ISO/IEC 27002:2022
Overview of ISO/IEC 27002:2022
ISO/IEC 27002:2022, published by the International Organization for Standardization and the International Electrotechnical Commission, represents a major evolution of the information security control framework, introducing a revolutionary thematic structure that reorganizes controls around four themes: Organizational, People, Physical, and Technological. This 2022 edition represents the most significant structural change since the standard's inception, moving from 14 control categories to a streamlined thematic approach with 93 controls that better reflects modern information security management practices and digital transformation realities.
The 2022 edition maintains ISO/IEC 27002's role as a code of practice for information security controls, providing detailed guidance that organizations can reference when implementing security controls within their Information Security Management Systems (ISMS). The new thematic structure reflects the understanding that effective information security requires coordinated efforts across organizational structures, people, physical environments, and technology, providing a more intuitive framework for understanding and implementing security controls. The reorganization makes the standard more accessible and easier to navigate, while the reduction from 114 controls in the 2013 edition to 93 controls reflects consolidation and streamlining of guidance.
ISO/IEC 27002:2022 introduced 11 new controls addressing emerging security concerns including cloud security, threat intelligence, data leakage prevention, monitoring activities, web filtering, secure coding, configuration management, information deletion, data masking, and data leakage prevention. These new controls reflect the evolving threat landscape and the increasing importance of cloud computing, threat intelligence, and data protection in modern information security programs. The standard also updated existing controls to reflect current best practices and emerging technologies.
The standard achieved rapid international adoption following its publication, as organizations recognized the value of the updated structure and new controls addressing cloud security, threat intelligence, and data protection. Organizations implementing ISO/IEC 27001:2022 certification programs typically reference ISO/IEC 27002:2022 for control guidance, making the 2022 edition essential for organizations pursuing current ISMS certification. The framework's international recognition and comprehensive coverage make it valuable for organizations operating globally, enabling them to demonstrate security capabilities across diverse markets and regulatory environments.
Framework Applicability and Adoption
ISO/IEC 27002:2022 applies to organizations of all sizes and types, across all industries and sectors, providing flexible guidance that can be adapted to diverse organizational contexts. The standard is particularly valuable for organizations seeking to establish comprehensive information security programs, pursue ISO/IEC 27001:2022 certification, demonstrate security maturity to customers and partners, meet contractual security requirements, and align with international best practices. While ISO/IEC 27002:2022 itself does not provide for certification, organizations implementing the standard typically do so as part of broader ISO/IEC 27001 certification programs.
The standard's adoption accelerated rapidly following its publication, as organizations recognized the value of the updated thematic structure and new controls addressing cloud security, threat intelligence, and data protection. Many organizations transitioned from ISO/IEC 27002:2013 to the 2022 edition to align with ISO/IEC 27001:2022 requirements and benefit from updated best practices. The framework's international recognition makes it valuable for organizations operating globally, enabling them to demonstrate security capabilities across diverse markets and regulatory environments.
ISO/IEC 27002:2022 has influenced numerous other security standards and regulations, with many frameworks referencing or aligning with its thematic structure and control guidance. The standard's comprehensive coverage and international recognition make it a valuable reference for organizations managing multiple compliance obligations, enabling them to implement security controls once while meeting multiple requirements. The 2022 edition's thematic structure provides a model that other frameworks may adopt or adapt, demonstrating the standard's influence on global information security practices.
Key Changes from ISO/IEC 27002:2013
ISO/IEC 27002:2022 introduced significant structural and content changes from the 2013 edition, reflecting evolving information security concerns and improved understanding of effective security management. Understanding these changes helps organizations transitioning from the 2013 edition or implementing the 2022 edition for the first time.
Major Structural Reorganization: The most significant change was the reorganization from 14 control categories to four themes: Organizational, People, Physical, and Technological. This thematic structure provides a more intuitive framework for understanding information security, recognizing that effective security requires coordinated efforts across organizational structures, people, physical environments, and technology. The reorganization makes the standard more accessible and easier to navigate.
Consolidation of Controls: The 2022 edition consolidated controls from 114 in the 2013 edition to 93 controls, reflecting streamlining and consolidation of guidance. Some controls were merged, while others were reorganized to better reflect their relationships. This consolidation makes the standard more manageable while maintaining comprehensive coverage of information security concerns.
