Back to Frameworks

ISO 27002:2022

International
v2022
7 domains
104 controls

Information security, cybersecurity and privacy protection - Information security controls

Verified

ISO 27002:2022 is a compliance framework from International with 7 domains and 104 controls that map to 119 other frameworks. The largest domains are Organizational controls – ISO 27002:2022 (37 controls), Technological controls – ISO 27002:2022 (34 controls), Physical controls – ISO 27002:2022 (14 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Clause 0 – ISO 27002:2022

6 controls

Organizational controls – ISO 27002:2022

37 controls
Controls in the Organizational controls – ISO 27002:2022 domain of ISO 27002:202237 controls
CodeTitle
iso-27002-2022::5.1Policies for information security
iso-27002-2022::5.10Acceptable use of information and other associated assets
iso-27002-2022::5.11Return of assets
iso-27002-2022::5.12Classification of information
iso-27002-2022::5.13Labelling of information
iso-27002-2022::5.14Information transfer
iso-27002-2022::5.15Access control
iso-27002-2022::5.16Identity management
iso-27002-2022::5.17Authentication information
iso-27002-2022::5.18Access rights
iso-27002-2022::5.19Information security in supplier relationships
iso-27002-2022::5.2Information security roles and responsibilities
iso-27002-2022::5.20Addressing information security within supplier agreements
iso-27002-2022::5.21Managing information security in the ICT supply chain
iso-27002-2022::5.22Monitoring, review and change management of supplier services
iso-27002-2022::5.23Information security for use of cloud services
iso-27002-2022::5.24Information security incident management planning and preparation
iso-27002-2022::5.25Assessment and decision on information security events
iso-27002-2022::5.26Response to information security incidents
iso-27002-2022::5.27Learning from information security incidents
iso-27002-2022::5.28Collection of evidence
iso-27002-2022::5.29Information security during disruption
iso-27002-2022::5.3Segregation of duties
iso-27002-2022::5.30ICT readiness for business continuity
iso-27002-2022::5.31Legal, statutory, regulatory and contractual requirements
iso-27002-2022::5.32Intellectual property rights
iso-27002-2022::5.33Protection of records
iso-27002-2022::5.34Privacy and protection of PII
iso-27002-2022::5.35Independent review of information security
iso-27002-2022::5.36Compliance with policies, rules and standards for information security
iso-27002-2022::5.37Documented operating procedures
iso-27002-2022::5.4Management responsibilities
iso-27002-2022::5.5Contact with authorities
iso-27002-2022::5.6Contact with special interest groups
iso-27002-2022::5.7Threat intelligence
iso-27002-2022::5.8Information security in project management
iso-27002-2022::5.9Inventory of information and other associated assets

People controls – ISO 27002:2022

8 controls
Controls in the People controls – ISO 27002:2022 domain of ISO 27002:20228 controls
CodeTitle
iso-27002-2022::6.1Screening
iso-27002-2022::6.2Terms and conditions of employment
iso-27002-2022::6.3Information security awareness, education and training
iso-27002-2022::6.4Disciplinary process
iso-27002-2022::6.5Responsibilities after termination or change of employment
iso-27002-2022::6.6Confidentiality or non-disclosure agreements
iso-27002-2022::6.7Remote working
iso-27002-2022::6.8Information security event reporting

Physical controls – ISO 27002:2022

14 controls
Controls in the Physical controls – ISO 27002:2022 domain of ISO 27002:202214 controls
CodeTitle
iso-27002-2022::7.1Physical security perimeters
iso-27002-2022::7.10Storage media
iso-27002-2022::7.11Supporting utilities
iso-27002-2022::7.12Cabling security
iso-27002-2022::7.13Equipment maintenance
iso-27002-2022::7.14Secure disposal or re-use of equipment
iso-27002-2022::7.2Physical entry
iso-27002-2022::7.3Securing offices, rooms and facilities
iso-27002-2022::7.4Physical security monitoring
iso-27002-2022::7.5Protecting against physical and environmental threats
iso-27002-2022::7.6Working in secure areas
iso-27002-2022::7.7Clear desk and clear screen
iso-27002-2022::7.8Equipment siting and protection
iso-27002-2022::7.9Security of assets off-premises

