Expert Advice Community

Guest

Is ISO 27002 mandatory?

  Quote
Guest
Guest user Created:   Sep 04, 2018 Last commented:   Sep 04, 2018

Is ISO 27002 mandatory?

Does an ISO 27001 certification REQUIRE that you select your controls from ISO 27002, or is this just one of the options? As I see it, the goal of ISO 27001 is to ensure that you select and implement the controls that are needed based on the risks of the assets you want to protect. Period. From which control framework these controls originate (ISO 27002, NIST, BSI, Cobit, etc.) should not matter. So, an ISO 27001 auditor should not force me to use ISO 27002. Is that correct? I've asked two ISO 27001 Lead Auditors, and got two contradicting answers. What do you think? Is there any clear guidance in the ISO standards (which?) that clarifies this issue?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Sep 04, 2018

Answer:

I think there are a couple of thigs that need to be clarified here:

1) The controls from ISO 27001 Annex A and from ISO 27002 are the same; what is different is that ISO 27002 provides detailed guidelines on how to implement controls, and ISO 27001 does not have those guidelines.

2) ISO 27002 is not a mandatory standard if you want to get certified against ISO 27001. Or to be more precise, ISO 27001 does not mention that the control guidelines from ISO 27002 are mandatory. Therefore, the certification auditor cannot ask you to implement particular control in a way that is described in ISO 27002.

3) However, you need to implement each control that you consider is applicable, so unless you have a very good idea on how to implement that control you can use ISO 27002 as a guideline.

See also: ISO 27001 vs. ISO 27002 https://advisera.com/27001academy/knowledgebase/iso-27001-vs-iso-27002/

These materials will also help you regarding ISO 27001 implementation:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 04, 2018

Sep 04, 2018

Suggested Topics