Skip to main content
Framework library
Framework module · iso-27002-2022

ISO/IEC 27002

The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.

2022 · ISO/IEC 27002:2022 · published 2022-02-15

Standing today
Directory entry

00Answer

from the registry record
What is ISO/IEC 27002?
The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.
Who does ISO/IEC 27002 apply to?
ISO/IEC 27002 applies to all sectors, SaaS, technology, global, per ISO/IEC 27002:2022.
What is the current version of ISO/IEC 27002?
The current edition is 2022, issued by ISO/IEC 27002:2022 and published 2022-02-15. Source: https://www.iso.org/standard/75652.html.
What does an assessment under ISO/IEC 27002 require?
No control catalog has been ingested for ISO/IEC 27002 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

ISO/IEC 27002 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Organizational · People · Physical · Technological
Applies to
all sectors · SaaS · technology · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06

03Version ledger

2 editions
2013Supersededdate not published
2022Current edition · supersedes 20132022-02-15

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to SaaS · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

  2. Also applies to SaaS · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

  3. ISO/IEC 270012022 (Amd 1:2024)

    Also applies to all sectors · The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.

  4. Also applies to technology · International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.

ISO/IEC 27002 | ControlFrame