ISO/IEC 27002:2013
Overview of ISO/IEC 27002:2013
ISO/IEC 27002:2013, published by the International Organization for Standardization and the International Electrotechnical Commission, represents a significant evolution of the information security control framework, expanding from 11 control domains in the 2005 edition to 14 control categories that better reflect the evolving information security landscape. This 2013 revision introduced major structural changes, reorganizing controls into a more logical structure, adding dedicated categories for supplier relationships and cryptography, and updating guidance to address emerging technologies including cloud computing, mobile devices, and virtualization.
The 2013 edition maintained ISO/IEC 27002's role as a code of practice for information security controls, providing detailed guidance that organizations can reference when implementing security controls within their Information Security Management Systems (ISMS). The expansion to 14 control categories reflected the growing complexity of information security management, recognizing that organizations needed more granular guidance for specific security concerns. The 2013 edition also improved alignment with ISO/IEC 27001:2013, ensuring that control guidance supported the updated ISMS requirements.
ISO/IEC 27002:2013 addressed several key trends in information security, including increased reliance on third-party suppliers, growing adoption of cloud computing services, proliferation of mobile devices, and the need for stronger cryptographic controls. The standard recognized that modern information security programs must address these evolving concerns while maintaining foundational security principles. The 2013 edition's expanded structure provided organizations with clearer guidance for implementing controls across diverse technology environments and business models.
The standard achieved widespread international adoption, becoming the most current version of ISO/IEC 27002 for nearly a decade until the 2022 edition. Organizations implementing ISO/IEC 27001:2013 certification programs typically referenced ISO/IEC 27002:2013 for control guidance, making the 2013 edition essential for organizations pursuing ISMS certification. The framework's international recognition and comprehensive coverage made it valuable for organizations operating globally, enabling them to demonstrate security capabilities across diverse markets and regulatory environments.
Framework Applicability and Adoption
ISO/IEC 27002:2013 applies to organizations of all sizes and types, across all industries and sectors, providing flexible guidance that can be adapted to diverse organizational contexts. The standard is particularly valuable for organizations seeking to establish comprehensive information security programs, pursue ISO/IEC 27001:2013 certification, demonstrate security maturity to customers and partners, meet contractual security requirements, and align with international best practices. While ISO/IEC 27002:2013 itself does not provide for certification, organizations implementing the standard typically do so as part of broader ISO/IEC 27001 certification programs.
The standard's adoption accelerated rapidly following its publication, as organizations recognized the value of updated control guidance that addressed cloud computing, mobile security, and supplier relationships. Many organizations transitioned from ISO/IEC 27002:2005 to the 2013 edition to align with ISO/IEC 27001:2013 requirements and benefit from updated best practices. The framework's international recognition made it valuable for organizations operating globally, enabling them to demonstrate security capabilities across diverse markets and regulatory environments.
ISO/IEC 27002:2013 has influenced numerous other security standards and regulations, with many frameworks referencing or aligning with its 14-category structure. The standard's comprehensive coverage and international recognition made it a valuable reference for organizations managing multiple compliance obligations, enabling them to implement security controls once while meeting multiple requirements. The 2013 edition's expanded structure provided a model that other frameworks adopted or adapted, demonstrating the standard's influence on global information security practices.
Key Changes from ISO/IEC 27002:2005
ISO/IEC 27002:2013 introduced significant structural and content changes from the 2005 edition, reflecting evolving information security concerns and improved understanding of effective security management. Understanding these changes helps organizations transitioning from the 2005 edition or implementing the 2013 edition for the first time.
Expansion from 11 to 14 Control Categories: The most significant structural change was the expansion from 11 control domains to 14 control categories. The 2013 edition split some 2005 domains into separate categories, added new categories for emerging concerns, and reorganized controls to improve logical flow. This expansion provided more granular guidance for specific security concerns while maintaining comprehensive coverage.
New Dedicated Category for Supplier Relationships: ISO/IEC 27002:2013 introduced a dedicated "Supplier Relationships" category, recognizing that modern organizations rely extensively on third-party suppliers and that supplier security represents a critical concern. This category consolidated supplier-related controls that were previously distributed across multiple domains, providing comprehensive guidance for managing supplier security throughout supplier lifecycles.
