27002 answers how. 27001 is what's certified.
ISO/IEC 27002 is the companion volume, and it is the one people actually read. Where 27001 names a control in a single line, 27002 explains what it is for, how it is typically implemented, and what to think about while doing it. It covers the same control set under the same four themes — organizational, people, physical, technological — and it is guidance, not a certifiable standard. Nobody audits you against 27002.
Which is exactly why it goes missing at the moment it is most useful. The guidance lives in a document; the control lives in your evidence system; and the person implementing the control is not reading the document. Held apart, 27002 becomes something referenced during the design phase and never again. Held against the control entry itself, it is available at the point the work is being done.
Who it applies to
Anyone implementing the controls 27001 requires — so, in practice, the same teams, for the same reason, at a different moment. It is also used on its own by organizations with no intention of seeking a certificate, as a well-argued reference for what a given control ought to look like when it is done properly.
How 27002 relates to 27001
27001 states the requirement and names the control; 27002 tells you how the control is normally implemented. You are certified against the first and guided by the second, and the pair works the same way ISO 27005 relates to risk assessment or ISO 23894 relates to AI risk. The 2022 revision added attributes to each control — control type, information security properties, cybersecurity concepts, operational capabilities and security domains — so the same control set can be filtered along whichever dimension the question came in on. That is genuinely useful when a customer asks about detective controls and your control library is organized by theme.
What it asks, in operating terms
Read as an operating aid rather than a document, 27002 reduces to a handful of standing asks — each answerable at the control, not in a PDF someone has to go and find.
| What 27002 offers | Where it is answered |
|---|---|
| Implementation guidance for each Annex A control | Control library · guidance surfaced on the control entry |
| Attributes to filter controls by type and purpose | Control library · same set, viewed along the axis you need |
| A shared definition of what "implemented" means | Evidence requirements · defined per control, not per person |
| One control set feeding 27001 certification evidence | Shared control library · guidance and evidence on one entry |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a control entry is made of:
- Theme
- technological
- Guidance
- 27002 · shown against the control, not filed separately
- Attributes
- control type · security property · capability
- Evidence
- continuous · provenance tracked
- Also cited by
- ISO 27001 · CIS Controls · NIST CSF
Where teams usually start
With a demo walked through by TruSecure — a single control opened to its 27002 guidance, its attributes and its evidence in one place, and the same entry answering an auditor sampling against 27001. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
ISO/IEC 27002 provides implementation guidance for the Annex A controls defined in ISO 27001 — it is not itself a certifiable standard. TruSecure surfaces 27002 guidance directly against the same control entries used for 27001 evidence.