11 New Controls: ISO/IEC 27002:2022 introduced 11 new controls addressing emerging security concerns: Threat intelligence (5.7), Information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), Physical security monitoring (7.4), Configuration management (8.9), Information deletion (8.10), Data masking (8.11), Data leakage prevention (8.12), Monitoring activities (8.16), Web filtering (8.23), and Secure coding (8.28). These new controls reflect the evolving threat landscape and emerging technologies.
Updated Control Guidance: The 2022 edition updated existing controls to reflect current best practices, emerging technologies, and evolving threat landscapes. Controls addressing cloud computing, mobile security, and supplier relationships were updated to provide better guidance for modern information security programs. The updated guidance reflects lessons learned from real-world implementations and emerging security concerns.
Improved Alignment with ISO/IEC 27001:2022: The 2022 edition improved alignment with ISO/IEC 27001:2022, ensuring that control guidance supports the updated ISMS requirements. The thematic structure better aligns with the management system approach, making it easier for organizations to implement controls within their ISMS.
Key Framework Components and Control Themes
ISO/IEC 27002:2022 organizes information security controls into four themes, each addressing specific aspects of information security management. These themes provide comprehensive coverage of information security concerns, from strategic organizational structures through people, physical environments, and technology.
Organizational Controls Theme
The Organizational Controls theme addresses information security management from an organizational perspective, including policies, roles and responsibilities, risk management, and supplier relationships. This theme includes 37 controls covering organizational aspects of information security, ensuring that organizations establish appropriate governance structures, manage risks effectively, and address security in relationships with suppliers and other external parties.
Key organizational controls include information security policies, roles and responsibilities, segregation of duties, contact with authorities, contact with special interest groups, threat intelligence, information security in project management, information security for use of cloud services, information and communication technology (ICT) readiness for business continuity, and compliance with legal and contractual requirements. These controls ensure that organizations establish appropriate governance structures, manage information security effectively, and address security in all organizational activities.
The organizational theme recognizes that effective information security requires strong organizational structures, clear roles and responsibilities, and appropriate governance. Organizations must establish information security policies, define security roles, manage risks, and ensure that security is addressed in all organizational activities. The theme also addresses supplier relationships, recognizing that modern organizations rely extensively on third-party suppliers and that supplier security represents a critical concern.
People Controls Theme
The People Controls theme addresses information security from a human resources perspective, including screening, awareness and training, and disciplinary processes. This theme includes 8 controls covering people-related aspects of information security, ensuring that organizations address security in human resources processes and that personnel understand their security responsibilities.
Key people controls include screening, terms and conditions of employment, information security awareness, education and training, disciplinary process, and termination or change of employment responsibilities. These controls ensure that organizations address security in human resources processes, that personnel are suitable for their roles, and that personnel understand their security responsibilities. Organizations must conduct security screening, provide security awareness and training, and manage security aspects of employment changes and terminations.
The people theme recognizes that people represent both a critical asset and a potential security risk. Organizations must ensure that personnel are suitable for their roles, understand their security responsibilities, and are trained appropriately. Security awareness and training programs must address security policies, security procedures, and security responsibilities, ensuring that personnel understand how to protect information and respond to security incidents.
Physical Controls Theme
The Physical Controls theme addresses information security from a physical and environmental perspective, including physical security perimeters, physical entry controls, and protection against environmental threats. This theme includes 14 controls covering physical and environmental aspects of information security, ensuring that physical security controls protect information and information processing facilities.
Key physical controls include physical security perimeters, physical entry controls, securing offices, rooms and facilities, physical security monitoring, protecting against physical and environmental threats, working in secure areas, supporting utilities, and equipment siting and protection. These controls ensure that organizations establish secure physical environments, implement physical access controls, and protect equipment from environmental threats. Organizations must define security perimeters, implement physical access controls, and protect equipment appropriately.
The physical theme recognizes that physical security represents a foundational aspect of information security. Organizations must establish secure physical environments, implement physical access controls, and protect equipment from environmental threats. Physical security controls must be appropriate for organizational risk levels and must be tested and maintained regularly. The theme also addresses physical security monitoring, recognizing that organizations must monitor physical security to detect and respond to physical security incidents.