New Dedicated Category for Cryptography: The 2013 edition introduced a dedicated "Cryptography" category, recognizing the growing importance of cryptographic controls for protecting information. This category consolidated cryptographic controls that were previously distributed across multiple domains, providing comprehensive guidance for implementing cryptographic controls appropriately.
Reorganization of System Development Controls: ISO/IEC 27002:2013 reorganized system development controls, splitting the 2005 "Information Systems Acquisition, Development, and Maintenance" domain into separate categories for "System Acquisition, Development, and Maintenance" and improved integration with secure development practices. This reorganization provided clearer guidance for addressing security throughout system lifecycles.
Updated Guidance for Cloud Computing: The 2013 edition included updated guidance addressing cloud computing concerns, recognizing that organizations increasingly rely on cloud services and that cloud security requires specific considerations. Controls addressing cloud security were updated and expanded to provide better guidance for organizations adopting cloud services.
Enhanced Mobile Device Security: ISO/IEC 27002:2013 included enhanced guidance for mobile device security, recognizing the proliferation of mobile devices and the unique security challenges they present. Controls addressing mobile device security were updated and expanded to provide better guidance for organizations managing mobile device deployments.
Key Framework Components and Control Categories
ISO/IEC 27002:2013 organizes information security controls into 14 control categories, each addressing specific aspects of information security management. These categories provide comprehensive coverage of information security concerns, from strategic security policy through operational security management and business continuity.
Information Security Policies
ISO/IEC 27002:2013 requires organizations to establish comprehensive information security policies that define management direction and support for information security. Information security policy requirements address policy development, policy review, and policy communication, ensuring that security policies are established, maintained, and communicated effectively throughout organizations. Security policies must be approved by management, reviewed regularly, and updated as organizational needs, threats, or technologies change.
The standard recognizes that effective security policies provide the foundation for information security programs, establishing management commitment, defining security objectives, and providing guidance for security decision-making. Security policies must be appropriate for organizational contexts, account for legal and regulatory requirements, and be communicated to all personnel and relevant external parties. Organizations must ensure that security policies are accessible, understood, and followed consistently, and must establish processes for policy review and update.
Organization of Information Security
ISO/IEC 27002:2013 requires organizations to establish management frameworks for information security, including security roles and responsibilities, coordination of security activities, and authorization processes for information processing facilities. Organization of information security requirements address internal organization, mobile devices and teleworking, and external parties, ensuring that security responsibilities are clearly defined, security activities are coordinated effectively, and security programs receive appropriate oversight.
The standard requires organizations to establish security management forums, designate security officers, define security roles and responsibilities, and coordinate security activities across organizational units. Organizations must address security in relationships with external parties, establish security requirements for third-party access, and ensure that external party security practices meet organizational requirements. The 2013 edition added specific requirements for mobile devices and teleworking, recognizing that modern work environments require specific security considerations.
Human Resource Security
ISO/IEC 27002:2013 requires organizations to ensure that personnel understand their security responsibilities and are suitable for the roles they are considered for. Human resource security requirements address security aspects of employment, including prior to employment, during employment, and termination or change of employment. Organizations must conduct security screening for personnel, provide security awareness and training, and manage security aspects of employment changes and terminations.
The standard requires organizations to define security roles and responsibilities in job descriptions, conduct background checks for personnel, ensure that personnel understand security responsibilities, and provide security awareness and training. Organizations must establish processes for managing security during employment changes, including role changes and transfers, and must ensure that access is revoked promptly when employment terminates. Human resource security must be integrated into standard human resources processes, ensuring that security considerations are addressed throughout employment lifecycles.
Asset Management
ISO/IEC 27002:2013 requires organizations to achieve and maintain appropriate protection of organizational assets, including information assets, software assets, physical assets, and services. Asset management requirements address responsibility for assets and information classification, ensuring that assets are identified, classified, and protected according to their value and sensitivity. Organizations must maintain inventories of assets, assign ownership responsibilities, and classify information based on sensitivity and criticality.
The standard requires organizations to establish processes for asset identification, maintain accurate asset inventories, assign asset ownership, and classify information appropriately. Information classification schemes must enable organizations to apply protection measures commensurate with information sensitivity, and must be communicated to personnel who handle information. Asset management processes must address the full asset lifecycle, from acquisition through disposal, ensuring that assets are protected throughout their existence in organizations.
Access Control
ISO/IEC 27002:2013 requires organizations to control access to information, ensuring that users receive only the access necessary for their job functions. Access control requirements address business requirements for access control, user access management, user responsibilities, and system and application access control. Organizations must establish access control policies based on business requirements, manage user access throughout access lifecycles, define user responsibilities, and control system and application access appropriately.
The standard requires organizations to establish access control policies, manage user registration and deregistration, manage privileged access, manage user passwords, review user access rights, and remove or adjust access rights when no longer needed. Access control implementations must enforce least privilege principles, ensure that access is granted based on business needs, and prevent unauthorized access. System and application access controls must protect information systems, control user authentication, and control access to applications and information.
Cryptography
ISO/IEC 27002:2013 introduced a dedicated "Cryptography" category, recognizing the growing importance of cryptographic controls for protecting information. Cryptographic requirements address cryptographic controls, ensuring that cryptographic controls are used appropriately to protect information confidentiality, integrity, and authenticity. Organizations must establish cryptographic policies, select appropriate cryptographic controls, and manage cryptographic keys securely.
The standard requires organizations to establish cryptographic policies that define when and how cryptographic controls should be used, select cryptographic controls that are appropriate for information sensitivity and risk levels, and manage cryptographic keys throughout key lifecycles. Cryptographic controls must be implemented correctly, cryptographic keys must be protected appropriately, and cryptographic implementations must be reviewed regularly. The dedicated cryptography category provides comprehensive guidance for organizations implementing cryptographic controls.
Physical and Environmental Security
ISO/IEC 27002:2013 requires organizations to prevent unauthorized physical access, damage, and interference to organizational premises and information. Physical and environmental security requirements address secure areas, equipment security, and general controls, ensuring that physical security controls protect information and information processing facilities. Organizations must establish secure areas for information processing, implement physical access controls, and protect equipment from environmental threats.
The standard requires organizations to define security perimeters, implement physical access controls, protect against environmental threats, and secure equipment appropriately. Secure areas must be protected by appropriate physical barriers, access controls, and monitoring, and must be designed to prevent unauthorized access. Equipment security requirements address equipment siting and protection, supporting utilities, cabling security, equipment maintenance, and secure disposal of equipment. Physical security controls must be appropriate for organizational risk levels and must be tested and maintained regularly.
Operations Security
ISO/IEC 27002:2013 requires organizations to ensure the correct and secure operation of information processing facilities. Operations security requirements address operational procedures and responsibilities, protection against malware, backup, logging and monitoring, control of operational software, technical vulnerability management, and information systems audit considerations. This category provides comprehensive coverage of operational security concerns.
The standard requires organizations to establish operational procedures, protect against malware, implement backup procedures, implement logging and monitoring, control operational software, manage technical vulnerabilities, and support information systems audits. Operational security controls must ensure that information processing facilities operate correctly and securely, that operational procedures are documented and followed, and that security events are detected and responded to appropriately. The 2013 edition's operations security category consolidated operational controls that were previously distributed across multiple domains.
Communications Security
ISO/IEC 27002:2013 requires organizations to ensure the security of information in networks and information transfer. Communications security requirements address network security management, information transfer, and general controls, ensuring that communications are protected appropriately. Organizations must manage network security, protect information transfer, and ensure that communications security controls are implemented effectively.
The standard requires organizations to manage network security, protect information transfer, and ensure that communications security controls address confidentiality, integrity, and availability. Network security management must address network segmentation, network access controls, and network monitoring. Information transfer controls must protect information during transfer, ensure that information is transferred securely, and prevent unauthorized access to information during transfer.
System Acquisition, Development, and Maintenance
ISO/IEC 27002:2013 requires organizations to ensure that security is an integral part of information systems throughout their lifecycles. System acquisition, development, and maintenance requirements address security requirements of information systems, security in development and support processes, and test data, ensuring that security is addressed during system acquisition, development, and maintenance activities.
The standard requires organizations to include security requirements in information system specifications, ensure that applications process information correctly, implement security in development and support environments, and manage test data securely. Security must be addressed throughout system lifecycles, from initial requirements through development, testing, deployment, and maintenance. Organizations must ensure that security controls are designed into systems, that security testing is conducted, and that vulnerabilities are managed effectively.
