Law and standards
ISO/IEC 27002
What is ISO/IEC 27002?
ISO/IEC 27002:2022 is the catalogue of security measures. It describes 93 individual controls, meaning concrete measures, and explains for each what is meant by it and what to watch when implementing it.
The distinction from ISO/IEC 27001 is simple. The 27001 describes the management system and is the standard you certify against. The 27002 provides the guidance on the measures themselves. You certify to 27001 and look things up in 27002.
The 93 controls are grouped into four themes: organisational, people, physical and technological measures. They cover points such as access control, handling of vulnerabilities, backup of data, cryptography, supply chain security and staff training.
For businesses that do not want to certify, the 27002 is still useful. It is a vetted list of what has to be thought about. We use it as our testing basis and map the requirements of the NISG 2026 to the related controls.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.