{"licence":{"name":"CC BY-SA 4.0","spdx":"CC-BY-SA-4.0","url":"https://creativecommons.org/licenses/by-sa/4.0/","attribution":"Atlas, a bilingual technical dictionary (https://atlas.maintz.dev/)"},"id":"security/iso-27002","url":{"en":"https://atlas.maintz.dev/en/terms/security/iso-27002/","da":"https://atlas.maintz.dev/da/terms/security/iso-27002/"},"term":{"en":"ISO 27002","da":"ISO 27002"},"aka":{"en":["ISO/IEC 27002"],"da":["ISO/IEC 27002"]},"domain":["security"],"cluster":"compliance","layer":"governance","status":"current","era":2007,"summary":{"en":"A guidance standard describing each security control in detail - what it is for and how to put it in place.","da":"En vejledende standard, der beskriver hver sikkerhedskontrol i detaljer - hvad den skal og hvordan den indføres."},"body":{"formal":{"en":"A companion standard to ISO 27001, current edition 2022, that gives the purpose of the same 93 controls and guidance on putting them in place, grouped into four themes - organisational, people, physical and technological; it contains no requirements and cannot be certified against.","da":"En følgestandard til ISO 27001, nuværende udgave fra 2022, der giver formål og vejledning for de samme 93 kontroller, fordelt på fire temaer - organisatoriske, menneskelige, fysiske og teknologiske; den stiller ingen krav og kan ikke bruges til certificering."},"plain":{"en":"If the house rules say \"keep the house safe\", this is the handyman's manual explaining which locks, alarms and smoke detectors to fit and where.","da":"Hvis husordenen siger \"hold huset sikkert\", er det her håndværkerens manual, der forklarer, hvilke låse, alarmer og røgalarmer der skal sættes op, og hvor."},"inPractice":{"en":"The IT security lead at a Danish hospital drafts the rules for who may open patient records by working through the ISO 27002 guidance on access control and adapting each point to the hospital's systems.","da":"Den IT-sikkerhedsansvarlige på et dansk hospital skriver reglerne for, hvem der må åbne patientjournaler, ved at gå ISO 27002's vejledning om adgangskontrol igennem og tilpasse hvert punkt til hospitalets systemer."},"whyItMatters":{"en":"A one-line control title says what to achieve but not how; without the guidance each organisation would have to work out every control from scratch and would often miss key parts.","da":"En kontroloverskrift på én linje siger, hvad man skal opnå, men ikke hvordan; uden vejledningen skulle hver organisation selv udtænke hver kontrol fra bunden og ville ofte overse vigtige dele."}},"deepDive":{"en":"The 2022 edition, retitled \"Information security, cybersecurity and privacy protection - Information security controls\", replaced the 114 controls in 14 clauses of the 2013 edition with 93 controls in four themes: organisational (clause 5, 37 controls), people (clause 6, 8), physical (clause 7, 14) and technological (clause 8, 34). Every control follows the same template: a control statement, a purpose, guidance and other information. The control statements are the same short texts that appear in ISO/IEC 27001 Annex A, so the Annex A entry says what, and the 27002 entry explains why and how.\n\nEleven controls were new in 2022: 5.7 threat intelligence, 5.23 information security for use of cloud services, 5.30 ICT readiness for business continuity, 7.4 physical security monitoring, 8.9 configuration management, 8.10 information deletion, 8.11 data masking, 8.12 data leakage prevention, 8.16 monitoring activities, 8.23 web filtering and 8.28 secure coding. Many older controls were merged rather than removed; Annex B of the standard maps each 2022 control back to its 2013 predecessors, which is what organisations used when moving their SoA to the new edition.\n\nA second structural addition is attributes, hashtag-style tags that let the same controls be viewed in different ways: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts (#Identify, #Protect, #Detect, #Respond, #Recover, borrowed from the NIST CSF functions), operational capabilities and security domains. Annex A of 27002 explains how to filter by them, for example to list all detective controls that support availability, and organisations may define their own attributes.