Almost every conversation about information security runs into three similar numbers: 27000, 27001 and 27002. They are not different versions of the same thing, nor rungs on a ladder. They are documents with distinct jobs, and mixing them up costs time and money.
The essential distinction
Only one standard in the family is certifiable: ISO/IEC 27001. The rest are supporting documents. That already settles half the confusion — when somebody asks for "ISO 27002 certification", the thing they are asking for does not exist.
| Standard | What it is | Certifiable? |
|---|---|---|
| ISO/IEC 27000 | Vocabulary and overview of the family. Defines the terms the others use. | No |
| ISO/IEC 27001 | ISMS requirements. This is what you are audited against. | Yes |
| ISO/IEC 27002 | Implementation guidance for the Annex A controls. Explains the "how". | No |
| ISO/IEC 27005 | Guidance on information security risk management. | No |
| ISO/IEC 27701 | Privacy extension of the ISMS (privacy information management). | Yes, as an extension |
27000: the dictionary
ISO/IEC 27000 is the most ignored and the cheapest to consult — it is published free of charge. Its job is to define the terms the other standards use. When two departments spend half an hour arguing whether something is an "asset", a "risk" or a "vulnerability", the problem is usually that nobody opened 27000.
27001: what you have to comply with
This is the requirements standard. It says what must exist — policy, risk assessment, Statement of Applicability, internal audit, management review — but is deliberately sparing about how. That is a design choice: the same standard has to serve a bank and a ten-person startup.
Annex A of 27001 lists the 93 controls in one line each. It is a verification reference, not a manual.
27002: the controls manual
This is where each of those 93 controls gets several pages of guidance: purpose, implementation guidance, other considerations. Where 27001 says "access control shall be managed in line with business policy", 27002 is what discusses what that means in practice.
The 2022 revision aligned the two: the 27002 controls use the same numbering and the same four-theme organisation as Annex A of 27001. 27002 also introduced attributes — control type, information security properties, cybersecurity concepts, operational capabilities — that help filter controls and map them to other frameworks.
27005 and 27701: when they come in
27005 becomes necessary the moment you have to defend your risk assessment method to an auditor. 27001 requires a consistent, repeatable method but does not prescribe which — and 27005 supplies the repertoire.
27701 only makes sense once the ISMS exists. It extends the system to cover personal data, which makes it the natural path for demonstrating privacy maturity within an auditable structure. With no ISMS in place, there is nothing to extend.
Which one you need to buy
If the goal is certification: 27001 is mandatory and 27002 is close to indispensable in practice — implementing the controls from Annex A's single-line entries is possible, but expensive in rework. 27000 is free. 27005 earns its place once risk assessment stops being a spreadsheet exercise.
Watch the edition year. When purchasing, check for ISO/IEC 27001:2022 and ISO/IEC 27002:2022. Copies of the 2013 editions still circulate through resellers and training material, and the control numbering is incompatible between the two.