🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Start your free trial
Back to Resource Center

Difference between ISO 27001 and ISO 27002

iso 27001 checklist

ISO 27001 and ISO 27002 are often mentioned together, but they are not the same. One is a certification standard, the other a practical guide. Anyone serious about information security benefits from both, but in different ways.

What is ISO 27001?

ISO 27001 is the international standard for information security. It defines the requirements for an Information Security Management System (ISMS): a coherent set of policies, processes, and measures to protect information. Organisations can get certified against ISO 27001, meaning an independent auditor verifies compliance with its requirements.

The standard defines what you need to arrange, not how. Think of: risk assessments, internal audits, management involvement and training employees in security awareness. The latter is explicitly listed in Annex A of the standard.

What is ISO 27002?

ISO 27002 is the practical elaboration of the security controls required by ISO 27001. Where 27001 states that you must take measures, 27002 explains how to implement them. You cannot get certified against ISO 27002: it is a guideline, not a certification standard.

In 2022, ISO 27002 was thoroughly revised. The number of controls dropped from 114 to 93, divided across four categories: organisational, people, physical, and technological. Security awareness training falls under the people category.

The difference at a glance

ISO 27001 ISO 27002
Type Certification standard Guideline
Purpose Requirements for an ISMS Guidance on how to implement controls
Certification possible? Yes No
Number of controls 93 (via Annex A) 93 (elaborated per control)
Mandatory? For certification: yes Recommended as a reference
Target audience Management, auditors Security teams, implementors

Which standard do you need?

If you want to demonstrate that you take information security seriously, to customers, partners, or regulators, ISO 27001 certification is the goal. ISO 27002 serves as a reference during implementation: it helps you understand which controls make sense and how to put them into practice.

The two standards complement each other. ISO 27001 without ISO 27002 is building without a blueprint. ISO 27002 without ISO 27001 is knowing how, but not knowing why.

The role of security awareness training

Both ISO 27001 and ISO 27002 require that employees be trained in information security. ISO 27001 sets it as a requirement (Annex A, control 6.3), while ISO 27002 explains how to make that training effective: regular, role-specific, and measurable.

One-off e-learnings or annual workshops rarely meet that bar in practice. Guardey helps organisations meet the ISO 27001 requirements for security awareness, with weekly microtrainings, phishing simulations, and audit-ready reports.

Security awareness training that fits ISO 27001

Guardey helps organisations meet the ISO 27001 training requirements, without the hassle. Request a demo and see for yourself what the platform can do for your organisation.

Plan a demo
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo