Back to Frameworks

ISO 27002:2022

International
v2022
4 domains
93 controls

Information security, cybersecurity and privacy protection - Information security controls

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

A.5 Organizational Controls

37 controls
Controls in the A.5 Organizational Controls domain of ISO 27002:202237 controls
CodeTitle
ISO27002-5.1Policies for information security
ISO27002-5.10Acceptable use of information and other associated assets
ISO27002-5.11Return of assets
ISO27002-5.12Classification of information
ISO27002-5.13Labelling of information
ISO27002-5.14Information transfer
ISO27002-5.15Access control
ISO27002-5.16Identity management
ISO27002-5.17Authentication information
ISO27002-5.18Access rights
ISO27002-5.19Information security in supplier relationships
ISO27002-5.2Information security roles and responsibilities
ISO27002-5.20Addressing information security within supplier agreements
ISO27002-5.21Managing information security in the ICT supply chain
ISO27002-5.22Monitoring, review and change management of supplier services
ISO27002-5.23Information security for use of cloud services
ISO27002-5.24Information security incident management planning and preparation
ISO27002-5.25Assessment and decision on information security events
ISO27002-5.26Response to information security incidents
ISO27002-5.27Learning from information security incidents
ISO27002-5.28Collection of evidence
ISO27002-5.29Information security during disruption
ISO27002-5.3Segregation of duties
ISO27002-5.30ICT readiness for business continuity
ISO27002-5.31Legal, statutory, regulatory and contractual requirements
ISO27002-5.32Intellectual property rights
ISO27002-5.33Protection of records
ISO27002-5.34Privacy and protection of PII
ISO27002-5.35Independent review of information security
ISO27002-5.36Compliance with policies, rules and standards for information security
ISO27002-5.37Documented operating procedures
ISO27002-5.4Management responsibilities
ISO27002-5.5Contact with authorities
ISO27002-5.6Contact with special interest groups
ISO27002-5.7Threat intelligence
ISO27002-5.8Information security in project management
ISO27002-5.9Inventory of information and other associated assets

A.6 People Controls

8 controls
Controls in the A.6 People Controls domain of ISO 27002:20228 controls
CodeTitle
ISO27002-6.1Screening
ISO27002-6.2Terms and conditions of employment
ISO27002-6.3Information security awareness, education and training
ISO27002-6.4Disciplinary process
ISO27002-6.5Responsibilities after termination or change of employment
ISO27002-6.6Confidentiality or non-disclosure agreements
ISO27002-6.7Remote working
ISO27002-6.8Information security event reporting

A.7 Physical Controls

14 controls
Controls in the A.7 Physical Controls domain of ISO 27002:202214 controls
CodeTitle
ISO27002-7.1Physical security perimeters
ISO27002-7.10Storage media
ISO27002-7.11Supporting utilities
ISO27002-7.12Cabling security
ISO27002-7.13Equipment maintenance
ISO27002-7.14Secure disposal or re-use of equipment
ISO27002-7.2Physical entry
ISO27002-7.3Securing offices, rooms and facilities
ISO27002-7.4Physical security monitoring
ISO27002-7.5Protecting against physical and environmental threats
ISO27002-7.6Working in secure areas
ISO27002-7.7Clear desk and clear screen
ISO27002-7.8Equipment siting and protection
ISO27002-7.9Security of assets off-premises

A.8 Technological Controls

34 controls
Controls in the A.8 Technological Controls domain of ISO 27002:202234 controls
CodeTitle
ISO27002-8.1User end point devices
ISO27002-8.10Information deletion
ISO27002-8.11Data masking
ISO27002-8.12Data leakage prevention
ISO27002-8.13Information backup
ISO27002-8.14Redundancy of information processing facilities
ISO27002-8.15Logging
ISO27002-8.16Monitoring activities
ISO27002-8.17Clock synchronization
ISO27002-8.18Use of privileged utility programs
ISO27002-8.19Installation of software on operational systems
ISO27002-8.2Privileged access rights
ISO27002-8.20Networks security
ISO27002-8.21Security of network services
ISO27002-8.22Segregation of networks
ISO27002-8.23Web filtering
ISO27002-8.24Use of cryptography
ISO27002-8.25Secure development life cycle
ISO27002-8.26Application security requirements
ISO27002-8.27Secure system architecture and engineering principles
ISO27002-8.28Secure coding
ISO27002-8.29Security testing in development and acceptance
ISO27002-8.3Information access restriction
ISO27002-8.30Outsourced development
ISO27002-8.31Separation of development, test and production environments
ISO27002-8.32Change management
ISO27002-8.33Test information
ISO27002-8.34Protection of information systems during audit testing
ISO27002-8.4Access to source code
ISO27002-8.5Secure authentication
ISO27002-8.6Capacity management
ISO27002-8.7Protection against malware
ISO27002-8.8Management of technical vulnerabilities
ISO27002-8.9Configuration management

Frequently Asked Questions

What is ISO 27002:2022?

ISO 27002:2022 is a compliance framework from International with 4 domains and 93 controls. Information security, cybersecurity and privacy protection - Information security controls It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISO 27002:2022 have?

ISO 27002:2022 has 93 controls organised across 4 domains. The largest domains are A.5 Organizational Controls (37 controls), A.8 Technological Controls (34 controls), A.7 Physical Controls (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISO 27002:2022 map to?

ISO 27002:2022 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with ISO 27002:2022 compliance?

Start your ISO 27002:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 27002:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 93 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required