International

ISO 27002:2022

96 controls. 124 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

96 controls 124 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO/IEC 27002:2022 Information Security Controls Evidence & Implementation Kit

96 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
4.1Clauses0
4.2Themes and attributes0
4.3Control layout0
5.1Policies for information security43
5.10Acceptable use of information and other associated assets28
5.11Return of assets22
5.12Classification of information31
5.13Labelling of information22
5.14Information transfer41
5.15Access control35
5.16Identity management34
5.17Authentication information32
5.18Access rights34
5.19Information security in supplier relationships42
5.2Information security roles and responsibilities43
5.20Addressing information security within supplier agreements35
5.21Managing information security in the ICT supply chain35
5.22Monitoring, review and change management of supplier services33
5.23Information security for use of cloud services34
5.24Information security incident management planning and preparation45
5.25Assessment and decision on information security events37
5.26Response to information security incidents45
5.27Learning from information security incidents35
5.28Collection of evidence29
5.29Information security during disruption31
5.3Segregation of duties29
5.30ICT readiness for business continuity35
5.31Legal, statutory, regulatory and contractual requirements34
5.32Intellectual property rights11
5.33Protection of records38
5.34Privacy and protection of PII27
5.35Independent review of information security48
5.36Compliance with policies, rules and standards for information security38
5.37Documented operating procedures31
5.4Management responsibilities30
5.5Contact with authorities42
5.6Contact with special interest groups26
5.7Threat intelligence35
5.8Information security in project management26
5.9Inventory of information and other associated assets41
6.1Screening29
6.2Terms and conditions of employment26
6.3Information security awareness, education and training46
6.4Disciplinary process17
6.5Responsibilities after termination or change of employment22
6.6Confidentiality or non-disclosure agreements28
6.7Remote working27
6.8Information security event reporting36
7.1Physical security perimeters32
7.10Storage media28
7.11Supporting utilities17
7.12Cabling security15
7.13Equipment maintenance22
7.14Secure disposal or re-use of equipment32
7.2Physical entry27
7.3Securing offices, rooms and facilities21
7.4Physical security monitoring27
7.5Protecting against physical and environmental threats18
7.6Working in secure areas18
7.7Clear desk and clear screen20
7.8Equipment siting and protection22
7.9Security of assets off-premises27
8.1User endpoint devices31
8.10Information deletion31
8.11Data masking17
8.12Data leakage prevention28
8.13Information backup36
8.14Redundancy of information processing facilities22
8.15Logging43
8.16Monitoring activities47
8.17Clock synchronization17
8.18Use of privileged utility programs27
8.19Installation of software on operational systems32
8.2Privileged access rights34
8.20Networks security34
8.21Security of network services29
8.22Segregation of networks36
8.23Web filtering23
8.24Use of cryptography39
8.25Secure development life cycle30
8.26Application security requirements30
8.27Secure system architecture and engineering principles30
8.28Secure coding26
8.29Security testing in development and acceptance29
8.3Information access restriction34
8.30Outsourced development23
8.31Separation of development, test and production environments25
8.32Change management49
8.33Test information17
8.34Protection of information systems during audit testing21
8.4Access to source code19
8.5Secure authentication39
8.6Capacity management23
8.7Protection against malware33
8.8Management of technical vulnerabilities42
8.9Configuration management55

Tell me when ISO 27002:2022 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO 27002:2022, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition