ISO/IEC 27002
Information security standard

ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and by the International Electrotechnical Commission (IEC), titled Information security, cybersecurity and privacy protection — Information security controls.
The ISO/IEC 27000 family of standards are descended from a corporate security standard donated by Shell to a UK government initiative in the early 1990s. The Shell standard was developed into British Standard BS 7799 in the mid-1990s, and was adopted as ISO/IEC 17799 in 2000. The ISO/IEC standard was revised in 2005, and renumbered ISO/IEC 27002 in 2007 to align with the other ISO/IEC 27000-series standards. It was revised again in 2013 and in 2022. Later in 2015 the ISO/IEC 27017 was created from that standard in order to suggest additional security controls for the cloud which were not completely defined in ISO/IEC 27002.
ISO/IEC 27002 provides best practice recommendations on information security controls for use by those responsible for initiating, implementing or maintaining information security management systems (ISMS). Information security is defined within the standard in the context of the CIA triad:
the preservation of confidentiality (ensuring that information is accessible only to those authorized to have access), integrity (safeguarding the accuracy and completeness of information and processing methods) and availability (ensuring that authorized users have access to information and associated assets when required).
Outline
Outline for ISO/IEC 27002:2022
The standard starts with 4 introductory chapters:
Scope
Normative Reference
Terms, definitions, and abbreviated terms
Structure of this document
These are followed by 4 main chapters:
Organizational controls
People controls
Physical controls
Technological controls
Outline for ISO/IEC 27002:2013
The standard starts with 5 introductory chapters:
Introduction
Scope
Normative references
Terms and definitions
Structure of this standard
These are followed by 14 main chapters:
Information Security Policies
Organization of Information Security
Human Resource Security
Asset Management
Access Control
Cryptography
Physical and environmental security
Operation Security- procedures and responsibilities, Protection from malware, Backup, Logging and monitoring, Control of operational software, Technical vulnerability management and Information systems audit coordination
Communication security - Network security management and Information transfer
System acquisition, development and maintenance - Security requirements of information systems, Security in development and support processes and Test data
Supplier relationships - Information security in supplier relationships and Supplier service delivery management
Information security incident management - Management of information security incidents and improvements
Information security aspects of business continuity management - Information security continuity and Redundancies
Compliance - Compliance with legal and contractual requirements and Information security reviews
Controls
Within each chapter, information security controls and their objectives are specified and outlined. The information security controls are generally regarded as best practice means of achieving those objectives.
Begin with the source’s own compact description: “ISO/IEC 27002” is information security standard. The dossier treats that line as a proposition to test through Information, security and standard, not as a finished interpretation.
Why this record matters
The phrase “information security standard” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.
Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 9, 2026. The linked authority identifier is Q1654656. None of the 1 selected statements returned an explicit reference. The first chronological checks are 2000, 2005, 2007 and 2013.
The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “ISO/IEC 27002”, its source revision and the description used here.
- Expand the search: follow ISO/IEC 27002 primary sources, ISO/IEC 27002 archive and Information research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “ISO/IEC 27002”?
- What terminology or title could unlock a more precise catalogue search?
- Which cited source is closest to the event, object or claim?
Search terms from this dossier
This entry incorporates text from “ISO/IEC 27002” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.