ISO 27002: A part of the ISO 27000 family, ISO 27002 is a code of practice for information security controls. It provides best practice guidance on applying the controls listed under Annex A of ISO 27001. These controls, when implemented, provide ways of managing information security risks and ensuring confidentiality, integrity, and availability of data. Organizations often use ISO 27002 to guide the selection and implementation of controls based on their specific risk environment.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D1: Security Concepts and Practices
« Back to Glossary Index