Structure of this document – ISO 27002:2022

3 controls

Technological controls – ISO 27002:2022

34 controls
Controls in the Technological controls – ISO 27002:2022 domain of ISO 27002:202234 controls
CodeTitle
iso-27002-2022::8.1User endpoint devices
iso-27002-2022::8.10Information deletion
iso-27002-2022::8.11Data masking
iso-27002-2022::8.12Data leakage prevention
iso-27002-2022::8.13Information backup
iso-27002-2022::8.14Redundancy of information processing facilities
iso-27002-2022::8.15Logging
iso-27002-2022::8.16Monitoring activities
iso-27002-2022::8.17Clock synchronization
iso-27002-2022::8.18Use of privileged utility programs
iso-27002-2022::8.19Installation of software on operational systems
iso-27002-2022::8.2Privileged access rights
iso-27002-2022::8.20Networks security
iso-27002-2022::8.21Security of network services
iso-27002-2022::8.22Segregation of networks
iso-27002-2022::8.23Web filtering
iso-27002-2022::8.24Use of cryptography
iso-27002-2022::8.25Secure development life cycle
iso-27002-2022::8.26Application security requirements
iso-27002-2022::8.27Secure system architecture and engineering principles
iso-27002-2022::8.28Secure coding
iso-27002-2022::8.29Security testing in development and acceptance
iso-27002-2022::8.3Information access restriction
iso-27002-2022::8.30Outsourced development
iso-27002-2022::8.31Separation of development, test and production environments
iso-27002-2022::8.32Change management
iso-27002-2022::8.33Test information
iso-27002-2022::8.34Protection of information systems during audit testing
iso-27002-2022::8.4Access to source code
iso-27002-2022::8.5Secure authentication
iso-27002-2022::8.6Capacity management
iso-27002-2022::8.7Protection against malware
iso-27002-2022::8.8Management of technical vulnerabilities
iso-27002-2022::8.9Configuration management

Terms, definitions and abbreviated terms – ISO 27002:2022

2 controls

Your Compliance Coverage

If you comply with ISO 27002:2022, you already cover:

