3.2 ISO/IEC 27001 vs ISO/IEC 27002 — The Classic Exam Trap
Key Takeaways
- ISO/IEC 27001 contains mandatory ISMS requirements (Clauses 4–10) plus Annex A control objectives; it is the only certifiable core standard in the family
- ISO/IEC 27002 provides implementation guidance for controls; it is NOT certifiable and its controls are NOT automatically mandatory — an organization selects applicable controls through the Statement of Applicability (SoA) required by 27001 Clause 6.1.3 d)
- The exam distractor "27002 controls are mandatory" is FALSE — only the 27001 Annex A control selection documented in the SoA is mandatory, and the SoA must justify both included and excluded controls
- ISO/IEC 27002:2022 restructured controls into 4 themes (Organizational 37, People 8, Physical 14, Technological 34) — 93 controls total — and ISO/IEC 27001:2022 Annex A was aligned to match; the 2013 14-domain structure (A.5–A.18) is retired
- Both 27001:2022 Annex A and 27002:2022 use the same 4-theme, 93-control structure, so a control referenced in Annex A maps directly to its implementation guidance in 27002
If you take only one distinction from Chapter 3 into the PECB ISO/IEC 27001 Foundation exam, make it this one: ISO/IEC 27001 is requirements; ISO/IEC 27002 is guidance. The exam will test this distinction in at least one form — usually by presenting a statement that confuses which standard is certifiable, which standard's controls are mandatory, or which standard's structure is in force. This section is built to make every one of those traps obvious.
Why This Distinction Matters
ISO/IEC 27001 and ISO/IEC 27002 are deliberately split. 27001 tells you what an Information Security Management System (ISMS) must do; 27002 tells you how you might implement the controls that satisfy the "what." Keeping these separate lets the requirements stay stable and auditable while the implementation guidance can evolve with technology and practice. If the two were merged, every update to control guidance would destabilize the certifiable requirements — and certifications would have to be reissued every time implementation advice changed.
Side-by-Side Comparison
| Dimension | ISO/IEC 27001 | ISO/IEC 27002 |
|---|---|---|
| Document type | Requirements standard | Guidance / code of practice |
| Certifiable? | Yes — the certifiable core of the family | No — not certifiable |
| Structure (2022) | Clauses 4–10 (ISMS requirements) + Annex A (control objectives referencing 93 controls) | 4 themes — Organizational, People, Physical, Technological — containing 93 controls with implementation guidance |
| Mandatory? | Yes — all of Clauses 4–10 are mandatory; Annex A control selection is mandatory via the Statement of Applicability (SoA) | No — controls are guidance; an organization decides which are applicable via its SoA |
| Audited against? | Yes — certification audits use 27001 Clauses 4–10 + Annex A selection as the criteria | No — but auditors may reference 27002 to judge whether an implemented control is adequate |
| Primary audience | Organizations seeking ISMS certification, and certification bodies | Implementers, security managers, control owners |
| Updated in | 2022 (current version) | 2022 (current version) |
The Mandatory-Controls Trap (Most Common on the Exam)
A classic exam distractor reads something like: "Because ISO/IEC 27002 contains the controls, all 27002 controls are mandatory for a certified organization." This is false. The correct chain of obligation is:
- 27001 Clause 6.1.3 d) requires the organization to produce a Statement of Applicability (SoA) that contains the controls chosen from 27001's Annex A, together with justification for including or excluding each one.
- 27001 Annex A lists the control objectives (the 93 controls in the 2022 version) from which the organization selects.
- 27002 provides implementation guidance for each of those 93 controls — it tells you how to implement them in practice.
So the mandatory act is the selection and justification documented in the SoA, not 27002 itself. A control listed in 27002 is mandatory for a given organization only if the organization's SoA has selected it as applicable. An organization can legitimately exclude a 27002 control from its SoA provided the exclusion is justified (e.g., the risk does not apply, no applicable threats, or other controls already cover the risk).
The SoA Is the Bridge
The Statement of Applicability is the document that turns 27002 guidance into 27001 obligation. It must, per 27001 Clause 6.1.3 e) and Annex A, include:
- The controls selected from Annex A (which mirror 27002's 93 controls in the 2022 versions);
- Justification for each inclusion;
- Justification for each exclusion;
- The current status of each selected control (implemented, in progress, planned).
If a control is in the SoA, it is mandatory for that organization. If it is not, it is not — regardless of how prominent it is in 27002.
