Skip to main content
FRAMEWORK

27002 answers how. 27001 is what's certified.

ISO/IEC 27002 is the companion volume, and it is the one people actually read. Where 27001 names a control in a single line, 27002 explains what it is for, how it is typically implemented, and what to think about while doing it. It covers the same control set under the same four themes — organizational, people, physical, technological — and it is guidance, not a certifiable standard. Nobody audits you against 27002.

Which is exactly why it goes missing at the moment it is most useful. The guidance lives in a document; the control lives in your evidence system; and the person implementing the control is not reading the document. Held apart, 27002 becomes something referenced during the design phase and never again. Held against the control entry itself, it is available at the point the work is being done.

Who it applies to

Anyone implementing the controls 27001 requires — so, in practice, the same teams, for the same reason, at a different moment. It is also used on its own by organizations with no intention of seeking a certificate, as a well-argued reference for what a given control ought to look like when it is done properly.

How 27002 relates to 27001

27001 states the requirement and names the control; 27002 tells you how the control is normally implemented. You are certified against the first and guided by the second, and the pair works the same way ISO 27005 relates to risk assessment or ISO 23894 relates to AI risk. The 2022 revision added attributes to each control — control type, information security properties, cybersecurity concepts, operational capabilities and security domains — so the same control set can be filtered along whichever dimension the question came in on. That is genuinely useful when a customer asks about detective controls and your control library is organized by theme.

What it asks, in operating terms

Read as an operating aid rather than a document, 27002 reduces to a handful of standing asks — each answerable at the control, not in a PDF someone has to go and find.

ISO 27002 guidance · how TruSecure answers it
What 27002 offersWhere it is answered
Implementation guidance for each Annex A controlControl library · guidance surfaced on the control entry
Attributes to filter controls by type and purposeControl library · same set, viewed along the axis you need
A shared definition of what "implemented" meansEvidence requirements · defined per control, not per person
One control set feeding 27001 certification evidenceShared control library · guidance and evidence on one entry

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a control entry is made of:

Control entry · 27002 viewSample data
Theme
technological
Guidance
27002 · shown against the control, not filed separately
Attributes
control type · security property · capability
Evidence
continuous · provenance tracked
Also cited by
ISO 27001 · CIS Controls · NIST CSF

Where teams usually start

With a demo walked through by TruSecure — a single control opened to its 27002 guidance, its attributes and its evidence in one place, and the same entry answering an auditor sampling against 27001. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

ISO/IEC 27002 provides implementation guidance for the Annex A controls defined in ISO 27001 — it is not itself a certifiable standard. TruSecure surfaces 27002 guidance directly against the same control entries used for 27001 evidence.