\n\nBecause it is guidance, 27002 uses \"should\" throughout and cannot be certified against; an auditor assesses the organisation against 27001 and uses 27002 as a reference for what a reasonable implementation looks like. A common mistake is treating the guidance text as a checklist that must be followed word for word, when the actual obligation is the risk-based selection documented in the SoA. Sector documents such as ISO/IEC 27017 (cloud), 27018 (personal data in public clouds) and 27019 (energy utilities) extend the controls with sector-specific guidance, while the CIS Controls offer a more prescriptive, prioritised set of technical safeguards that can sit underneath the technological theme.","da":"2022-udgaven, med den nye titel \"Information security, cybersecurity and privacy protection - Information security controls\", erstattede 2013-udgavens 114 kontroller i 14 afsnit med 93 kontroller i fire temaer: organisatoriske (afsnit 5, 37 kontroller), menneskelige (afsnit 6, 8), fysiske (afsnit 7, 14) og teknologiske (afsnit 8, 34). Hver kontrol følger samme skabelon: en kontroltekst, et formål, vejledning og øvrig information. Kontrolteksterne er de samme korte formuleringer, som står i ISO/IEC 27001 anneks A, så anneks A siger hvad, mens 27002 forklarer hvorfor og hvordan.\n\nElleve kontroller var nye i 2022: 5.7 trusselsefterretninger, 5.23 informationssikkerhed ved brug af cloudtjenester, 5.30 IKT-parathed til driftskontinuitet, 7.4 overvågning af fysisk sikkerhed, 8.9 konfigurationsstyring, 8.10 sletning af information, 8.11 datamaskering, 8.12 forebyggelse af datalæk, 8.16 overvågningsaktiviteter, 8.23 webfiltrering og 8.28 sikker kodning. Mange ældre kontroller blev slået sammen frem for fjernet; standardens anneks B kobler hver 2022-kontrol til sine forgængere fra 2013, og det var den kobling, organisationerne brugte, da de flyttede deres SoA til den nye udgave.\n\nEn anden strukturel nyskabelse er attributter, tags i hashtag-form, der gør det muligt at se de samme kontroller fra forskellige vinkler: kontroltype (#Preventive, #Detective, #Corrective), informationssikkerhedsegenskaber (#Confidentiality, #Integrity, #Availability), cybersikkerhedsbegreber (#Identify, #Protect, #Detect, #Respond, #Recover, lånt fra funktionerne i NIST CSF), operationelle kapabiliteter og sikkerhedsdomæner. Anneks A i 27002 forklarer, hvordan man filtrerer på dem, fx for at finde alle detekterende kontroller, der understøtter tilgængelighed, og organisationer kan definere deres egne attributter.\n\nFordi det er vejledning, bruger 27002 \"bør\" hele vejen igennem og kan ikke bruges til certificering; auditoren vurderer organisationen efter 27001 og bruger 27002 som reference for, hvordan en rimelig implementering ser ud. En udbredt fejl er at behandle vejledningsteksten som en tjekliste, der skal følges ord for ord, når den egentlige forpligtelse er det risikobaserede valg, der dokumenteres i SoA'en. Sektordokumenter som ISO/IEC 27017 (cloud), 27018 (personoplysninger i offentlige clouds) og 27019 (energiforsyning) udvider kontrollerne med sektorspecifik vejledning, mens CIS Controls tilbyder et mere foreskrivende, prioriteret sæt tekniske sikringer, der kan ligge under det teknologiske tema."},"howTo":{"steps":{"en":["Start from the ISO 27001 risk assessment, which decides which risks need treatment; ISO 27002 is the guidance you use to choose and implement controls, not a checklist to follow word for word.","For each risk, go through the 93 controls in the four themes - organisational, people, physical and technological - and pick those that fit, adding your own controls where none does.","Record in the Statement of Applicability, for each Annex A control, whether it is used, why or why not, and how far it is implemented.","Use each control's purpose and guidance to write the rule or procedure, adapted to your own systems, fx access control (5.15-5.18) or backup (8.13), and name an owner for it.","Use the attributes, such as control type or cybersecurity concept, to check the balance, fx that you have detective and corrective controls and not only preventive ones.","Where sector guidance applies, such as ISO/IEC 27017 for cloud or 27019 for energy utilities, add its extra guidance to the relevant controls.","Implement the controls and keep evidence that they work, such as logs, access reviews and test results.","Review the controls and the SoA in internal audits and the management review at least yearly, and after incidents, new systems or new suppliers."],"da":["Tag udgangspunkt i risikovurderingen efter ISO 27001, som afgør, hvilke risici der skal håndteres; ISO 27002 er den vejledning, I bruger til at vælge og indføre kontroller, ikke en tjekliste, der skal følges ord for ord.","Gå for hver risiko de 93 kontroller i de fire temaer igennem - organisatoriske, menneskelige, fysiske og teknologiske - og vælg dem, der passer, og tilføj egne kontroller, hvor ingen passer.","Skriv i jeres SoA (Statement of Applicability) for hver kontrol i anneks A, om den bruges, hvorfor eller hvorfor ikke, og hvor langt den er implementeret.","Brug hver kontrols formål og vejledning til at skrive reglen eller proceduren, tilpasset jeres egne systemer, fx adgangskontrol (5.15-5.18) eller backup (8.13), og udpeg en ejer.","Brug attributterne, fx kontroltype eller cybersikkerhedsbegreb, til at tjekke balancen, fx at I har detekterende og korrigerende kontroller og ikke kun forebyggende.","Hvor der findes sektorvejledning, fx ISO/IEC 27017 til cloud eller 27019 til energiforsyning, så læg dens ekstra vejledning oven i de relevante kontroller.","Indfør kontrollerne, og gem dokumentation for, at de virker, fx logs, gennemgange af adgange og testresultater.","Gennemgå kontrollerne og SoA'en ved interne audits og ledelsens evaluering mindst en gang om året og efter hændelser, nye systemer eller nye leverandører."]},"pitfalls":{"en":["Treating the guidance text as a checklist that must be followed word for word, instead of choosing controls from the risk assessment.","Trying to get certified against ISO 27002, which is not possible; certification is against ISO 27001.","Copying control texts into policies without adapting them, so the rules do not match how the systems are actually run.","Leaving the SoA untouched when new risks, systems or suppliers appear."],"da":["At behandle vejledningsteksten som en tjekliste, der skal følges ord for ord, i stedet for at vælge kontroller ud fra risikovurderingen.","At forsøge at blive certificeret efter ISO 27002, hvilket ikke kan lade sig gøre; certificering sker efter ISO 27001.","At kopiere kontrolteksterne ind i politikkerne uden at tilpasse dem, så reglerne ikke passer til, hvordan systemerne faktisk drives.","At lade SoA'en stå uændret, når nye risici, systemer eller leverandører kommer til."]},"guides":[{"title":"ISO/IEC 27002 - Foranstaltninger til informationssikkerhed","url":"https://www.ds.dk/da/om-standarder/ledelsesstandarder/iso-27001-informationssikkerhed/iso-27002-foranstaltninger","publisher":"Dansk Standard","tier":"official-doc","lang":"da"},{"title":"ISO 27001 implementering - her finder du overblik og hjælp","url":"https://www.sikkerdigital.dk/myndighed/iso-27001-implementering","publisher":"Styrelsen for Samfundssikkerhed","tier":"official-doc","lang":"da"},{"title":"Vejledninger og skabeloner","url":"https://www.sikkerdigital.dk/myndighed/vejledninger-og-skabeloner","publisher":"Styrelsen for Samfundssikkerhed","tier":"official-doc","lang":"da"}]},"edges":[{"type":"requires","to":"security/control","confidence":"high","strength":"normal"},{"type":"kind-of","to":"security/security-framework","confidence":"high","strength":"normal"},{"type":"part-of","to":"security/iso-27000-series","confidence":"high","strength":"normal"},{"type":"used-with","to":"security/risk-treatment","why":{"en":"When treating a risk, teams pick fitting controls and use the guidance to put them in place.","da":"Når en risiko skal håndteres, vælger man passende kontroller og bruger vejledningen til at indføre dem."},"confidence":"high","strength":"normal"},{"type":"used-with","to":"security/security-policy","confidence":"medium","strength":"minor"},{"type":"used-with","to":"security/statement-of-applicability","why":{"en":"The SoA lists the Annex A controls that ISO 27002 explains in detail.","da":"SoA'en gennemgår de kontroller i anneks A, som ISO 27002 forklarer i detaljer."},"confidence":"high","strength":"normal"}],"depth":5,"sources":[{"title":"Cyber Security Fast Track - Ordliste","tier":"course-material"},{"title":"ISO/IEC 27002:2022","tier":"standard","publisher":"ISO/IEC"}],"draft":true}