← Back to Library
ISO 27002

ISO/IEC 27002:2005

Full Name:
International Organization for Standardization (ISO) 27002
Acronym:
ISO 27002:2005
Type:
International Standard
Organization:
International Organization for Standardization
Version:
2005
Year Published:
2005
Popularity:
Low

Overview of ISO/IEC 27002:2005

ISO/IEC 27002:2005, published by the International Organization for Standardization and the International Electrotechnical Commission, represents a landmark standard in information security management, providing a comprehensive code of practice for information security controls. This standard emerged in 2005 as a significant evolution from its predecessor, ISO/IEC 17799:2005, marking the transition of the standard into the ISO/IEC 27000 series and establishing the foundation for modern information security management practices. ISO/IEC 27002:2005 provides detailed guidance on selecting and implementing security controls across 11 key domains, offering organizations a structured approach to establishing comprehensive information security programs.

The 2005 edition established the framework that would become the cornerstone of information security management globally, providing organizations with best-practice recommendations for implementing security controls. Unlike prescriptive regulations, ISO/IEC 27002:2005 offers guidance that organizations can adapt to their specific contexts, risk profiles, and business requirements. The standard recognizes that effective information security requires a balanced approach addressing people, processes, and technology, and provides comprehensive coverage of security domains from security policy through business continuity management.

ISO/IEC 27002:2005 serves as a companion standard to ISO/IEC 27001:2005, which specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2005 provides the detailed control guidance that organizations reference when implementing security controls within their ISMS. The standard has achieved widespread international adoption, becoming one of the most recognized information security frameworks globally and influencing countless other security standards and regulations.

Framework Applicability and Adoption

ISO/IEC 27002:2005 applies to organizations of all sizes and types, across all industries and sectors, providing flexible guidance that can be adapted to diverse organizational contexts. The standard is particularly valuable for organizations seeking to establish comprehensive information security programs, demonstrate security maturity to customers and partners, meet contractual security requirements, and align with international best practices. While ISO/IEC 27002:2005 itself does not provide for certification, organizations implementing the standard often pursue ISO/IEC 27001 certification, which references ISO/IEC 27002 controls.

The standard's adoption accelerated rapidly following its publication, as organizations recognized the value of structured approaches to information security management. Many organizations adopted ISO/IEC 27002:2005 as part of broader ISO/IEC 27001 certification programs, while others implemented the standard's controls independently to improve their security postures. The framework's international recognition made it valuable for organizations operating globally, enabling them to demonstrate security capabilities across diverse markets and regulatory environments.

ISO/IEC 27002:2005 has influenced numerous other security standards and regulations, with many frameworks referencing or aligning with its control structure. The standard's 11-domain structure provided a model that other frameworks adopted or adapted, and its comprehensive coverage of information security topics made it a valuable reference for organizations managing multiple compliance obligations. While superseded by later editions, ISO/IEC 27002:2005 remains historically significant as the foundation for modern information security management practices.

Key Framework Components and Control Domains

ISO/IEC 27002:2005 organizes information security controls into 11 key domains, each addressing specific aspects of information security management. These domains provide comprehensive coverage of information security concerns, from strategic security policy through operational security management and business continuity.

Security Policy

ISO/IEC 27002:2005 requires organizations to establish comprehensive security policies that define management direction and support for information security. Security policy requirements address policy development, policy review, and policy communication, ensuring that security policies are established, maintained, and communicated effectively throughout organizations. Security policies must be approved by management, reviewed regularly, and updated as organizational needs, threats, or technologies change.

The standard recognizes that effective security policies provide the foundation for information security programs, establishing management commitment, defining security objectives, and providing guidance for security decision-making. Security policies must be appropriate for organizational contexts, account for legal and regulatory requirements, and be communicated to all personnel and relevant external parties. Organizations must ensure that security policies are accessible, understood, and followed consistently, and must establish processes for policy review and update.

Organization of Information Security

ISO/IEC 27002:2005 requires organizations to establish management frameworks for information security, including security roles and responsibilities, coordination of security activities, and authorization processes for information processing facilities. Organization of information security requirements address internal organization, external parties, and independent review, ensuring that security responsibilities are clearly defined, security activities are coordinated effectively, and security programs receive appropriate oversight.

The standard requires organizations to establish security management forums, designate security officers, define security roles and responsibilities, and coordinate security activities across organizational units. Organizations must address security in relationships with external parties, establish security requirements for third-party access, and ensure that external party security practices meet organizational requirements. The standard also requires independent review of information security, ensuring that security programs are evaluated objectively and that security effectiveness is assessed regularly.

