3.2 ISO/IEC 27001 vs ISO/IEC 27002 — The Classic Exam Trap

Key Takeaways

  • ISO/IEC 27001 contains mandatory ISMS requirements (Clauses 4–10) plus Annex A control objectives; it is the only certifiable core standard in the family
  • ISO/IEC 27002 provides implementation guidance for controls; it is NOT certifiable and its controls are NOT automatically mandatory — an organization selects applicable controls through the Statement of Applicability (SoA) required by 27001 Clause 6.1.3 d)
  • The exam distractor "27002 controls are mandatory" is FALSE — only the 27001 Annex A control selection documented in the SoA is mandatory, and the SoA must justify both included and excluded controls
  • ISO/IEC 27002:2022 restructured controls into 4 themes (Organizational 37, People 8, Physical 14, Technological 34) — 93 controls total — and ISO/IEC 27001:2022 Annex A was aligned to match; the 2013 14-domain structure (A.5–A.18) is retired
  • Both 27001:2022 Annex A and 27002:2022 use the same 4-theme, 93-control structure, so a control referenced in Annex A maps directly to its implementation guidance in 27002
Last updated: July 2026

If you take only one distinction from Chapter 3 into the PECB ISO/IEC 27001 Foundation exam, make it this one: ISO/IEC 27001 is requirements; ISO/IEC 27002 is guidance. The exam will test this distinction in at least one form — usually by presenting a statement that confuses which standard is certifiable, which standard's controls are mandatory, or which standard's structure is in force. This section is built to make every one of those traps obvious.

Why This Distinction Matters

ISO/IEC 27001 and ISO/IEC 27002 are deliberately split. 27001 tells you what an Information Security Management System (ISMS) must do; 27002 tells you how you might implement the controls that satisfy the "what." Keeping these separate lets the requirements stay stable and auditable while the implementation guidance can evolve with technology and practice. If the two were merged, every update to control guidance would destabilize the certifiable requirements — and certifications would have to be reissued every time implementation advice changed.

Side-by-Side Comparison

DimensionISO/IEC 27001ISO/IEC 27002
Document typeRequirements standardGuidance / code of practice
Certifiable?Yes — the certifiable core of the familyNo — not certifiable
Structure (2022)Clauses 4–10 (ISMS requirements) + Annex A (control objectives referencing 93 controls)4 themes — Organizational, People, Physical, Technological — containing 93 controls with implementation guidance
Mandatory?Yes — all of Clauses 4–10 are mandatory; Annex A control selection is mandatory via the Statement of Applicability (SoA)No — controls are guidance; an organization decides which are applicable via its SoA
Audited against?Yes — certification audits use 27001 Clauses 4–10 + Annex A selection as the criteriaNo — but auditors may reference 27002 to judge whether an implemented control is adequate
Primary audienceOrganizations seeking ISMS certification, and certification bodiesImplementers, security managers, control owners
Updated in2022 (current version)2022 (current version)

The Mandatory-Controls Trap (Most Common on the Exam)

A classic exam distractor reads something like: "Because ISO/IEC 27002 contains the controls, all 27002 controls are mandatory for a certified organization." This is false. The correct chain of obligation is:

  1. 27001 Clause 6.1.3 d) requires the organization to produce a Statement of Applicability (SoA) that contains the controls chosen from 27001's Annex A, together with justification for including or excluding each one.
  2. 27001 Annex A lists the control objectives (the 93 controls in the 2022 version) from which the organization selects.
  3. 27002 provides implementation guidance for each of those 93 controls — it tells you how to implement them in practice.

So the mandatory act is the selection and justification documented in the SoA, not 27002 itself. A control listed in 27002 is mandatory for a given organization only if the organization's SoA has selected it as applicable. An organization can legitimately exclude a 27002 control from its SoA provided the exclusion is justified (e.g., the risk does not apply, no applicable threats, or other controls already cover the risk).

The SoA Is the Bridge

The Statement of Applicability is the document that turns 27002 guidance into 27001 obligation. It must, per 27001 Clause 6.1.3 e) and Annex A, include:

  • The controls selected from Annex A (which mirror 27002's 93 controls in the 2022 versions);
  • Justification for each inclusion;
  • Justification for each exclusion;
  • The current status of each selected control (implemented, in progress, planned).

If a control is in the SoA, it is mandatory for that organization. If it is not, it is not — regardless of how prominent it is in 27002.

The 2022 Restructure — A High-Probability Exam Topic

Both 27001:2022 and 27002:2022 were restructured. The exam expects you to know the new structure and to recognize that the old structure is retired.

