ISO/IEC 27002
Understand and apply the information security controls that ISO/IEC 27001 draws on.
ISO/IEC 27002: what it is and why it matters
ISO/IEC 27002 is a reference set of information security controls with guidance on purpose, implementation and attributes. It is guidance, not a set of requirements to certify against, which makes it the practical handbook for people who design, operate and review controls.
The 2022 edition groups 93 controls into four themes and adds attributes that help you filter controls by type, security property and cybersecurity concept.
Built for the people who carry the work
- Security architects and control owners
- IT and operations managers who implement controls
- GRC analysts mapping controls to frameworks
- Auditors who need a shared vocabulary of controls
What you will be able to do
- Describe the four control themes and how attributes help to sort controls
- Interpret control guidance and tailor it to your context
- Link controls to risks, policies and evidence
- Map ISO/IEC 27002 controls to other frameworks used in your sector
- Identify gaps between current practice and control intent
Subject outline
- 01
Organisational controls
- 02
People controls
- 03
Physical controls
- 04
Technological controls
- 05
Control attributes and views
- 06
Using the guidance with an ISMS
- 07
Mapping to regulatory and framework requirements
How it supports real work
Writing control descriptions that operations teams can follow
Rationalising overlapping controls from several frameworks into one set
Preparing evidence for control testing
Training, examination and certification are different steps
ISO/IEC 27002 is a guidance standard and has no organisational certification of its own. Personal credentials built around it, where they exist, are issued by third-party bodies under their own rules.
- No organisational certification exists for ISO/IEC 27002 itself.
- Training builds knowledge of the controls. It does not award a credential.
- Ask us which personal credential, if any, applies to your goal.
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Can my organisation be certified to ISO/IEC 27002?
No. Certification is against ISO/IEC 27001. ISO/IEC 27002 is guidance on controls.
How many controls are in the 2022 edition?
93 controls, grouped in four themes.
Is this course only for people using ISO/IEC 27001?
No. The controls are useful for any organisation that wants a structured control set, certified or not.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for ISO/IEC 27002.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


