ISO/IEC 27002 Information Security Controls

The international standard ISO/IEC 27002 offers instructions for choosing and implementing information security controls as well as for putting information security principles and practices into practice. It is applicable to businesses of all sizes and sectors. Information security management standards can be created using ISO/IEC 27002 and customized for each organization's unique situation.

 

ISO/IEC 27002 was first released in 2005 and then updated in 2013, which was followed by a new revision and publication in 2022. A list of information security measures that are frequently used in the information security sector is provided in this updated version, along with instructions for how to put them into practice. Four types of information security controls are provided by ISO/IEC 27002: organizational, human resources, physical, and technology.

Related Courses