanding and implementing information security controls.
If you want organizational certification
ISO 27001 is the relevant certification standard.
If you are an information security professional
Understanding both standards can be valuable because ISO 27001 provides the overall ISMS framework while ISO 27002 provides additional control-related guidance.
ISO 27001 and ISO 27002 for Professionals
Knowledge of ISO 27001 and ISO 27002 can be useful for professionals working in:
- Information security
- Cybersecurity
- Governance, Risk and Compliance (GRC)
- Risk management
- IT management
- Internal auditing
- Compliance
- Information security consulting
Professionals can choose training based on their career objectives and responsibilities.
Foundation-level training can provide an introduction to ISO 27001 and information security management, while Lead Implementer and Lead Auditor training can provide more specialized knowledge for implementation and auditing activities.
ISO 27001 vs ISO 27002: Quick Comparison
| ISO 27001 | ISO 27002 |
|---|---|
| Defines requirements for an ISMS | Provides guidance on information security controls |
| Supports organizational certification | Not a certification standard |
| Focuses on the management system | Focuses on control guidance |
| Uses a risk-based approach | Provides detailed control guidance |
| Suitable for organizations establishing an ISMS | Useful for organizations implementing and improving controls |
Conclusion
ISO 27001 and ISO 27002 are complementary but serve different purposes.
ISO 27001 defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System and provides the basis for organizational certification.
ISO 27002 provides additional guidance on information security controls and can support organizations in understanding and implementing appropriate security measures.
For organizations and professionals working toward stronger information security practices, understanding how these two standards work together can provide a clearer and more structured approach to information security management.
Interested in ISO 27001 Certification Training?
Explore our ISO/IEC 27001 training programs and choose the learning format that best fits your professional goals.



