ISO 27001 And ISO 27002 – What’s the difference?
ISO 27001 And ISO 27002 confusion!
If you’ve been exploring information security standards for more than five minutes, you’ve probably encountered two very similar-looking names:
- ISO 27001
- ISO 27002
You might also be asked by clients to prove you are ISO 27001 AND ISO27002 compliant.
You’re probably now asking a perfectly reasonable question:
“Wait… aren’t they basically the same thing?”
No. Not at all.
They are related, like siblings. But confusing them can lead to misunderstandings, a lot of wasted effort, and occasionally the kind of awkward silence that happens halfway through an ISO audit when someone realises they’ve been preparing for the wrong thing.
So let’s clear things up. Because once you understand the difference between ISO 27001 and ISO 27002, everything about information security standards suddenly makes a lot more sense, makes things a lot easier to manage. And more importantly, you’ll know what actually you’re being asked to do
What is ISO 27002?
First of all, let’s talk about what ISO 27002 is NOT… It is NOT a standard!
You can NOT certify to ISO 27002.
There you go Are we clear? Good.
So what is it? In a word, it’s ‘Guidance’. Saying “We’ve implemented ISO 27002.” Is a bit like saying “We’ve implemented the Highway Code.”
You can certainly follow the Highway Code. You can use it for guidance and you can base your driving behaviour on it. But you don’t get certified in the Highway Code! (ok, yes you pass your test which is based on the Highway Code, but it covers everything not just what needs to be done.)
So what’s the difference between ISO 27001 and ISO 27002?
Let’s start with the simplest explanation possible.
ISO 27001 is the certifiable standard and defines what you SHALL do
ISO 27002 is guidance and suggests what you SHOULD do to implement the Annex A controls.
Think of it this way: ISO 27001 is the rulebook that auditors will assess you against. It contains a list of Clauses that the auditor will review, along with the controls that you have selected to protect against the risks you have identified.
ISO 27002 offers you advice and guidance on how to implement the conrols you have selected. It only focuses on the controls, and offers suggestions on what you might implement.
Clear? No? Ok… Perhaps think of it this way;
ISO 27002 is the study guide. Use it to figure out how to implement security controls.
ISO 27001 is the exam. You get a nice certificate once you pass it..
What ISO 27001 Actually Is.
ISO 27001 is the international standard for building and running an Information Security Management System (ISMS). The key words are ‘Management System’. Now, before your eyes glaze over at this phrase, here’s what that really means.
ISO 27001 is about how your organisation manages information security, not just the security tools and controls you buy and implement.
It asks questions like:
- Do you understand the context of your organisation?
- Do you understand your security risks?
- Have you implemented controls to manage them?
- Do you review and improve those controls over time?
- Is security embedded into how the business operates?
In other words:
ISO 27001 focuses on governance, structure, accountability, and continual improvement. It’s not just about firewalls and passwords. It’s about how security is managed across the business.
If you were baking a cake you’d probably follow a recipe, and that’s what ISO 27001 is; It’s a receipe for successfully building (and managing) security. No guessing. No half-baked measures. No wasted effort.
And importantly: This is the standard organisations get certified against. Auditors assess whether your ISMS meets the requirements defined in ISO 27001.
What ISO 27002 Actually Is
ISO 27002 is something slightly different. It’s a code of practice that explains how security controls can be implemented and it provides detailed guidance on the 93 Annex A controls. Such as:
- 10 – Acceptable Use of Assets
- 16 – Identity Management
- 1 – Screening
- 7 – Remote working
- 2 – Physical Entry
- 10 – Storage Media
- 1 – User Endpoint Devices
- 11 – Data Masking
Where ISO 27001 says: “You must identify and implement controls to manage risk.”
ISO 27002 says: “Here are examples of good ways organisations implement those controls.”
It’s essentially a best-practice playbook. It’s not mandatory and it’s not certifiable. Incredibly useful and certainly worth getting hold of a copy (you can follow this link to buy one from the ISO website).
Why Do People Confuse ISO 27001 and ISO 27002?
I think the confusion exists for three main reasons.
First, the numbers are nearly identical! ISO 27001 and 27002 look like they were named by someone who enjoys watching people suffer 😂 If you’re new to the standards, they sound interchangeable, but they’re not.
Next, they reference the same set of controls. ISO 27001 includes something called Annex A, which lists security controls, and those controls are explained in much greater detail in ISO 27002. So naturally people assume, “If ISO 27002 explains the controls… that must be the standard we follow.”
