The ISO/IEC 27002 standard is part of a family of international standards (ISO 27000) for the management of information security. It includes the best industry practices to protect the availability, integrity and confidentiality of information. A risk assessment is initially necessary to identify priority controls to be implemented within a company in order to improve the information’s security level.

The ISO/IEC 27002 is an international standard used as a reference for selecting and implementing information security controls. In addition, it guides on the information security best practices that help organizations in selecting, implementing, and managing information security controls such as organizational, people, physical, and technological controls, among others.

ISO/IEC 27002:2013 gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization’s information security risk environment(s).

ISO/IEC 27002 applies to all types and sizes of organizations, including public and private sectors, commercial and non-profit that collect, process, store and transmit information in many forms including electronic, physical and verbal.

Key clauses of ISO/IEC 27002:2013

ISO/IEC 27002 is organized into the following main clauses:

The standard contains 14 security control clauses, collectively containing a total of 35 main security categories and 114 controls.

Clause 5: Information Security Policies

Clause 6: Organization of Information Security

Clause 7: Human Resource Security

Clause 8: Asset Management

Clause 9: Access Control

Clause 10: Cryptography

Clause 11: Physical and Environmental Security

Clause 12: Operations Security

Clause 13: Communication Security

Clause 14: System Acquisition, Development and Maintenance

Clause 15: Supplier Relationships

Clause 16: Information Security Incident Management

Clause 17: Information Security Aspects of Business Continuity Management

 

Benefits of ISO/IEC 27002 

By implementing information security controls found in ISO 27002, organisations can rest assured that their information assets are protected by internationally recognized and approved standards. Organisations of all sizes and levels of security maturity can reap the following benefits from adherence to the ISO 27002 code of practice:

  • It provides a working framework for the resolution of information security issues.
  • Clients and business partners will be more confident and have a positive perception of an organisation that implements the recommended standards and controls.
  • Since the policies and procedures provided are in line with internationally recognized requirements, cooperation with foreign partners is made easier.
  • Compliance with the ISO 27002 standard helps in the development of an organisation’s best practices which will increase the overall productivity.
  • It provides a defined implementation, management, maintenance and evaluation of information security management systems.
  • An ISO-compliant organisation will have an advantage in contract negotiations and participation in global business opportunities.