Asset Management

ISO/IEC 27002:2005 requires organizations to achieve and maintain appropriate protection of organizational assets, including information assets, software assets, physical assets, and services. Asset management requirements address responsibility for assets and information classification, ensuring that assets are identified, classified, and protected according to their value and sensitivity. Organizations must maintain inventories of assets, assign ownership responsibilities, and classify information based on sensitivity and criticality.

The standard requires organizations to establish processes for asset identification, maintain accurate asset inventories, assign asset ownership, and classify information appropriately. Information classification schemes must enable organizations to apply protection measures commensurate with information sensitivity, and must be communicated to personnel who handle information. Asset management processes must address the full asset lifecycle, from acquisition through disposal, ensuring that assets are protected throughout their existence in organizations.

Human Resources Security

ISO/IEC 27002:2005 requires organizations to ensure that personnel understand their security responsibilities and are suitable for the roles they are considered for. Human resources security requirements address security aspects of employment, including prior to employment, during employment, and termination or change of employment. Organizations must conduct security screening for personnel, provide security awareness and training, and manage security aspects of employment changes and terminations.

The standard requires organizations to define security roles and responsibilities in job descriptions, conduct background checks for personnel, ensure that personnel understand security responsibilities, and provide security awareness and training. Organizations must establish processes for managing security during employment changes, including role changes and transfers, and must ensure that access is revoked promptly when employment terminates. Human resources security must be integrated into standard human resources processes, ensuring that security considerations are addressed throughout employment lifecycles.

Physical and Environmental Security

ISO/IEC 27002:2005 requires organizations to prevent unauthorized physical access, damage, and interference to organizational premises and information. Physical and environmental security requirements address secure areas, equipment security, and general controls, ensuring that physical security controls protect information and information processing facilities. Organizations must establish secure areas for information processing, implement physical access controls, and protect equipment from environmental threats.

The standard requires organizations to define security perimeters, implement physical access controls, protect against environmental threats, and secure equipment appropriately. Secure areas must be protected by appropriate physical barriers, access controls, and monitoring, and must be designed to prevent unauthorized access. Equipment security requirements address equipment siting and protection, supporting utilities, cabling security, equipment maintenance, and secure disposal of equipment. Physical security controls must be appropriate for organizational risk levels and must be tested and maintained regularly.

Communications and Operations Management

ISO/IEC 27002:2005 requires organizations to ensure the correct and secure operation of information processing facilities. Communications and operations management requirements address operational procedures and responsibilities, third-party service delivery management, system planning and acceptance, protection against malicious and mobile code, backup, network security management, media handling, exchange of information, electronic commerce services, and monitoring. This domain provides comprehensive coverage of operational security concerns.

The standard requires organizations to establish operational procedures, manage third-party service delivery, plan and accept systems securely, protect against malicious code, implement backup procedures, manage network security, handle media securely, exchange information securely, protect electronic commerce, and monitor systems and networks. Operational security controls must ensure that information processing facilities operate correctly and securely, that operational procedures are documented and followed, and that security events are detected and responded to appropriately.

Access Control

ISO/IEC 27002:2005 requires organizations to control access to information, ensuring that users receive only the access necessary for their job functions. Access control requirements address business requirements for access control, user access management, user responsibilities, and network access control. Organizations must establish access control policies based on business requirements, manage user access throughout access lifecycles, define user responsibilities, and control network access appropriately.

The standard requires organizations to establish access control policies, manage user registration and deregistration, manage privileged access, manage user passwords, review user access rights, and remove or adjust access rights when no longer needed. Access control implementations must enforce least privilege principles, ensure that access is granted based on business needs, and prevent unauthorized access. Network access controls must protect network services, control user authentication for external connections, and control equipment identification and authentication.

Information Systems Acquisition, Development, and Maintenance

ISO/IEC 27002:2005 requires organizations to ensure that security is an integral part of information systems throughout their lifecycles. Information systems acquisition, development, and maintenance requirements address security requirements of information systems, correct processing in applications, cryptographic controls, security of system files, security in development and support processes, and technical vulnerability management. Organizations must address security during system acquisition, development, and maintenance activities.

The standard requires organizations to include security requirements in information system specifications, ensure that applications process information correctly, implement cryptographic controls appropriately, secure system files, manage security in development and support environments, and manage technical vulnerabilities. Security must be addressed throughout system lifecycles, from initial requirements through development, testing, deployment, and maintenance. Organizations must ensure that security controls are designed into systems, that security testing is conducted, and that vulnerabilities are managed effectively.