Supplier Relationships
ISO/IEC 27002:2013 introduced a dedicated "Supplier Relationships" category, recognizing that modern organizations rely extensively on third-party suppliers and that supplier security represents a critical concern. Supplier relationship requirements address information security in supplier relationships and supplier service delivery management, ensuring that supplier security is managed throughout supplier lifecycles.
The standard requires organizations to address information security in supplier relationships, establish security requirements for suppliers, monitor supplier security, and manage supplier service delivery securely. Organizations must assess supplier security before engagement, establish security requirements in supplier contracts, monitor supplier security throughout relationships, and ensure that suppliers meet security requirements. The dedicated supplier relationships category provides comprehensive guidance for managing supplier security, addressing a critical concern for modern organizations.
Information Security Incident Management
ISO/IEC 27002:2013 requires organizations to ensure that information security events and weaknesses associated with information systems are communicated in a manner allowing timely corrective action. Information security incident management requirements address management of information security incidents and improvements, ensuring that security incidents are detected, reported, and responded to appropriately.
The standard requires organizations to establish incident reporting procedures, ensure that security events are reported promptly, establish incident response capabilities, and learn from security incidents. Incident management processes must enable organizations to detect security incidents, respond to incidents effectively, recover from incidents, and improve security based on incident lessons learned. Organizations must establish incident response teams, define incident response procedures, test incident response capabilities, and conduct post-incident reviews.
Information Security Aspects of Business Continuity Management
ISO/IEC 27002:2013 requires organizations to counteract interruptions to business activities and protect critical business processes from the effects of major failures of information systems or disasters. Information security aspects of business continuity management requirements address information security continuity and redundancies, ensuring that information security is addressed in business continuity planning.
The standard requires organizations to address information security in business continuity management, develop business continuity plans that include information security requirements, test business continuity plans regularly, and maintain business continuity capabilities. Business continuity planning must address information security requirements, ensure that security controls are maintained during disruptions, and enable organizations to recover information security capabilities following disruptions. Organizations must test business continuity plans, update plans as business needs change, and ensure that personnel understand continuity procedures.
Compliance
ISO/IEC 27002:2013 requires organizations to avoid breaches of any law, statutory, regulatory, or contractual obligations, and of any security requirements. Compliance requirements address compliance with legal and contractual requirements, and information systems audit considerations, ensuring that organizations meet legal, regulatory, and contractual obligations.
The standard requires organizations to identify applicable legal and regulatory requirements, ensure that information processing complies with legal requirements, protect organizational records, ensure privacy of personal information, prevent misuse of information processing facilities, and regulate cryptographic controls. Organizations must ensure compliance with security policies and standards, review compliance regularly, and support information systems audits. Compliance activities must be integrated into standard operations, ensuring that legal and regulatory requirements are met continuously.
Implementation Strategies and Best Practices
Successfully implementing ISO/IEC 27002:2013 requires organizations to understand the standard's guidance, assess current security practices, and implement controls systematically. Organizations should begin by conducting comprehensive gap assessments comparing current security practices against ISO/IEC 27002:2013 requirements, identifying security strengths and weaknesses, and developing implementation plans that address gaps progressively.
Establish Information Security Governance: Organizations must establish governance structures for information security, including security policies, security management forums, and security roles and responsibilities. Governance structures should ensure that information security receives appropriate management attention, that security decisions are made appropriately, and that security programs are managed effectively. Organizations should establish security committees, designate security officers, and ensure that security responsibilities are clearly defined.
Conduct Risk Assessment: ISO/IEC 27002:2013 implementation should be risk-based, with organizations identifying security risks and implementing controls appropriate for their risk levels. Risk assessments should identify threats, vulnerabilities, and potential impacts, enabling organizations to prioritize security control implementation based on risk. Organizations should use risk assessment results to select controls from ISO/IEC 27002:2013, ensuring that controls address identified risks effectively.
Implement Controls Systematically: Organizations should implement ISO/IEC 27002:2013 controls systematically across all 14 categories, ensuring comprehensive security coverage. Implementation should be prioritized based on risk, with high-risk areas receiving early attention. Organizations should ensure that controls are implemented consistently, that controls are documented clearly, and that controls are tested and validated. Implementation should be phased, with early phases focusing on foundational controls and later phases addressing more advanced requirements.