Old (2013) Structure — Retired

ISO/IEC 27002:2013 (and 27001:2013 Annex A) organized controls into 14 domains (A.5 through A.18) containing 114 controls. Examples of the old domains: A.5 Information security policies, A.6 Organization of information security, A.7 Human resource security, A.8 Asset management, A.9 Access control, … A.18 Compliance. This 14-domain / 114-control structure is no longer in force. Exam distractors that reference "14 domains" or "114 controls" or specific old clauses like "A.9 Access control" are signalling an outdated structure.

New (2022) Structure — Current

ISO/IEC 27002:2022 (and 27001:2022 Annex A) organizes controls into 4 themes containing 93 controls:

ThemeNumber of ControlsFocus
5 — Organizational controls37Policies, roles, asset management, supplier relationships, incident management, compliance
6 — People controls8Pre-employment, terms of employment, awareness, disciplinary process, secure onboarding/offboarding
7 — Physical controls14Offices, equipment, secure areas, clear desk/clear screen, physical entry controls
8 — Technological controls34Access controls, cryptography, network security, secure development, logging, configuration management
Total93

(Note: the 93 controls are distributed across themes 5–8; the theme numbers come from the clause numbering in 27002:2022.)

Why the 2022 Change Matters for the Exam

  1. 27001:2022 Annex A and 27002:2022 now share the same 4-theme, 93-control structure. A control referenced in Annex A maps directly to the same numbered control in 27002. This makes the SoA-to-guidance path seamless.
  2. The 2013 14-domain structure is retired. Any answer choice that references 14 domains, 114 controls, or the old A.5–A.18 numbering is incorrect for the 2022 versions.
  3. The themes are not domains. A 2013 "domain" grouped controls by topic (e.g., access control). A 2022 "theme" groups controls by the type of measure (organizational rule, people action, physical barrier, technology). Expect a distractor that calls the 4 themes "domains" — that is wrong terminology.

A Worked Exam Scenario

Scenario: An exam question states: "A certified organization must implement all controls listed in ISO/IEC 27002." True or false?

Answer: False. The organization must produce a Statement of Applicability (per 27001 Clause 6.1.3 d) that selects controls from 27001 Annex A and justifies each inclusion and exclusion. 27002 provides implementation guidance for those controls; it is not a list of uniformly mandatory controls. Only the controls the organization has selected in its SoA are mandatory for that organization.

A Second Worked Scenario

Scenario: A question asks which standard a certification body audits an organization against. The answer choices include 27001, 27002, 27005, and 27006.

Answer: 27001. The audit criteria are 27001 Clauses 4–10 and the Annex A controls selected in the SoA. 27002 may be referenced by the auditor to evaluate the adequacy of implementation, but the certification decision is made against 27001. 27006 is about accrediting the certification body itself, not about the organization being audited.

A Third Worked Scenario (2022 Structure)

Scenario: A question lists four answer choices describing 27002's structure. Which is correct?

  • A. 14 domains and 114 controls
  • B. 4 themes and 93 controls
  • C. 10 clauses and 14 controls
  • D. 5 domains and 93 controls

Answer: B — 4 themes (Organizational, People, Physical, Technological) and 93 controls. Choice A describes the retired 2013 structure. Choice D is wrong because the new grouping is called themes, not domains.

Summary of the Trap

  • 27001 = requirements, certifiable. Clauses 4–10 mandatory; Annex A control selection mandatory via SoA.
  • 27002 = guidance, not certifiable. Controls become mandatory only when the SoA selects them.
  • Distractor "27002 controls are mandatory" = false.
  • Distractor "27002 is certifiable" = false.
  • Distractor "14 domains / 114 controls" = retired 2013 structure. Current 2022 structure: 4 themes, 93 controls.
  • The SoA is the bridge that turns 27002 guidance into 27001 obligation.
Test Your Knowledge

An exam statement says: "All controls listed in ISO/IEC 27002 are mandatory for any organization certified to ISO/IEC 27001." Why is this statement incorrect?

A
B
C
D
Test Your Knowledge

How are controls structured in ISO/IEC 27002:2022, and how does that structure relate to ISO/IEC 27001:2022 Annex A?

A
B
C
D
Test Your Knowledge

Which document is the formal bridge that makes an ISO/IEC 27002 control mandatory for a specific certified organization?

A
B
C
D
Test Your Knowledge

A certification body audits an organization's ISMS. Which standard provides the audit criteria (the requirements the organization is audited against)?

A
B
C
D