Information Security Incident Management

ISO/IEC 27002:2005 requires organizations to ensure that information security events and weaknesses associated with information systems are communicated in a manner allowing timely corrective action. Information security incident management requirements address reporting information security events and weaknesses, and management of information security incidents and improvements. Organizations must establish processes for detecting, reporting, and responding to security incidents.

The standard requires organizations to establish incident reporting procedures, ensure that security events are reported promptly, establish incident response capabilities, and learn from security incidents. Incident management processes must enable organizations to detect security incidents, respond to incidents effectively, recover from incidents, and improve security based on incident lessons learned. Organizations must establish incident response teams, define incident response procedures, test incident response capabilities, and conduct post-incident reviews.

Business Continuity Management

ISO/IEC 27002:2005 requires organizations to counteract interruptions to business activities and protect critical business processes from the effects of major failures of information systems or disasters. Business continuity management requirements address information security aspects of business continuity management, ensuring that information security is addressed in business continuity planning. Organizations must develop business continuity plans, test continuity plans, and maintain continuity capabilities.

The standard requires organizations to address information security in business continuity management, develop business continuity plans that include information security requirements, test business continuity plans regularly, and maintain business continuity capabilities. Business continuity planning must address information security requirements, ensure that security controls are maintained during disruptions, and enable organizations to recover information security capabilities following disruptions. Organizations must test business continuity plans, update plans as business needs change, and ensure that personnel understand continuity procedures.

Compliance

ISO/IEC 27002:2005 requires organizations to avoid breaches of any law, statutory, regulatory, or contractual obligations, and of any security requirements. Compliance requirements address compliance with legal requirements, compliance with security policies and standards, and information systems audit considerations. Organizations must identify legal and regulatory requirements, ensure compliance with requirements, and support information systems audits.

The standard requires organizations to identify applicable legal and regulatory requirements, ensure that information processing complies with legal requirements, protect organizational records, ensure privacy of personal information, prevent misuse of information processing facilities, and regulate cryptographic controls. Organizations must ensure compliance with security policies and standards, review compliance regularly, and support information systems audits. Compliance activities must be integrated into standard operations, ensuring that legal and regulatory requirements are met continuously.

Implementation Strategies and Best Practices

Successfully implementing ISO/IEC 27002:2005 requires organizations to understand the standard's guidance, assess current security practices, and implement controls systematically. Organizations should begin by conducting comprehensive gap assessments comparing current security practices against ISO/IEC 27002:2005 requirements, identifying security strengths and weaknesses, and developing implementation plans that address gaps progressively.

Establish Information Security Governance: Organizations must establish governance structures for information security, including security policies, security management forums, and security roles and responsibilities. Governance structures should ensure that information security receives appropriate management attention, that security decisions are made appropriately, and that security programs are managed effectively. Organizations should establish security committees, designate security officers, and ensure that security responsibilities are clearly defined.

Conduct Risk Assessment: ISO/IEC 27002:2005 implementation should be risk-based, with organizations identifying security risks and implementing controls appropriate for their risk levels. Risk assessments should identify threats, vulnerabilities, and potential impacts, enabling organizations to prioritize security control implementation based on risk. Organizations should use risk assessment results to select controls from ISO/IEC 27002:2005, ensuring that controls address identified risks effectively.

Implement Controls Systematically: Organizations should implement ISO/IEC 27002:2005 controls systematically across all 11 domains, ensuring comprehensive security coverage. Implementation should be prioritized based on risk, with high-risk areas receiving early attention. Organizations should ensure that controls are implemented consistently, that controls are documented clearly, and that controls are tested and validated. Implementation should be phased, with early phases focusing on foundational controls and later phases addressing more advanced requirements.

Integrate Security into Business Processes: Information security should be integrated into standard business processes, ensuring that security is considered in all business activities. Organizations should integrate security into system development lifecycles, change management processes, and operational procedures. Security should be addressed throughout business processes, from initial planning through ongoing operations, ensuring that security is not treated as separate activities.

Provide Security Awareness and Training: Organizations must ensure that personnel understand security responsibilities and are trained appropriately. Security awareness and training programs should address security policies, security procedures, and security responsibilities. Training should be provided to all personnel, with specialized training for personnel with specific security roles. Organizations should provide ongoing security awareness, ensuring that security remains a priority and that personnel understand evolving security requirements.

Implement Security Monitoring: Organizations must implement security monitoring capabilities that detect security events and verify compliance. Security monitoring should include continuous monitoring, security event detection, audit logging, and security reporting. Organizations should monitor systems and networks for security events, review audit logs regularly, and use monitoring findings to improve security controls. Security monitoring must be continuous and comprehensive, enabling organizations to detect security incidents promptly.