Technological Controls Theme
The Technological Controls theme addresses information security from a technology perspective, including access control, cryptography, secure development, and security monitoring. This theme includes 34 controls covering technological aspects of information security, ensuring that technological controls protect information and information systems effectively.
Key technological controls include user endpoint devices, privileged access rights, information access restriction, access to source code, secure authentication, access rights, information access restriction, use of privileged utility programs, access control to program source code, secure coding, configuration management, information deletion, data masking, data leakage prevention, information backup, logging, monitoring activities, clock synchronization, use of privileged utility programs, installation of software on operational systems, network security management, security of network services, segregation of networks, web filtering, use of cryptography, key management, and secure development lifecycle. These controls ensure that organizations implement appropriate technological controls to protect information and information systems.
The technological theme recognizes that technology represents both a critical enabler and a potential security risk. Organizations must implement appropriate technological controls to protect information and information systems, including access controls, cryptography, secure development practices, and security monitoring. Technological controls must be implemented correctly, configured appropriately, and monitored continuously to ensure continued effectiveness.
New Controls in ISO/IEC 27002:2022
ISO/IEC 27002:2022 introduced 11 new controls addressing emerging security concerns. Understanding these new controls helps organizations implement the 2022 edition effectively.
Threat Intelligence (5.7): This new control requires organizations to collect and analyze information about threats to enable proactive identification and mitigation of security risks. Organizations must establish threat intelligence capabilities, collect threat information from various sources, analyze threat information, and use threat intelligence to inform security decisions. Threat intelligence helps organizations understand the threat landscape and implement appropriate security controls.
Information Security for Use of Cloud Services (5.23): This new control addresses security requirements for cloud services, recognizing that organizations increasingly rely on cloud services and that cloud security requires specific considerations. Organizations must assess cloud service security, establish security requirements for cloud services, and monitor cloud service security. The control provides guidance for organizations adopting cloud services.
ICT Readiness for Business Continuity (5.30): This new control addresses information and communication technology readiness for business continuity, ensuring that ICT systems support business continuity objectives. Organizations must plan ICT continuity, test ICT continuity plans, and maintain ICT continuity capabilities. The control ensures that ICT systems can support business operations during disruptions.
Physical Security Monitoring (7.4): This new control requires organizations to monitor physical security to detect and respond to physical security incidents. Organizations must implement physical security monitoring capabilities, monitor physical security continuously, and respond to physical security incidents appropriately. Physical security monitoring helps organizations detect unauthorized physical access and respond to physical security threats.
Configuration Management (8.9): This new control requires organizations to establish and maintain secure configurations for information systems. Organizations must establish configuration baselines, manage configuration changes, and verify configuration compliance. Configuration management helps organizations maintain secure system configurations and prevent configuration drift.
Information Deletion (8.10): This new control requires organizations to delete information securely when no longer needed. Organizations must establish information deletion procedures, delete information securely, and verify information deletion. Secure information deletion helps organizations protect information and comply with data protection requirements.
Data Masking (8.11): This new control requires organizations to mask sensitive data to protect information while enabling legitimate use. Organizations must identify data requiring masking, implement data masking techniques, and verify data masking effectiveness. Data masking helps organizations protect sensitive information while enabling testing and development activities.
Data Leakage Prevention (8.12): This new control requires organizations to prevent unauthorized disclosure of information. Organizations must implement data leakage prevention technologies, monitor data movement, and respond to data leakage incidents. Data leakage prevention helps organizations protect sensitive information from unauthorized disclosure.
Monitoring Activities (8.16): This new control requires organizations to monitor information systems and networks to detect security events. Organizations must implement monitoring capabilities, monitor systems and networks continuously, and respond to security events appropriately. Monitoring activities help organizations detect security incidents and respond to security threats.
Web Filtering (8.23): This new control requires organizations to filter web content to prevent access to malicious or inappropriate websites. Organizations must implement web filtering technologies, configure web filtering appropriately, and monitor web filtering effectiveness. Web filtering helps organizations prevent access to malicious websites and protect against web-based threats.
Secure Coding (8.28): This new control requires organizations to implement secure coding practices to prevent security vulnerabilities in software. Organizations must establish secure coding standards, train developers in secure coding, and verify secure coding compliance. Secure coding helps organizations prevent security vulnerabilities in software applications.
