CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

ISO/IEC 27002

Information security standard

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionSep 9, 2026
Entity authorityQ1654656
Source-derived summary

ISO/IEC 27002 is an information security standard published by the International Organization for Standardization (ISO) and by the International Electrotechnical Commission (IEC), titled Information security, cybersecurity and privacy protection — Information security controls.

The ISO/IEC 27000 family of standards are descended from a corporate security standard donated by Shell to a UK government initiative in the early 1990s. The Shell standard was developed into British Standard BS 7799 in the mid-1990s, and was adopted as ISO/IEC 17799 in 2000. The ISO/IEC standard was revised in 2005, and renumbered ISO/IEC 27002 in 2007 to align with the other ISO/IEC 27000-series standards. It was revised again in 2013 and in 2022. Later in 2015 the ISO/IEC 27017 was created from that standard in order to suggest additional security controls for the cloud which were not completely defined in ISO/IEC 27002.

ISO/IEC 27002 provides best practice recommendations on information security controls for use by those responsible for initiating, implementing or maintaining information security management systems (ISMS). Information security is defined within the standard in the context of the CIA triad:

the preservation of confidentiality (ensuring that information is accessible only to those authorized to have access), integrity (safeguarding the accuracy and completeness of information and processing methods) and availability (ensuring that authorized users have access to information and associated assets when required).

Outline

Outline for ISO/IEC 27002:2022

The standard starts with 4 introductory chapters:

Scope

Normative Reference

Terms, definitions, and abbreviated terms

Structure of this document

These are followed by 4 main chapters:

Organizational controls

People controls

Physical controls

Technological controls

Outline for ISO/IEC 27002:2013

The standard starts with 5 introductory chapters:

Introduction

Scope

Normative references

Terms and definitions

Structure of this standard

These are followed by 14 main chapters:

Information Security Policies

Organization of Information Security

Human Resource Security

Asset Management

Access Control

Cryptography

Physical and environmental security

Operation Security- procedures and responsibilities, Protection from malware, Backup, Logging and monitoring, Control of operational software, Technical vulnerability management and Information systems audit coordination

Communication security - Network security management and Information transfer

System acquisition, development and maintenance - Security requirements of information systems, Security in development and support processes and Test data

Supplier relationships - Information security in supplier relationships and Supplier service delivery management

Information security incident management - Management of information security incidents and improvements

Information security aspects of business continuity management - Information security continuity and Redundancies

Compliance - Compliance with legal and contractual requirements and Information security reviews

Controls

Within each chapter, information security controls and their objectives are specified and outlined. The information security controls are generally regarded as best practice means of achieving those objectives.

Editorial summary

Begin with the source’s own compact description: “ISO/IEC 27002” is information security standard. The dossier treats that line as a proposition to test through Information, security and standard, not as a finished interpretation.

Editorial reviewA practical starting point whose main value is the path it opens into stronger specialist and primary sources. The current lead gives the account dated anchors—2000, 2005, 2007, 2013—that can be checked directly. The selected authority fields contribute no independent date. For this dossier, Information, security and standard is the immediate research focus.
Editorial analysis

Why this record matters

The phrase “information security standard” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.

Evidence profile

Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 9, 2026. The linked authority identifier is Q1654656. None of the 1 selected statements returned an explicit reference. The first chronological checks are 2000, 2005, 2007 and 2013.

Critical limits

The absence of detail may reflect summary conventions rather than a lack of surviving documentation. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “ISO/IEC 27002”, its source revision and the description used here.
  2. Expand the search: follow ISO/IEC 27002 primary sources, ISO/IEC 27002 archive and Information research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “ISO/IEC 27002”?
  2. What terminology or title could unlock a more precise catalogue search?
  3. Which cited source is closest to the event, object or claim?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from ISO/IEC 27002” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.