The Relationship Between ISO 27001 and 27002
Published: Jul 12, 2023
Last Updated: Oct 23, 2023
So what's the relationship between ISO 27001 and ISO 27002?
They're often used interchangeably, which can lead to confusion about their intended uses. In the video above, I provide a high-level overview of the differences and relationships between these two standards.
What is ISO 27001?
ISO 27001 is a management system standard, which provides the requirements for establishing, implementing, maintaining, and continually improving what's referred to as an information security management system or an ISMS.
Now, what's an ISMS you might ask? It's a collection of people processes and technologies with the purpose of managing information security risk within an organization.
What is ISO 27002?
ISO 27001 is the standard that you get certified against. So where does that leave ISO 27002? Well, the intent of this standard is to be used as a reference for determining and implementing the controls to address and mitigate risks identified during your ISMS risk assessment process.
They are contained within annex A of ISO 27001, and will often comprise what's referred to as your statement of applicability or SOA, which is a tool utilized during a risk treatment or risk mitigation process based on their applicability to your unique environment and scope and the results of your risk assessment process.
You cannot get certified against ISO 27002. That is because it is guidance, not requirements like 27001. There are a lot of tools and supplemental information that facilitate key ISMS activities like the selection and implementation of controls and the overall risk mitigation activities.
In Summary
To sum up everything:
- ISO 27001 is a management system standard, which you are certified against.
- ISO 27002 are the controls and contain guidance, tools, and additional insights to assist you in your risk management process.
About Danny Manimbo
Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).