Skip to main content
← All answers
Frameworks

What is the difference between ISO 27001 and ISO 27002?

More context

ISO 27001 contains the mandatory management-system requirements (context, leadership, planning, support, operation, performance evaluation, improvement) plus Annex A, the control list an organization scopes through its Statement of Applicability. ISO 27002 mirrors the 93 Annex A controls, organized into organizational, people, physical, and technological themes, with attributes and implementation detail for each.

The technological controls are where configuration evidence carries the audit: secure configuration, logging, network security, and hardening controls all expect proof that systems are configured securely and stay that way. Continuous CIS benchmark scanning mapped to ISO 27001, as CISGuard provides, turns one scanning program into recurring Annex A evidence.

Related questions

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.

Request Executive Briefing →