But as stated previously, ISO 27001 is the requirement, whereas ISO 27002 is the explanation.
Finally (and frustratingly) vendors and consultants often blur the lines! You’ll often hear things like, “Our platform delivers ISO 27002 compliance.” Or “We align with ISO 27002 controls.”
Which sounds impressive and makes the product/service provider sound like they’re giving you a lot… which in a way they are – it’s just MORE THAN YOU ACTUALLY NEED!
Just remember; You cannot be certified to ISO 27002. Only ISO 27001 certification exists, so saying something is aligned to ISO 27002, is like saying they align with the Highway Code! (“Wait?! What? ALL of it? Are you sure you need to do that?!”)
Where Organisations Get This Wrong
Now let’s talk about the real-world implications. Because this confusion often leads to overly complicated and confusing management systems. Let’s deconstruct one example.
ISO27001 Annex A control: A5.1 Policies for Information Security states;
“Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties and reviewed at planned intervals and if significant changes occur.”
There is a lot to unpack in there already (watch the video and read the blog to learn more). Notice the word ‘Shall’ in the first part of the statement.
Now contrast this with what ISO 27002 says about this control. It states that
“At the highest level, the organization should define an “information security policy” which is approved by top management and which sets out the organization’s approach to managing its information security.
The information security policy should take into consideration requirements derived from:
- business strategy and requirements;
- regulations, legislation and contracts;
- the current and projected information security risks and threats.
Information security policy should contain statements concerning:
definition of information security;
- information security objectives or the framework for setting information security objectives;
- principles to guide all activities relating to information security;
- commitment to satisfy applicable requirements related to information security;
- commitment to continual improvement of the information security management system;
- assignment of responsibilities for information security management to defined roles;
- procedures for handling exemptions and exceptions.
- Top management should approve any changes to the information security policy.
At a lower level, the information security policy should be supported by topic-specific policies as needed, to further mandate the implementation of information security controls. Topic-specific policies are typically structured to address the needs of certain target groups within an organization or to cover certain security areas. Topic-specific policies should be aligned with and complementary to the information security policy of the organization.
Examples of such topics include…”
It then goes on to provide a long list of EXAMPLES of policies. Not mandatory policies, but examples of policies that you might select. The word ‘should’ appears 6 times in the section above.
What you need to do
Sometimes organisations implement controls purely because they appear in ISO 27002, without asking the most important question: “Do we actually need this?”
ISO 27001 requires organisations to justify which controls they apply. That’s why the Statement of Applicability exists. It explains which controls you’ve chosen, why they’re necessary and why others aren’t
This ensures security remains proportionate and risk-based (remember that ISO 27001 is a risk based management system – you only implement controls if there is a risk to your business).
What is ISO 27002 good for?
Please don’t mistake this article as a ‘bashing’ of ISO 27002, because that’s not the intention. ISO 27002 is a useful resource and can be most helpful when you’re not sure what you might want to implement as part of a particular control.
You might like to think of it as a ‘toolkit’ that contains all manner of tools and items that might come in helpful. Personally, I suggest that people don’t look at ISO 27002 until they have become certified to ISO 27001. Once you have ‘passed the exam’, you need to think about how you can improve your security controls, and ISO 27002 has a whole lot of ideas to offer.
ISO 27001 isn’t about technology. It’s about leadership and accountability. It’s about governance, risk and continual improvement. ISO 27001 gives you a set of controls, and ISO 27002 gives you ideas on how to implement them. It’s as simple as that.
When discussing ISO standards, I usually ask “Are you trying to impress your clients or pass an audit? If you are then ISO 27001 is for you”
If the company in question already has ISO 27001, I know they’ll need to improve security, and that’s where ISO 27002 can become immensely useful.
But the best organisations do both and Consultants Like Us understand that ISO 27001 provides the framework for managing security properly and ISO 27002 provides guidance for implementing and improving controls effectively.
Together they create a system that is both auditable and practical, and ultimately make you more secure and resilient.
Final Thoughts
One of the biggest myths about ISO standards is that they’re complicated.
They’re not. What they are… is often poorly explained, and when standards aren’t understood properly, organisations either over-engineer their security or treat certification as a box-ticking exercise. Neither outcome improves security.
But when businesses understand the intent behind the standards, something interesting happens. Security stops feeling like a burden and starts becoming a structured, manageable way to build trust.
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon.
If you’d like to talk through any of the points above, please get in touch.
Whether it’s to discuss if ISO 27001 is right for you or to help understand what ISO 42001 could mean for your organisation or to see how both standards fit into your AI and cyber strategy.
