# ISO/IEC 27002

**What is ISO/IEC 27002?**

ISO/IEC 27002:2022 is the catalogue of security measures. It describes 93 individual controls, meaning concrete measures, and explains for each what is meant by it and what to watch when implementing it.

The distinction from ISO/IEC 27001 is simple. The 27001 describes the management system and is the standard you certify against. The 27002 provides the guidance on the measures themselves. You certify to 27001 and look things up in 27002.

The 93 controls are grouped into four themes: organisational, people, physical and technological measures. They cover points such as access control, handling of vulnerabilities, backup of data, cryptography, supply chain security and staff training.

For businesses that do not want to certify, the 27002 is still useful. It is a vetted list of what has to be thought about. We use it as our testing basis and map the requirements of the NISG 2026 to the related controls.

## Related terms
- [ISO/IEC 27001](https://vetosec.at/en/it-security/iso-27001/)
- [NIS2](https://vetosec.at/en/it-security/nis2/)
- [Gap analysis](https://vetosec.at/en/it-security/gap-analyse/)
- [Technical and organisational measures (TOMs)](https://vetosec.at/en/it-security/tom-dsgvo/)

## Source
https://vetosec.at/en/it-security/iso-27002/ (vetosec, recht)