The 2022 Restructure — A High-Probability Exam Topic
Both 27001:2022 and 27002:2022 were restructured. The exam expects you to know the new structure and to recognize that the old structure is retired.
Old (2013) Structure — Retired
ISO/IEC 27002:2013 (and 27001:2013 Annex A) organized controls into 14 domains (A.5 through A.18) containing 114 controls. Examples of the old domains: A.5 Information security policies, A.6 Organization of information security, A.7 Human resource security, A.8 Asset management, A.9 Access control, … A.18 Compliance. This 14-domain / 114-control structure is no longer in force. Exam distractors that reference "14 domains" or "114 controls" or specific old clauses like "A.9 Access control" are signalling an outdated structure.
New (2022) Structure — Current
ISO/IEC 27002:2022 (and 27001:2022 Annex A) organizes controls into 4 themes containing 93 controls:
| Theme | Number of Controls | Focus |
|---|---|---|
| 5 — Organizational controls | 37 | Policies, roles, asset management, supplier relationships, incident management, compliance |
| 6 — People controls | 8 | Pre-employment, terms of employment, awareness, disciplinary process, secure onboarding/offboarding |
| 7 — Physical controls | 14 | Offices, equipment, secure areas, clear desk/clear screen, physical entry controls |
| 8 — Technological controls | 34 | Access controls, cryptography, network security, secure development, logging, configuration management |
| Total | 93 | — |
(Note: the 93 controls are distributed across themes 5–8; the theme numbers come from the clause numbering in 27002:2022.)
Why the 2022 Change Matters for the Exam
- 27001:2022 Annex A and 27002:2022 now share the same 4-theme, 93-control structure. A control referenced in Annex A maps directly to the same numbered control in 27002. This makes the SoA-to-guidance path seamless.
- The 2013 14-domain structure is retired. Any answer choice that references 14 domains, 114 controls, or the old A.5–A.18 numbering is incorrect for the 2022 versions.
- The themes are not domains. A 2013 "domain" grouped controls by topic (e.g., access control). A 2022 "theme" groups controls by the type of measure (organizational rule, people action, physical barrier, technology). Expect a distractor that calls the 4 themes "domains" — that is wrong terminology.
A Worked Exam Scenario
Scenario: An exam question states: "A certified organization must implement all controls listed in ISO/IEC 27002." True or false?
Answer: False. The organization must produce a Statement of Applicability (per 27001 Clause 6.1.3 d) that selects controls from 27001 Annex A and justifies each inclusion and exclusion. 27002 provides implementation guidance for those controls; it is not a list of uniformly mandatory controls. Only the controls the organization has selected in its SoA are mandatory for that organization.
A Second Worked Scenario
Scenario: A question asks which standard a certification body audits an organization against. The answer choices include 27001, 27002, 27005, and 27006.
Answer: 27001. The audit criteria are 27001 Clauses 4–10 and the Annex A controls selected in the SoA. 27002 may be referenced by the auditor to evaluate the adequacy of implementation, but the certification decision is made against 27001. 27006 is about accrediting the certification body itself, not about the organization being audited.
A Third Worked Scenario (2022 Structure)
Scenario: A question lists four answer choices describing 27002's structure. Which is correct?
- A. 14 domains and 114 controls
- B. 4 themes and 93 controls
- C. 10 clauses and 14 controls
- D. 5 domains and 93 controls
Answer: B — 4 themes (Organizational, People, Physical, Technological) and 93 controls. Choice A describes the retired 2013 structure. Choice D is wrong because the new grouping is called themes, not domains.
Summary of the Trap
- 27001 = requirements, certifiable. Clauses 4–10 mandatory; Annex A control selection mandatory via SoA.
- 27002 = guidance, not certifiable. Controls become mandatory only when the SoA selects them.
- Distractor "27002 controls are mandatory" = false.
- Distractor "27002 is certifiable" = false.
- Distractor "14 domains / 114 controls" = retired 2013 structure. Current 2022 structure: 4 themes, 93 controls.
- The SoA is the bridge that turns 27002 guidance into 27001 obligation.
An exam statement says: "All controls listed in ISO/IEC 27002 are mandatory for any organization certified to ISO/IEC 27001." Why is this statement incorrect?
How are controls structured in ISO/IEC 27002:2022, and how does that structure relate to ISO/IEC 27001:2022 Annex A?
Which document is the formal bridge that makes an ISO/IEC 27002 control mandatory for a specific certified organization?
A certification body audits an organization's ISMS. Which standard provides the audit criteria (the requirements the organization is audited against)?