ISO 27001 + 1

ISO 27001 + 1

ISO 27001 and ISO 27002 are two essential standards within the ISO 27000 family, both focusing on information security management. While they are closely related, they serve distinct purposes and work together to provide a comprehensive approach to safeguarding an organization’s information assets.

While ISO 27001 provides the framework for an ISMS, ISO 27002 offers detailed guidance on the interpretation and implementation of specific information security controls. While ISO 27001 defines the “what” (requirements for the ISMS), ISO 27002 defines the “how” (how to implement specific controls).

The relationship between ISO 27001 and ISO 27002 is symbiotic. ISO 27001 provides the strategic direction, framework, and process structure for managing information security, while ISO 27002 provides practical guidance for the implementation of security controls that help fulfill ISO 27001’s requirements. This is why ISO 27001 Annex A references match exactly with ISO 27002 standard body references.

ISO 27002 is not a certification standard, so you don’t have to address every item in the guidance description. But it is very useful to match all of them with your assets to decide if there is a need to define a control element. There should be a balance between the resources deployed for implementing controls and the potential resulting business impact from security incidents in the absence of those controls.

Information has a life cycle, from creation to disposal. The value of and risks to a piece of information can vary throughout this life cycle (e.g. unauthorized disclosure or theft of a company’s financial accounts is not significant after they have been published, but maintaining integrity is still critical) therefore, information security remains important to some extent at all stages. Guidance in ISO 27002 helps to remember control requirements resulting from asset lifecycle.

ISO 27002 contains an attribute table for each control. It is nice to have, but it is not always fully consequent. For example, both controls 5.35 and 5.36 request a review, but the control type of the former is preventive and corrective, while the latter’s is preventive only. The review itself is always preventive and the actions resulting from the review are always corrective in nature. In fact, a review is pretty useless in itself without correcting the findings.

08/09/2025
DACHS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.