ISO/IEC 27002: The 93 Information Security Controls
What you'll learn
- Implement an effective information security programme
- Determine and apply appropriate security controls
- Achieve compliance with ISO/IEC 27001
- Understand information security best practices
- Manage information security risks
Requirements
- Familiarity with the ISO/IEC 27000 framework is useful, but not mandatory
- An understanding of information security management principles
Description
ISO/IEC 27002 is the international standard that explains the 93 information security controls of ISO/IEC 27001 — what each control means, what it is for, and how it can be implemented. Where ISO/IEC 27001 lists the controls (in its Annex A), ISO/IEC 27002 is the implementation guidance: the reference every ISMS implementer, security officer and auditor works with daily.
This course details all 93 controls, organized by the four themes of the standard.
Course structure
Introduction — the ISO/IEC 27000 family of standards, the position and purpose of ISO/IEC 27002, definitions of information security, cybersecurity and privacy, and what an information security management system (ISMS) consists of
The 37 organizational controls — including information security roles and responsibilities, segregation of duties, threat intelligence, information security in project management, information classification and labelling, access control, information transfer, supplier relationships, ICT continuity, privacy and protection of PII, and documented operating procedures
The 8 people controls — screening, terms and conditions of employment, security awareness and training, the disciplinary process, and remote working
The 14 physical controls — secure areas, physical entry controls, clear desk and clear screen, storage media, supporting utilities, and the secure re-use and disposal of equipment
The 34 technological controls — endpoint devices, data masking, information deletion, backup, cryptography, logging and monitoring, network security, secure development and secure coding, protection of test information, web filtering, secure authentication, access to source code, and privileged utility programs
Certification — how ISO/IEC 27001 certification works for organizations, and the certification paths available to individuals working with ISO/IEC 27001 and 27002
How this course relates to ISO/IEC 27001
ISO/IEC 27001 sets the requirements for an ISMS and is the standard organizations certify against; ISO/IEC 27002 provides the detailed guidance for implementing its controls. If you are implementing an ISMS, preparing for certification, or selecting controls for your Statement of Applicability (SoA), this course gives you the control-by-control understanding that ISO/IEC 27001 itself does not provide.
Who this course is for
ISMS implementers and information security officers selecting and implementing controls
IT and cybersecurity professionals mapping their technical work to ISO/IEC 27001 requirements
Internal auditors and consultants who need to understand what good control implementation looks like
Anyone preparing their organization for ISO/IEC 27001 certification
Who this course is for:
- Information security managers
- ISMS auditors and consultants
- Information security management practitioners and enthusiasts
- Cybersecurity and privacy practitioners
- Those interested in the ISO 27k framework
Instructor
Who am I?
I’ve been working in the field of standards, auditing, and certification since the early 2000s. Over the years, I’ve contributed to hundreds of projects across various industries and disciplines. Today, I work with RIGCERT, an accredited certification body based in Europe.
What do I do?
I translate the knowledge and best practices from international standards and recognized compliance frameworks into clear, practical language — to help individuals and organizations improve.
How do I teach?
I design and record every course myself. You will be learning from a human instructor with real-world auditing experience — not from AI-generated content. Since launching my first course in 2016, my focus has always been on extracting the core ideas from complex subjects and delivering them in a clear, concise format. I only build and publish courses that I myself would take.
What are my interests?
My work spans quality management, information security, data protection and privacy, artificial intelligence governance, risk management, business continuity, occupational health and safety, environmental management, energy management, compliance, food safety, and others.