Address Supplier Relationships: The 2013 edition's dedicated supplier relationships category requires organizations to establish comprehensive supplier security management programs. Organizations should assess supplier security before engagement, establish security requirements in supplier contracts, monitor supplier security throughout relationships, and ensure that suppliers meet security requirements. Supplier security management must be integrated into standard procurement and vendor management processes.
Implement Cryptographic Controls: The dedicated cryptography category requires organizations to establish cryptographic policies and implement cryptographic controls appropriately. Organizations should establish cryptographic policies that define when and how cryptographic controls should be used, select cryptographic controls that are appropriate for information sensitivity and risk levels, and manage cryptographic keys securely. Cryptographic implementations must be reviewed regularly to ensure continued effectiveness.
Integrate Security into Business Processes: Information security should be integrated into standard business processes, ensuring that security is considered in all business activities. Organizations should integrate security into system development lifecycles, change management processes, and operational procedures. Security should be addressed throughout business processes, from initial planning through ongoing operations, ensuring that security is not treated as separate activities.
Provide Security Awareness and Training: Organizations must ensure that personnel understand security responsibilities and are trained appropriately. Security awareness and training programs should address security policies, security procedures, and security responsibilities. Training should be provided to all personnel, with specialized training for personnel with specific security roles. Organizations should provide ongoing security awareness, ensuring that security remains a priority and that personnel understand evolving security requirements.
Implement Security Monitoring: Organizations must implement security monitoring capabilities that detect security events and verify compliance. Security monitoring should include continuous monitoring, security event detection, audit logging, and security reporting. Organizations should monitor systems and networks for security events, review audit logs regularly, and use monitoring findings to improve security controls. Security monitoring must be continuous and comprehensive, enabling organizations to detect security incidents promptly.
Conduct Regular Security Reviews: Organizations must conduct regular security reviews to verify that controls remain effective and that requirements continue to be met. Security reviews should include internal audits, management reviews, and independent assessments. Organizations should review security policies, assess control effectiveness, identify security weaknesses, and update security controls as needed. Security reviews must be conducted regularly, ensuring that security programs remain current and effective.
Relationship to Other Frameworks and Standards
ISO/IEC 27002:2013 exists within the broader ISO/IEC 27000 series, with important relationships to other standards that enable comprehensive information security management. Understanding these relationships helps organizations implement information security programs effectively.
ISO/IEC 27002:2013 serves as a companion to ISO/IEC 27001:2013, which specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2013 provides the detailed control guidance that organizations reference when implementing security controls. Organizations implementing ISO/IEC 27001:2013 typically use ISO/IEC 27002:2013 to identify and implement appropriate security controls within their ISMS.
The standard relates to ISO/IEC 27002:2005, which it superseded, and ISO/IEC 27002:2022, which superseded it. Organizations implementing ISO/IEC 27002:2013 should be aware that the 2022 edition provides updated guidance with a new structure organized around four themes, and may wish to reference the 2022 edition for current best practices. However, ISO/IEC 27002:2013 remains valid and provides valuable guidance for organizations establishing information security programs.
The standard influenced numerous other security frameworks and standards, with many frameworks referencing or aligning with its 14-category structure. NIST Cybersecurity Framework and other frameworks reference ISO/IEC 27002:2013 controls, enabling organizations to map controls across frameworks. The standard's comprehensive coverage and international recognition made it valuable for organizations managing multiple compliance obligations, enabling them to implement security controls once while meeting multiple requirements.
The standard aligns with other ISO standards including ISO/IEC 27005 (risk management) and ISO/IEC 27003 (ISMS implementation guidance), providing complementary guidance that supports comprehensive information security management. Organizations implementing ISO/IEC 27002:2013 may reference other ISO/IEC 27000 series standards for additional guidance on specific aspects of information security management.
Common Challenges and Solutions
Organizations implementing ISO/IEC 27002:2013 frequently encounter similar challenges related to the comprehensive nature of requirements, resource constraints, and the need to adapt guidance to organizational contexts. Understanding these common challenges helps organizations plan proactively and implement security controls effectively.