Implementation Strategies and Best Practices
Successfully implementing ISO/IEC 27002:2022 requires organizations to understand the standard's thematic structure, assess current security practices, and implement controls systematically. Organizations should begin by conducting comprehensive gap assessments comparing current security practices against ISO/IEC 27002:2022 requirements, identifying security strengths and weaknesses, and developing implementation plans that address gaps progressively.
Understand the Thematic Structure: Organizations must understand the four-theme structure and how controls relate to each theme. The thematic structure provides a more intuitive framework for understanding information security, recognizing that effective security requires coordinated efforts across organizational structures, people, physical environments, and technology. Organizations should approach implementation thematically, ensuring that controls are implemented across all four themes.
Establish Information Security Governance: Organizations must establish governance structures for information security, including security policies, security management forums, and security roles and responsibilities. Governance structures should ensure that information security receives appropriate management attention, that security decisions are made appropriately, and that security programs are managed effectively. Organizations should establish security committees, designate security officers, and ensure that security responsibilities are clearly defined.
Conduct Risk Assessment: ISO/IEC 27002:2022 implementation should be risk-based, with organizations identifying security risks and implementing controls appropriate for their risk levels. Risk assessments should identify threats, vulnerabilities, and potential impacts, enabling organizations to prioritize security control implementation based on risk. Organizations should use risk assessment results to select controls from ISO/IEC 27002:2022, ensuring that controls address identified risks effectively.
Implement Controls Systematically: Organizations should implement ISO/IEC 27002:2022 controls systematically across all four themes, ensuring comprehensive security coverage. Implementation should be prioritized based on risk, with high-risk areas receiving early attention. Organizations should ensure that controls are implemented consistently, that controls are documented clearly, and that controls are tested and validated. Implementation should be phased, with early phases focusing on foundational controls and later phases addressing more advanced requirements.
Address New Controls: Organizations must address the 11 new controls introduced in the 2022 edition, including threat intelligence, cloud security, configuration management, and data leakage prevention. These new controls address emerging security concerns and should be prioritized based on organizational risk levels. Organizations should assess their current capabilities for these new controls and implement them appropriately.
Integrate Security into Business Processes: Information security should be integrated into standard business processes, ensuring that security is considered in all business activities. Organizations should integrate security into system development lifecycles, change management processes, and operational procedures. Security should be addressed throughout business processes, from initial planning through ongoing operations, ensuring that security is not treated as separate activities.
Provide Security Awareness and Training: Organizations must ensure that personnel understand security responsibilities and are trained appropriately. Security awareness and training programs should address security policies, security procedures, and security responsibilities. Training should be provided to all personnel, with specialized training for personnel with specific security roles. Organizations should provide ongoing security awareness, ensuring that security remains a priority and that personnel understand evolving security requirements.
Implement Security Monitoring: Organizations must implement security monitoring capabilities that detect security events and verify compliance. Security monitoring should include continuous monitoring, security event detection, audit logging, and security reporting. Organizations should monitor systems and networks for security events, review audit logs regularly, and use monitoring findings to improve security controls. Security monitoring must be continuous and comprehensive, enabling organizations to detect security incidents promptly.
Conduct Regular Security Reviews: Organizations must conduct regular security reviews to verify that controls remain effective and that requirements continue to be met. Security reviews should include internal audits, management reviews, and independent assessments. Organizations should review security policies, assess control effectiveness, identify security weaknesses, and update security controls as needed. Security reviews must be conducted regularly, ensuring that security programs remain current and effective.
Relationship to Other Frameworks and Standards
ISO/IEC 27002:2022 exists within the broader ISO/IEC 27000 series, with important relationships to other standards that enable comprehensive information security management. Understanding these relationships helps organizations implement information security programs effectively.
ISO/IEC 27002:2022 serves as a companion to ISO/IEC 27001:2022, which specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2022 provides the detailed control guidance that organizations reference when implementing security controls. Organizations implementing ISO/IEC 27001:2022 typically use ISO/IEC 27002:2022 to identify and implement appropriate security controls within their ISMS.