Conduct Regular Security Reviews: Organizations must conduct regular security reviews to verify that controls remain effective and that requirements continue to be met. Security reviews should include internal audits, management reviews, and independent assessments. Organizations should review security policies, assess control effectiveness, identify security weaknesses, and update security controls as needed. Security reviews must be conducted regularly, ensuring that security programs remain current and effective.

Relationship to Other Frameworks and Standards

ISO/IEC 27002:2005 exists within the broader ISO/IEC 27000 series, with important relationships to other standards that enable comprehensive information security management. Understanding these relationships helps organizations implement information security programs effectively.

ISO/IEC 27002:2005 serves as a companion to ISO/IEC 27001:2005, which specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2005 provides the detailed control guidance that organizations reference when implementing security controls. Organizations implementing ISO/IEC 27001 typically use ISO/IEC 27002:2005 to identify and implement appropriate security controls within their ISMS.

The standard influenced numerous other security frameworks and standards, with many frameworks adopting or adapting its control structure. NIST Cybersecurity Framework and other frameworks reference ISO/IEC 27002:2005 controls, enabling organizations to map controls across frameworks. The standard's comprehensive coverage and international recognition made it valuable for organizations managing multiple compliance obligations, enabling them to implement security controls once while meeting multiple requirements.

ISO/IEC 27002:2005 relates to ISO/IEC 27002:2013, which expanded the standard to 14 control categories. Organizations implementing ISO/IEC 27002:2005 should be aware that the 2013 edition provides updated guidance, and may wish to reference the 2013 edition for current best practices. However, ISO/IEC 27002:2005 remains valid and provides valuable guidance for organizations establishing information security programs.

The standard aligns with other ISO standards including ISO/IEC 27005 (risk management) and ISO/IEC 27003 (ISMS implementation guidance), providing complementary guidance that supports comprehensive information security management. Organizations implementing ISO/IEC 27002:2005 may reference other ISO/IEC 27000 series standards for additional guidance on specific aspects of information security management.

Common Challenges and Solutions

Organizations implementing ISO/IEC 27002:2005 frequently encounter similar challenges related to the comprehensive nature of requirements, resource constraints, and the need to adapt guidance to organizational contexts. Understanding these common challenges helps organizations plan proactively and implement security controls effectively.

Understanding and Adapting Control Guidance: ISO/IEC 27002:2005 provides guidance rather than prescriptive requirements, requiring organizations to understand control intent and adapt controls to their contexts. Organizations may struggle to interpret control guidance, determine which controls apply, and adapt controls appropriately. Solutions include conducting comprehensive gap assessments, engaging security experts, and developing control implementation guidance specific to organizational contexts. Organizations should ensure that controls are adapted appropriately, addressing organizational risks while meeting control objectives.

Implementing Comprehensive Controls Across All Domains: ISO/IEC 27002:2005 includes extensive controls across 11 domains, which can be overwhelming for organizations to implement comprehensively. Organizations may struggle to prioritize implementation, ensure comprehensive coverage, and maintain controls over time. Solutions include developing phased implementation plans, prioritizing based on risk, and implementing controls systematically across domains. Organizations should approach implementation progressively, building toward comprehensive coverage over time.

Integrating Security into Business Processes: Effective information security requires integration into standard business processes, but organizations may struggle to integrate security without disrupting operations. Security integration can be challenging, requiring organizations to modify business processes, train personnel, and maintain security while enabling operations. Solutions include involving business personnel in security design, designing security controls that work within business processes, and providing security training that helps personnel understand security requirements. Organizations should ensure that security is integrated effectively, supporting business operations while providing protection.

Maintaining Security Controls Over Time: ISO/IEC 27002:2005 requires continuous maintenance of security controls, but organizations may struggle to keep controls current as threats evolve, technologies change, and business needs shift. Maintaining controls can be challenging, requiring organizations to review controls regularly, update controls as needed, and ensure that controls remain effective. Solutions include establishing processes for regular control review, integrating control maintenance into standard operations, and ensuring that security remains a priority. Organizations should approach control maintenance as an ongoing activity, ensuring that controls remain current and effective.

Demonstrating Control Effectiveness: Organizations must demonstrate that security controls are implemented effectively and that they provide appropriate protection, but demonstrating effectiveness can be challenging. Control effectiveness demonstration requires organizations to test controls, measure control performance, and provide evidence of control implementation. Solutions include establishing control testing processes, implementing security metrics, and maintaining comprehensive documentation. Organizations should ensure that control effectiveness is demonstrated regularly, enabling management to understand security posture and make informed decisions.

