What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard defining requirements for an information security management system (ISMS); ISO 27002 is the companion guidance document explaining how to implement the controls. Organizations certify against ISO 27001, never against ISO 27002. ISO 27001 Annex A lists 93 controls in summary form; ISO 27002 expands each of those controls with detailed implementation guidance. Auditors assess conformance to 27001; 27002 helps you build what they assess.
The longer answer.
ISO 27001 contains the mandatory management-system requirements (context, leadership, planning, support, operation, performance evaluation, improvement) plus Annex A, the control list an organization scopes through its Statement of Applicability. ISO 27002 mirrors the 93 Annex A controls, organized into organizational, people, physical, and technological themes, with attributes and implementation detail for each.
The technological controls are where configuration evidence carries the audit: secure configuration, logging, network security, and hardening controls all expect proof that systems are configured securely and stay that way. Continuous CIS benchmark scanning mapped to ISO 27001, as CISGuard provides, turns one scanning program into recurring Annex A evidence.
More questions on Frameworks?
Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.