{"id":2838,"date":"2019-06-05T11:23:14","date_gmt":"2019-06-05T11:23:14","guid":{"rendered":"https:\/\/www.imsm.com\/rwa\/gb\/?p=2838"},"modified":"2023-10-31T11:18:32","modified_gmt":"2023-10-31T11:18:32","slug":"iso-27001-iso-27002-how-they-work-together","status":"publish","type":"post","link":"https:\/\/www.imsm.com\/rwa\/news\/iso-27001-iso-27002-how-they-work-together\/","title":{"rendered":"ISO 27001 & ISO 27002: How they work together"},"content":{"rendered":"
In any organisation, threats to data security should be taken seriously. Whilst you cannot prepare for all eventualities, implementing an Information Security Management System (ISMS) is a good way of ensuring you are on top of your game when it comes to protecting confidential or sensitive data.<\/p>\n
If you\u2019ve come across ISO 27001<\/a> and ISO 27002 in your research, you might be wondering what the difference between the two are, and whether they work in conjunction with each other. In this blog we outline what each standard is and how they work together to help you implement a security system that you can trust.<\/p>\n ISO 27001<\/a> offers a comprehensive set of controls that outlines the requirements of ISMS. The process of becoming certified concentrates on improving your information (including cyber) security standards so that you can be sure you have an ultra-safe and validated data security management system.<\/p>\n Have more questions about ISO 27001<\/a>? Learn everything you need to know here.<\/a><\/p>\n ISO 27002 is more of a code of practice for security controls. It outlines the best practices for those implementing the ISMS, providing guidelines on the selection, implementation, and management of controls taking into consideration the risk environments of the organisation.<\/p>\n You cannot get certified to it as it is not a management standard, instead it is required for use by companies who are in the process of implementing ISO 27001<\/a>. The ISO 27002 can also be used by organisations who are planning to implement their own, or other commonly accepted information security management guidelines.<\/p>\n If you think of ISO 27001<\/a> as the \u2018what\u2019 to do, the ISO 27002 acts as the \u2018how\u2019 do I achieve this. The ISO 27001<\/a> can be audited and certified against, you follow certain steps to make sure you become compliant with the standard. The ISO 27002 outlines and offers guidance on how to apply controls that are included in Annex A of ISO 27001<\/a>.<\/p>\n Having the ISO 27001<\/a> certification will convey to your customers that you are keeping their data safe and secure, making you a business they can trust. If you are considering implementing an ISMS you should consider using both the ISO 27001<\/a> & ISO 27002 as a reference framework.<\/p>\n <\/p>\nWhat is ISO 27001?<\/h2>\n
What is ISO 27002?<\/h2>\n
How do they work together?<\/h2>\n