The standard relates to ISO/IEC 27002:2013, which it superseded, and ISO/IEC 27002:2005, providing updated guidance with a new thematic structure. Organizations implementing ISO/IEC 27002:2022 should be aware that the 2022 edition provides updated guidance with a new structure organized around four themes, and should reference the 2022 edition for current best practices. The 2022 edition's thematic structure provides a more intuitive framework for understanding information security.
The standard influenced numerous other security frameworks and standards, with many frameworks referencing or aligning with its thematic structure and control guidance. NIST Cybersecurity Framework and other frameworks reference ISO/IEC 27002:2022 controls, enabling organizations to map controls across frameworks. The standard's comprehensive coverage and international recognition make it valuable for organizations managing multiple compliance obligations, enabling them to implement security controls once while meeting multiple requirements.
The standard aligns with other ISO standards including ISO/IEC 27005 (risk management) and ISO/IEC 27003 (ISMS implementation guidance), providing complementary guidance that supports comprehensive information security management. Organizations implementing ISO/IEC 27002:2022 may reference other ISO/IEC 27000 series standards for additional guidance on specific aspects of information security management.
Common Challenges and Solutions
Organizations implementing ISO/IEC 27002:2022 frequently encounter similar challenges related to the new thematic structure, new controls, and the need to adapt guidance to organizational contexts. Understanding these common challenges helps organizations plan proactively and implement security controls effectively.
Understanding the Thematic Structure: The new four-theme structure represents a significant change from the 14-category structure in the 2013 edition, requiring organizations to understand how controls relate to themes and how themes relate to each other. Organizations may struggle to understand the thematic structure, map existing controls to themes, and implement controls thematically. Solutions include conducting training on the thematic structure, mapping existing controls to themes, and approaching implementation thematically. Organizations should ensure that they understand the thematic structure and how it applies to their implementations.
Implementing New Controls: The 11 new controls introduced in the 2022 edition address emerging security concerns, but organizations may lack capabilities for implementing these controls. New controls such as threat intelligence, cloud security, and data leakage prevention may require new technologies, processes, or expertise. Solutions include assessing current capabilities, developing implementation plans for new controls, and engaging external expertise where needed. Organizations should prioritize new controls based on risk and implement them progressively.
Transitioning from ISO/IEC 27002:2013: Organizations transitioning from the 2013 edition must understand the structural changes, identify new controls that should be implemented, and update existing controls based on revised guidance. Transition can be challenging, requiring organizations to map controls across editions, identify gaps, and update implementations. Solutions include conducting gap assessments, mapping controls across editions, and developing transition plans. Organizations should approach transition systematically, ensuring that security improvements are implemented while maintaining existing security capabilities.
Implementing Comprehensive Controls Across All Themes: ISO/IEC 27002:2022 includes 93 controls across four themes, which can be overwhelming for organizations to implement comprehensively. Organizations may struggle to prioritize implementation, ensure comprehensive coverage, and maintain controls over time. Solutions include developing phased implementation plans, prioritizing based on risk, and implementing controls systematically across themes. Organizations should approach implementation progressively, building toward comprehensive coverage over time.
Integrating Security into Business Processes: Effective information security requires integration into standard business processes, but organizations may struggle to integrate security without disrupting operations. Security integration can be challenging, requiring organizations to modify business processes, train personnel, and maintain security while enabling operations. Solutions include involving business personnel in security design, designing security controls that work within business processes, and providing security training that helps personnel understand security requirements. Organizations should ensure that security is integrated effectively, supporting business operations while providing protection.
Maintaining Security Controls Over Time: ISO/IEC 27002:2022 requires continuous maintenance of security controls, but organizations may struggle to keep controls current as threats evolve, technologies change, and business needs shift. Maintaining controls can be challenging, requiring organizations to review controls regularly, update controls as needed, and ensure that controls remain effective. Solutions include establishing processes for regular control review, integrating control maintenance into standard operations, and ensuring that security remains a priority. Organizations should approach control maintenance as an ongoing activity, ensuring that controls remain current and effective.
Demonstrating Control Effectiveness: Organizations must demonstrate that security controls are implemented effectively and that they provide appropriate protection, but demonstrating effectiveness can be challenging. Control effectiveness demonstration requires organizations to test controls, measure control performance, and provide evidence of control implementation. Solutions include establishing control testing processes, implementing security metrics, and maintaining comprehensive documentation. Organizations should ensure that control effectiveness is demonstrated regularly, enabling management to understand security posture and make informed decisions.
