Preparing for ISO/IEC 27001 certification can be a challenging undertaking. Organizations often plan to use ISO/IEC 27002 for guidance because it provides detailed information about information security controls. While ISO/IEC 27002 is undoubtedly a valuable reference, relying on it as the primary blueprint for designing and implementing an Information Security Management System (ISMS) can create unnecessary complexity.
The key is to understand the different roles of ISO/IEC 27001 and ISO/IEC 27002—and, more importantly, to understand what ISO/IEC 27002 does not tell you.
For organizations new to ISO/IEC 27001, our complete ISO 27001 guide provides an overview of the standard, its requirements, and the certification process.
ISO/IEC 27001 vs. ISO/IEC 27002: What Is the Difference? #
One of the most important distinctions to understand is that ISO/IEC 27001 is the standard an organization certifies against, while ISO/IEC 27002 is a guidance document for implementing information security controls.
ISO/IEC 27001 defines the requirements for establishing, implementing, maintaining, and continually improving an ISMS. It is the standard against which an organization’s ISMS is audited and certified.
ISO/IEC 27002, on the other hand, provides guidance and implementation recommendations for information security controls. It can help organizations understand different ways controls can be implemented, but it is not itself a certification standard.
For a detailed explanation of their relationship, see What Are ISO/IEC 27001:2022 and ISO/IEC 27002:2022? Purpose, Relationship, and How to Use Them Together.
This distinction is critical because organizations sometimes approach ISO/IEC 27002 as though it were a checklist of everything they must implement to achieve certification. It isn’t.
The Problem With Treating ISO/IEC 27002 as an Implementation Checklist #
In our experience, one of the most common mistakes organizations make is attempting to design their entire security control framework directly from ISO/IEC 27002.
At first, this seems logical. ISO/IEC 27002 provides extensive guidance on information security controls, including recommendations and considerations for implementing them.
For example, a large financial institution, a healthcare provider, a SaaS company, and a small professional-services organization can have dramatically different:
- Business risks
- Information assets
- Technology environments
- Regulatory obligations
- Threat profiles
- Organizational structures
- Available resources
A control implementation that makes sense for a multinational financial institution may be excessive or impractical for a small SaaS company.
Therefore, simply working through the guidance in ISO/IEC 27002 can lead organizations to ask:
“Which of these recommendations do we actually need to implement?”
That is the question the organization needs to answer through its risk assessment and ISMS context, rather than simply adopting every possible recommendation.
More Controls Do Not Necessarily Mean Better Security #
Another common misconception is that implementing more controls will make an organization more secure and improve its chances of passing certification.
In reality, an effective ISMS is not about implementing the largest possible number of controls. It is about implementing appropriate controls that effectively address identified risks.
The goal should be to achieve an appropriate level of risk reduction while using resources efficiently.
Organizations should therefore consider:
- What are our most significant information security risks?
- What assets and information require protection?
- What threats and vulnerabilities are relevant to our environment?
- What legal, regulatory, contractual, and business requirements apply?
- Which controls are necessary to address those risks?
- How should those controls be designed and implemented in our specific environment?
- How will we demonstrate that the controls are operating effectively?
This risk-based approach is much more effective than attempting to implement every recommendation that appears relevant in ISO/IEC 27002.
ISO/IEC 27002 Can Create an “Implementation Maze” #
For organizations without substantial compliance experience, the breadth of ISO/IEC 27002 can actually make implementation more difficult.
There can be multiple reasonable approaches to addressing a particular security objective. The organization must determine which approach is appropriate for its circumstances.
Without sufficient expertise, teams can easily spend significant amounts of time debating implementation details:
- Should we implement this particular technical control?
- Do we need this process?
- How much documentation is necessary?
- What technology should we purchase?
- Do we need another policy?
- What will the auditor expect?
- Is this control mandatory?
- Do we need to implement every recommendation?
These questions can lead to unnecessary work, additional technology costs, and significant delays.
More importantly, organizations can lose sight of the fundamental objective of an ISMS: managing information security risks in a systematic and effective way.
What Should Organizations Do Instead? #
Our recommendation is to use ISO/IEC 27002 as a reference and source of implementation guidance—not as the primary blueprint for building the ISMS.
A more effective approach is to start with the organization’s business context, risks, requirements, and objectives.
Organizations looking for practical guidance can also review How to Design and Implement an ISO 27001 ISMS, which provides a more structured approach to building an ISMS.
Step 1 Understand the Organization’s Context #
Before selecting controls, determine what the ISMS needs to protect and why.
Consider the organization’s:
- Business activities
- Information assets
- Technology environment
- Customers and stakeholders
- Regulatory requirements
- Contractual obligations
- Threat environment
- Existing security capabilities
This provides the foundation for determining what controls are actually necessary.
Step 2 Conduct a Meaningful Risk Assessment #
Controls should be driven by risk.
The organization should identify its significant information security risks and determine how those risks should be treated.