Maps to 119 other frameworks

93 total controls
SOC 2
93 source controls mapped|59 target controls covered
100%
NIST SP 800-53 Rev 5
93 source controls mapped|262 target controls covered
100%
ISO 27001:2022
92 source controls mapped|92 target controls covered
99%
C5 (Germany)
90 source controls mapped|116 target controls covered
97%
FedRAMP High
90 source controls mapped|319 target controls covered
97%
FedRAMP Moderate
90 source controls mapped|318 target controls covered
97%
NIST SP 800-53 Revision 5.1 HIGH
90 source controls mapped|237 target controls covered
97%
NIST SP 800-53 Rev 5 MODERATE
90 source controls mapped|233 target controls covered
97%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
90 source controls mapped|180 target controls covered
97%
NIST Cybersecurity Framework 2.0
88 source controls mapped|103 target controls covered
95%
NIST SP 800-53 Rev 5 LOW
86 source controls mapped|132 target controls covered
92%
PCI DSS 4.0
85 source controls mapped|247 target controls covered
91%
Australian Information Security Manual
81 source controls mapped|235 target controls covered
87%
NIST SP 800-161 Rev 1
77 source controls mapped|96 target controls covered
83%
ISO 27701:2019
75 source controls mapped|96 target controls covered
81%
CIS Controls v8
74 source controls mapped|150 target controls covered
80%
NIST SP 800-171 Rev 3
72 source controls mapped|79 target controls covered
77%
CMMC 2.0
71 source controls mapped|107 target controls covered
76%
HIPAA Security Rule
70 source controls mapped|66 target controls covered
75%
NIST SP 800-66 Rev 2
66 source controls mapped|55 target controls covered
71%
NIS2 Directive
63 source controls mapped|26 target controls covered
68%
Azure Security Benchmark
60 source controls mapped|85 target controls covered
65%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
59 source controls mapped|23 target controls covered
63%
AWS Well-Architected Security Pillar
57 source controls mapped|63 target controls covered
61%
Australia Consumer Data Right - Banking (CDR)
54 source controls mapped|15 target controls covered
58%
DORA
53 source controls mapped|25 target controls covered
57%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
49 source controls mapped|41 target controls covered
53%
NIST SP 800-172
48 source controls mapped|31 target controls covered
52%
ASD Strategies to Mitigate Cyber Security Incidents
36 source controls mapped|37 target controls covered
39%
ISO 22301:2019
32 source controls mapped|51 target controls covered
34%
Australia My Health Records Act 2012
32 source controls mapped|21 target controls covered
34%
ACSC Essential Eight
31 source controls mapped|20 target controls covered
33%
ISO/IEC 42001:2023
29 source controls mapped|32 target controls covered
31%
NIST SP 800-218
29 source controls mapped|42 target controls covered
31%
APRA CPS 230 Operational Risk Management
28 source controls mapped|37 target controls covered
30%
ISO 27018:2019
28 source controls mapped|31 target controls covered
30%
GDPR
27 source controls mapped|12 target controls covered
29%
APRA CPS 234
26 source controls mapped|24 target controls covered
28%
UK Cyber Essentials
21 source controls mapped|31 target controls covered
23%
Authorised Economic Operator (AEO) Programmes - Global Standards
20 source controls mapped|11 target controls covered
22%
ISO/IEC 27011:2024
16 source controls mapped|16 target controls covered
17%
ISO 27018
12 source controls mapped|4 target controls covered
13%
ISO/IEC 27018:2019
12 source controls mapped|4 target controls covered
13%
APPI
12 source controls mapped|16 target controls covered
13%
ISO 19011:2018
11 source controls mapped|13 target controls covered
12%
ISO 27017:2015
6 source controls mapped|5 target controls covered
6%
ISO/IEC 38500:2024
6 source controls mapped|4 target controls covered
6%
ISO/IEC 29100:2024
5 source controls mapped|2 target controls covered
5%
ISO 27043
4 source controls mapped|3 target controls covered
4%
ISO/SAE 21434
4 source controls mapped|3 target controls covered
4%
Annex 11 to EU GMP - Computerised Systems
4 source controls mapped|2 target controls covered
4%
API 1164
4 source controls mapped|4 target controls covered
4%
Australian Energy Sector Cyber Security Framework (AESCSF)
3 source controls mapped|3 target controls covered
3%
NIST SP 800-181
3 source controls mapped|6 target controls covered
3%
EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
3 source controls mapped|2 target controls covered
3%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|2 target controls covered
3%
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
3 source controls mapped|2 target controls covered
3%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
3 source controls mapped|4 target controls covered
3%
3%
PCI SSF
3 source controls mapped|3 target controls covered
3%
ISO 27019
3 source controls mapped|4 target controls covered
3%
NIST SP 800-53A Rev. 5
2 source controls mapped|5 target controls covered
2%
ISO/IEC 27010:2015
2 source controls mapped|2 target controls covered
2%
ISO/IEC 27701:2019