Understanding and Adapting Control Guidance: ISO/IEC 27002:2013 provides guidance rather than prescriptive requirements, requiring organizations to understand control intent and adapt controls to their contexts. Organizations may struggle to interpret control guidance, determine which controls apply, and adapt controls appropriately. Solutions include conducting comprehensive gap assessments, engaging security experts, and developing control implementation guidance specific to organizational contexts. Organizations should ensure that controls are adapted appropriately, addressing organizational risks while meeting control objectives.
Implementing Comprehensive Controls Across All Categories: ISO/IEC 27002:2013 includes extensive controls across 14 categories, which can be overwhelming for organizations to implement comprehensively. Organizations may struggle to prioritize implementation, ensure comprehensive coverage, and maintain controls over time. Solutions include developing phased implementation plans, prioritizing based on risk, and implementing controls systematically across categories. Organizations should approach implementation progressively, building toward comprehensive coverage over time.
Managing Supplier Relationships: The dedicated supplier relationships category requires organizations to establish comprehensive supplier security management programs, but organizations may struggle to assess supplier security, establish security requirements, and monitor supplier security effectively. Supplier security management can be challenging, requiring organizations to develop supplier security assessment capabilities, establish security requirements in contracts, and monitor supplier security throughout relationships. Solutions include developing supplier security assessment processes, establishing standard security requirements for suppliers, and implementing supplier security monitoring capabilities. Organizations should ensure that supplier security is managed effectively, addressing a critical concern for modern organizations.
Implementing Cryptographic Controls: The dedicated cryptography category requires organizations to establish cryptographic policies and implement cryptographic controls appropriately, but organizations may struggle to select appropriate cryptographic controls, manage cryptographic keys securely, and ensure that cryptographic implementations remain effective. Cryptographic control implementation can be challenging, requiring organizations to understand cryptographic technologies, establish key management processes, and review cryptographic implementations regularly. Solutions include engaging cryptographic experts, establishing cryptographic policies, and implementing key management processes. Organizations should ensure that cryptographic controls are implemented appropriately, providing protection for sensitive information.
Integrating Security into Business Processes: Effective information security requires integration into standard business processes, but organizations may struggle to integrate security without disrupting operations. Security integration can be challenging, requiring organizations to modify business processes, train personnel, and maintain security while enabling operations. Solutions include involving business personnel in security design, designing security controls that work within business processes, and providing security training that helps personnel understand security requirements. Organizations should ensure that security is integrated effectively, supporting business operations while providing protection.
Maintaining Security Controls Over Time: ISO/IEC 27002:2013 requires continuous maintenance of security controls, but organizations may struggle to keep controls current as threats evolve, technologies change, and business needs shift. Maintaining controls can be challenging, requiring organizations to review controls regularly, update controls as needed, and ensure that controls remain effective. Solutions include establishing processes for regular control review, integrating control maintenance into standard operations, and ensuring that security remains a priority. Organizations should approach control maintenance as an ongoing activity, ensuring that controls remain current and effective.
Demonstrating Control Effectiveness: Organizations must demonstrate that security controls are implemented effectively and that they provide appropriate protection, but demonstrating effectiveness can be challenging. Control effectiveness demonstration requires organizations to test controls, measure control performance, and provide evidence of control implementation. Solutions include establishing control testing processes, implementing security metrics, and maintaining comprehensive documentation. Organizations should ensure that control effectiveness is demonstrated regularly, enabling management to understand security posture and make informed decisions.
Managing Resource Constraints: Implementing comprehensive security controls requires significant resources, but organizations may have limited budgets, personnel, or expertise. Resource constraints can make comprehensive implementation challenging, requiring organizations to prioritize implementation and leverage resources efficiently. Solutions include prioritizing based on risk, implementing controls progressively, leveraging automation, and engaging external expertise where needed. Organizations should ensure that resources are allocated effectively, focusing on high-priority areas while building toward comprehensive coverage.
Transition to ISO/IEC 27002:2022
Organizations implementing ISO/IEC 27002:2013 should be aware that the standard was superseded by ISO/IEC 27002:2022, which introduced a major structural reorganization around four themes and updated control guidance. While ISO/IEC 27002:2013 remains valid and provides valuable guidance, organizations may wish to reference the 2022 edition for updated best practices and the new thematic structure.