This provides a rational basis for deciding which controls are necessary, rather than selecting controls simply because they appear in a guidance document.
Step 3 Design Controls for the Organization #
Once the risks are understood, controls should be designed around the organization’s actual environment.
This is where industry best practices become particularly valuable.
Instead of asking:
“What does ISO/IEC 27002 tell us to implement?”
a better question is:
“What is the most effective and practical way for our organization to address this risk and satisfy the applicable ISO/IEC 27001 requirements?”
That shift in perspective can significantly reduce unnecessary effort.
Step 4 Build an ISMS That Can Actually Be Operated #
An ISMS should not be designed simply to pass an audit.
It needs to be practical enough for employees and management to operate on an ongoing basis.
A control that looks excellent on paper but is consistently ignored by employees is unlikely to provide meaningful security benefits.
The best ISMS controls are those that are:
- Risk-based
- Appropriate to the organization
- Practical to operate
- Clearly defined
- Measurable
- Supported by evidence
- Sustainable over time
For a more detailed discussion of the implementation journey, see How Do You Design and Implement an ISO 27001 ISMS? The Definitive Guide for 2025–2026.
Why IT Alone Should Not Be Responsible for ISMS Implementation #
Another important consideration is the distinction between information technology and compliance.
IT teams are essential to implementing technical security measures. However, an ISO/IEC 27001 ISMS is much broader than technology.
An effective ISMS involves:
- Governance
- Risk management
- Policies and procedures
- Roles and responsibilities
- Legal and regulatory requirements
- Security controls
- Internal audits
- Management review
- Continual improvement
- Documentation and evidence
- Organizational accountability
These areas require a combination of security, compliance, risk-management, and auditing expertise.
As a result, organizations should strongly consider involving an experienced internal or external compliance professional when designing and implementing their ISMS.
The role of IT should be to provide the technical expertise necessary to implement and operate security controls—not to independently determine the organization’s entire compliance strategy.
The Value of an Experienced ISMS Expert #
An experienced ISMS and compliance professional can help translate the requirements of ISO/IEC 27001 into a practical program tailored to the organization.
Rather than simply asking an organization to implement everything described in ISO/IEC 27002, an experienced advisor can help determine:
This can save substantial time and resources while reducing the risk of over-engineering the security program.
It can also help management and IT teams focus their resources on controls that provide meaningful risk reduction.
Preparing for Certification: Focus on What Matters #
The ultimate objective should not be to create the largest possible collection of policies, procedures, and security controls.
The objective is to establish an effective, risk-based ISMS that meets the requirements of ISO/IEC 27001 and can be demonstrated to an independent certification auditor.
ISO/IEC 27002 can be an excellent source of ideas and implementation guidance. But organizations should avoid treating it as a prescriptive checklist.
The most effective approach is to combine:
This approach allows organizations to build an ISMS that is both certifiable and practical.
For organizations ready to move from planning to certification, our complete guide to ISO 27001 certification provides additional guidance on the certification process and key implementation considerations.
Final Advice #
If your organization is preparing for ISO/IEC 27001 certification, don’t start by asking:
“How do we implement ISO/IEC 27002?”
Start by asking:
“What information security risks do we need to manage, what does ISO/IEC 27001 require, and what controls are appropriate for our organization?”
ISO/IEC 27002 can then be used as a valuable reference to help determine how those controls can be implemented.
The difference may seem subtle, but it can have a significant impact on the cost, complexity, and effectiveness of your ISMS certification journey.
Frequently Asked Questions #
1. What is the main difference between ISO/IEC 27001 and ISO/IEC 27002? #
ISO/IEC 27001 is the formal standard containing requirements that an organization establishes, implements, and certifies against for its Information Security Management System (ISMS). In contrast, ISO/IEC 27002 is a reference and guidance document providing recommendations for implementing information security controls, and it is not a certification standard itself.
2. Why shouldn’t organizations use ISO/IEC 27002 as an implementation checklist? #
Treating ISO/IEC 27002 as an exhaustive checklist can create unnecessary complexity because it does not dictate which specific security measures are required for a particular organization’s unique context, risks, and environment.
3. Does implementing more security controls mean better security? #
No. An effective ISMS is not about maximizing the total number of controls, but rather about selecting and implementing appropriate controls that efficiently and effectively address identified information security risks.
4. How should an organization determine which security controls to implement? #
Controls should be determined through a structured risk assessment and an understanding of the organization’s specific business context, information assets, threat profile, regulatory obligations, and operational capabilities.
5. Why should IT not be solely responsible for ISMS implementation? #
An ISMS encompasses much more than just technical security measures; it involves broader organizational areas such as governance, risk management, policies, legal compliance, internal audits, and continual improvement, which require cross-functional expertise.
6. How should ISO/IEC 27002 be used during the ISO 27001 certification journey? #
ISO/IEC 27002 should be utilized as a valuable reference and source of implementation guidance for how to design specific controls, rather than serving as the primary blueprint or starting point for building your ISMS.