Managing Resource Constraints: Implementing comprehensive security controls requires significant resources, but organizations may have limited budgets, personnel, or expertise. Resource constraints can make comprehensive implementation challenging, requiring organizations to prioritize implementation and leverage resources efficiently. Solutions include prioritizing based on risk, implementing controls progressively, leveraging automation, and engaging external expertise where needed. Organizations should ensure that resources are allocated effectively, focusing on high-priority areas while building toward comprehensive coverage.
Frequently Asked Questions
What are the four themes in ISO/IEC 27002:2022?
ISO/IEC 27002:2022 organizes information security controls into four themes: Organizational Controls (37 controls), People Controls (8 controls), Physical Controls (14 controls), and Technological Controls (34 controls). The thematic structure provides a more intuitive framework for understanding information security, recognizing that effective security requires coordinated efforts across organizational structures, people, physical environments, and technology.
How many controls are in ISO/IEC 27002:2022?
ISO/IEC 27002:2022 includes 93 controls organized across four themes. This represents a consolidation from 114 controls in the 2013 edition, reflecting streamlining and consolidation of guidance while maintaining comprehensive coverage of information security concerns. The 93 controls address all aspects of information security management from strategic organizational structures through people, physical environments, and technology.
What are the new controls in ISO/IEC 27002:2022?
ISO/IEC 27002:2022 introduced 11 new controls: Threat intelligence (5.7), Information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), Physical security monitoring (7.4), Configuration management (8.9), Information deletion (8.10), Data masking (8.11), Data leakage prevention (8.12), Monitoring activities (8.16), Web filtering (8.23), and Secure coding (8.28). These new controls address emerging security concerns including cloud security, threat intelligence, and data protection.
How does ISO/IEC 27002:2022 differ from ISO/IEC 27002:2013?
ISO/IEC 27002:2022 introduced a major structural reorganization from 14 control categories to four themes, consolidated controls from 114 to 93, introduced 11 new controls addressing emerging security concerns, and updated existing controls to reflect current best practices. The thematic structure provides a more intuitive framework for understanding information security, while the new controls address cloud security, threat intelligence, and data protection.
How does ISO/IEC 27002:2022 relate to ISO/IEC 27001:2022?
ISO/IEC 27002:2022 serves as a companion standard to ISO/IEC 27001:2022, which specifies requirements for establishing an Information Security Management System (ISMS). While ISO/IEC 27001 provides the management system requirements, ISO/IEC 27002:2022 provides detailed control guidance that organizations reference when implementing security controls within their ISMS. Organizations implementing ISO/IEC 27001:2022 typically use ISO/IEC 27002:2022 to identify and implement appropriate security controls.
Do organizations need to implement all ISO/IEC 27002:2022 controls?
ISO/IEC 27002:2022 provides guidance rather than prescriptive requirements, enabling organizations to select and implement controls appropriate for their risk levels and contexts. Organizations should conduct risk assessments to identify which controls are most relevant, prioritize implementation based on risk, and implement controls systematically. Not all controls may be applicable to all organizations, but organizations should document control selections and ensure that selected controls address identified risks effectively.
Conclusion
ISO/IEC 27002:2022 provides essential guidance for organizations seeking to establish comprehensive information security programs, offering a structured approach to implementing security controls across four themes: Organizational, People, Physical, and Technological. As a major evolution from the 2013 edition, ISO/IEC 27002:2022 introduced a revolutionary thematic structure that reorganizes controls to better reflect modern information security management practices and digital transformation realities.
Successful ISO/IEC 27002:2022 implementation requires organizations to understand the standard's thematic structure, conduct risk assessments, and implement controls systematically based on identified risks. Organizations should approach implementation as a continuous improvement process, using ISO/IEC 27002:2022 controls as opportunities to strengthen security postures and build resilience against evolving threats.
By following ISO/IEC 27002:2022 guidance, maintaining comprehensive documentation, and continuously improving security controls, organizations can establish information security programs that effectively protect information assets, support business objectives, and demonstrate security maturity. The 2022 edition's thematic structure and new controls addressing cloud security, threat intelligence, and data protection provide organizations with current best practices for implementing information security controls in modern technology environments.