2 source controls mapped|2 target controls covered
2%
SOC 1 (SSAE 18 / ISAE 3402)
2 source controls mapped|3 target controls covered
2%
FFIEC IT Examination Handbook
2 source controls mapped|2 target controls covered
2%
Taiwan PDPA
2 source controls mapped|1 target controls covered
2%
C-TPAT - Customs-Trade Partnership Against Terrorism
2 source controls mapped|1 target controls covered
2%
BRCGS Global Standard for Food Safety Issue 9
2 source controls mapped|1 target controls covered
2%
CISA Industrial Control Systems (ICS) Security Guidance
2 source controls mapped|1 target controls covered
2%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|1 target controls covered
2%
IEC 62443
2 source controls mapped|2 target controls covered
2%
ITIL 4
2 source controls mapped|2 target controls covered
2%
ISO 20000-1
2 source controls mapped|2 target controls covered
2%
NIST SP 1800-32
2 source controls mapped|2 target controls covered
2%
AICPA SOC 3
2 source controls mapped|2 target controls covered
2%
ISO 26262:2018 - Functional Safety for Road Vehicles
2 source controls mapped|2 target controls covered
2%
NY DFS 23 NYCRR 500
2 source controls mapped|2 target controls covered
2%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-207
1 source controls mapped|2 target controls covered
1%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
1%
Equator Principles (EP4, 2020)
1 source controls mapped|1 target controls covered
1%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
1%
ISO/IEC TR 24028:2020
1 source controls mapped|1 target controls covered
1%
ISO 10005:2005
1 source controls mapped|1 target controls covered
1%
EDM Council CDMC - Cloud Data Management Capability Framework
1 source controls mapped|1 target controls covered
1%
SANS Incident Handler's Handbook and PICERL Methodology
1 source controls mapped|1 target controls covered
1%
CMMC 2.0 Level 1
1 source controls mapped|1 target controls covered
1%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|1 target controls covered
1%
Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
1 source controls mapped|1 target controls covered
1%
ISO 55001:2014
1 source controls mapped|1 target controls covered
1%
ISO 45001:2018
1 source controls mapped|2 target controls covered
1%
ISO 55001
1 source controls mapped|1 target controls covered
1%
ISO 45001
1 source controls mapped|1 target controls covered
1%
Botswana Data Protection Act (2024)
1 source controls mapped|1 target controls covered
1%
Bermuda Personal Information Protection Act 2016 (PIPA)
1 source controls mapped|1 target controls covered
1%
CNCF Security Technical Advisory Group (TAG)
1 source controls mapped|1 target controls covered
1%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
1%
ISO 10007:2017
1 source controls mapped|1 target controls covered
1%
NIST SP 800-160
1 source controls mapped|2 target controls covered
1%
FBI CJIS Security Policy
1 source controls mapped|2 target controls covered
1%
NIST SP 800-128
1 source controls mapped|2 target controls covered
1%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
1%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
1%
ASIC Cyber Resilience Good Practices
1 source controls mapped|1 target controls covered
1%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
1 source controls mapped|1 target controls covered
1%
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
1 source controls mapped|1 target controls covered
1%
SSAE 18 - Attestation Standards (SOC Reporting)
1 source controls mapped|1 target controls covered
1%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
1%
Australia NHMRC National Statement on Ethical Conduct in Human Research
1 source controls mapped|1 target controls covered
1%
ISO 19011
1 source controls mapped|2 target controls covered
1%
ISO 31000:2018
1 source controls mapped|2 target controls covered
1%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|2 target controls covered
1%
Digital Services Act (DSA) - Regulation (EU) 2022/2065
1 source controls mapped|1 target controls covered
1%

What is ISO 27002:2022 and who does it apply to?

ISO 27002:2022 is a compliance framework from International with 7 domains and 104 controls. Information security, cybersecurity and privacy protection - Information security controls It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 27002:2022 actually require?

ISO 27002:2022 has 104 controls organised across 7 domains. The largest domains are Organizational controls – ISO 27002:2022 (37 controls), Technological controls – ISO 27002:2022 (34 controls), Physical controls – ISO 27002:2022 (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 27002:2022 do I already cover?

ISO 27002:2022 maps to 119 other compliance frameworks. The top mapping partners are SOC 2 (100% coverage), NIST SP 800-53 Rev 5 (100% coverage), ISO 27001:2022 (99% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO 27002:2022?

Start your ISO 27002:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 27002:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 104 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required