Managing Resource Constraints: Implementing comprehensive security controls requires significant resources, but organizations may have limited budgets, personnel, or expertise. Resource constraints can make comprehensive implementation challenging, requiring organizations to prioritize implementation and leverage resources efficiently. Solutions include prioritizing based on risk, implementing controls progressively, leveraging automation, and engaging external expertise where needed. Organizations should ensure that resources are allocated effectively, focusing on high-priority areas while building toward comprehensive coverage.

Transition to Later Editions

Organizations implementing ISO/IEC 27002:2005 should be aware that the standard was superseded by ISO/IEC 27002:2013, which expanded the framework to 14 control categories and updated control guidance. While ISO/IEC 27002:2005 remains valid and provides valuable guidance, organizations may wish to reference the 2013 edition for updated best practices and additional controls addressing evolving security concerns.

Organizations transitioning from ISO/IEC 27002:2005 to later editions should conduct gap assessments comparing current implementations against new requirements, identify new controls that should be implemented, and update existing controls based on revised guidance. Transition activities should be planned systematically, ensuring that security improvements are implemented while maintaining existing security capabilities. Organizations should communicate transition plans to stakeholders, ensure that personnel understand changes, and maintain security throughout transition activities.

Frequently Asked Questions

What are the 11 control domains in ISO/IEC 27002:2005?

ISO/IEC 27002:2005 organizes information security controls into 11 domains: Security Policy, Organization of Information Security, Asset Management, Human Resources Security, Physical and Environmental Security, Communications and Operations Management, Access Control, Information Systems Acquisition Development and Maintenance, Information Security Incident Management, Business Continuity Management, and Compliance. Each domain addresses specific aspects of information security, providing comprehensive coverage of security concerns from strategic policy through operational security management.

How does ISO/IEC 27002:2005 relate to ISO/IEC 27001:2005?

ISO/IEC 27002:2005 serves as a companion standard to ISO/IEC 27001:2005, which specifies requirements for establishing an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2005 provides detailed control guidance that organizations reference when implementing security controls within their ISMS. Organizations implementing ISO/IEC 27001 typically use ISO/IEC 27002:2005 to identify and implement appropriate security controls.

Is ISO/IEC 27002:2005 still valid?

While ISO/IEC 27002:2005 was superseded by ISO/IEC 27002:2013, which expanded to 14 control categories, the 2005 edition remains historically significant and provides valuable guidance for organizations establishing information security programs. Organizations may reference ISO/IEC 27002:2005 for foundational guidance, though they should also consider the 2013 and 2022 editions for updated best practices. The 2005 edition's 11-domain structure provides a clear framework for understanding information security management.

Do organizations need to implement all ISO/IEC 27002:2005 controls?

ISO/IEC 27002:2005 provides guidance rather than prescriptive requirements, enabling organizations to select and implement controls appropriate for their risk levels and contexts. Organizations should conduct risk assessments to identify which controls are most relevant, prioritize implementation based on risk, and implement controls systematically. Not all controls may be applicable to all organizations, but organizations should document control selections and ensure that selected controls address identified risks effectively.

How does ISO/IEC 27002:2005 differ from ISO/IEC 17799?

ISO/IEC 27002:2005 represents the renaming and renumbering of ISO/IEC 17799:2005, moving the standard into the ISO/IEC 27000 series to align with ISO/IEC 27001. The content remained largely the same, with the 2005 edition maintaining the 11-domain structure and comprehensive control guidance. The transition to the 27000 series provided better alignment with other information security management standards and improved recognition of the standard's relationship to ISO/IEC 27001.

Conclusion

ISO/IEC 27002:2005 provides essential guidance for organizations seeking to establish comprehensive information security programs, offering a structured approach to implementing security controls across 11 key domains. As the foundation for modern information security management practices, ISO/IEC 27002:2005 established the framework that would influence countless other security standards and regulations globally.

Successful ISO/IEC 27002:2005 implementation requires organizations to understand the standard's guidance, conduct risk assessments, and implement controls systematically based on identified risks. Organizations should approach implementation as a continuous improvement process, using ISO/IEC 27002:2005 controls as opportunities to strengthen security postures and build resilience against evolving threats.

By following ISO/IEC 27002:2005 guidance, maintaining comprehensive documentation, and continuously improving security controls, organizations can establish information security programs that effectively protect information assets, support business objectives, and demonstrate security maturity. While superseded by later editions, ISO/IEC 27002:2005 remains historically significant as the standard that established the foundation for modern information security management, providing valuable guidance that continues to inform information security practices globally.