Organizations transitioning from ISO/IEC 27002:2013 to the 2022 edition should conduct gap assessments comparing current implementations against new requirements, understand the new thematic structure, identify new controls that should be implemented, and update existing controls based on revised guidance. Transition activities should be planned systematically, ensuring that security improvements are implemented while maintaining existing security capabilities. Organizations should communicate transition plans to stakeholders, ensure that personnel understand changes, and maintain security throughout transition activities.
Frequently Asked Questions
What are the 14 control categories in ISO/IEC 27002:2013?
ISO/IEC 27002:2013 organizes information security controls into 14 categories: Information Security Policies, Organization of Information Security, Human Resource Security, Asset Management, Access Control, Cryptography, Physical and Environmental Security, Operations Security, Communications Security, System Acquisition Development and Maintenance, Supplier Relationships, Information Security Incident Management, Information Security Aspects of Business Continuity Management, and Compliance. Each category addresses specific aspects of information security, providing comprehensive coverage of security concerns from strategic policy through operational security management.
How does ISO/IEC 27002:2013 differ from ISO/IEC 27002:2005?
ISO/IEC 27002:2013 expanded from 11 control domains to 14 control categories, introduced dedicated categories for Supplier Relationships and Cryptography, updated guidance for cloud computing and mobile security, and improved alignment with ISO/IEC 27001:2013. The 2013 edition's expanded structure provided more granular guidance for specific security concerns while maintaining comprehensive coverage. The reorganization improved logical flow and made the standard easier to navigate and implement.
How does ISO/IEC 27002:2013 relate to ISO/IEC 27001:2013?
ISO/IEC 27002:2013 serves as a companion standard to ISO/IEC 27001:2013, which specifies requirements for establishing an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2013 provides detailed control guidance that organizations reference when implementing security controls within their ISMS. Organizations implementing ISO/IEC 27001:2013 typically use ISO/IEC 27002:2013 to identify and implement appropriate security controls.
Is ISO/IEC 27002:2013 still valid?
While ISO/IEC 27002:2013 was superseded by ISO/IEC 27002:2022, the 2013 edition remains valid and provides valuable guidance for organizations establishing information security programs. Organizations may reference ISO/IEC 27002:2013 for comprehensive guidance, though they should also consider the 2022 edition for updated best practices and the new thematic structure. The 2013 edition's 14-category structure provides a clear framework for understanding information security management.
Do organizations need to implement all ISO/IEC 27002:2013 controls?
ISO/IEC 27002:2013 provides guidance rather than prescriptive requirements, enabling organizations to select and implement controls appropriate for their risk levels and contexts. Organizations should conduct risk assessments to identify which controls are most relevant, prioritize implementation based on risk, and implement controls systematically. Not all controls may be applicable to all organizations, but organizations should document control selections and ensure that selected controls address identified risks effectively.
What is the Supplier Relationships category in ISO/IEC 27002:2013?
The Supplier Relationships category is a new category introduced in ISO/IEC 27002:2013, recognizing that modern organizations rely extensively on third-party suppliers and that supplier security represents a critical concern. This category consolidates supplier-related controls that were previously distributed across multiple domains, providing comprehensive guidance for managing supplier security throughout supplier lifecycles, including supplier assessment, contract requirements, and ongoing monitoring.
Conclusion
ISO/IEC 27002:2013 provides essential guidance for organizations seeking to establish comprehensive information security programs, offering a structured approach to implementing security controls across 14 key categories. As a significant evolution from the 2005 edition, ISO/IEC 27002:2013 expanded the framework to address emerging security concerns including cloud computing, mobile security, and supplier relationships, while maintaining comprehensive coverage of foundational security principles.
Successful ISO/IEC 27002:2013 implementation requires organizations to understand the standard's guidance, conduct risk assessments, and implement controls systematically based on identified risks. Organizations should approach implementation as a continuous improvement process, using ISO/IEC 27002:2013 controls as opportunities to strengthen security postures and build resilience against evolving threats.
By following ISO/IEC 27002:2013 guidance, maintaining comprehensive documentation, and continuously improving security controls, organizations can establish information security programs that effectively protect information assets, support business objectives, and demonstrate security maturity. While superseded by the 2022 edition, ISO/IEC 27002:2013 remains valuable as a comprehensive framework that influenced global information security practices and provided organizations with structured guidance for implementing security controls across diverse technology environments and business models.