What is the difference between ISO 27001 and ISO 27002?

ISO 27002 is a supporting document that provides guidance on 93 best practice information security controls that can be implemented to help mitigate the risks identified by your ISO 27001 risk assessment.   The ISO/IEC 27002:20022 Standard restructured and rationalised the previous 114 controls, and added a further 11 controls to the structure, reflecting the evolving IS technologies and the emergence of new threats.

In fact, these 93 controls are replicated in Annex A of ISO 27001 and you are required to consider all of them when determining the most appropriate actions to mitigate your risks.

The controls are separated into 4 main themes organisational, people, technological and physical.  The Standard also introduced 5 ‘attributes’, where you can assign hashtags to controls to enable you to filter, sort, or present controls in different ways.  More information can be found here.

We have just received the CE+ certificate and notification that we have passed; we wanted to thank our assessor for all his help with this. It is greatly appreciated. I know that our team is very grateful as they were expecting the process to be difficult. Instead of being difficult, URM’s assessor made it a smooth process and we have all learned a lot
Contact centre software provider
Contact the ISO 27001 Experts Today

Streamlining Asset Identification For Effective Risk Management

Published on
25 Jul
2025

A question which comes up time and time again is ‘How do I approach asset identification within my information security risk assessment’.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
25/7/2025
How do you Categorise Your Assets When Conducting an Information Security Risk Assessment?

‘How do we approach asset identification within our information security risk assessment?’. This blog examines which assets or asset types to include.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
24/7/2025
ISO 27001:2022 - A.5 Organisational Controls (Incident Management)

URM’s blog breaks down the six incident management-related controls in Annex A of ISO 27001, providing key guidance on how to implement each control.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
18/7/2025
ISO 27001:2022 - A.5 Organisational Controls (Business Continuity)

URM’s blog explores the ISO 27001 business continuity controls, why they matter, & how they can be effectively implemented to ensure conformance to the Standard

Read more
"
From beginning to end URM made achieving PCI compliance incredibly easy & worked with us to educate us on the requirements. They were always available for a call whenever we needed to discuss queries along the way & were always flexible to our internal deadlines. We would highly recommend URM from a consultancy & auditing perspective.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.