Definition
ISO/IEC 27002 is an international standard providing guidance on selecting, implementing and maintaining Security Controls that support an Information Security Management System.
Human Explanation
Where ISO/IEC 27001 defines what must be achieved, ISO/IEC 27002 provides example ways to implement relevant Controls.
Why it Matters
It helps organisations select Controls appropriate to their Risk and operating context.
Conceptual Boundary
ISO/IEC 27002 does not contain mandatory certification requirements. It is guidance for implementing Controls.
Practical Perspective
Not every Control described in ISO/IEC 27002 must be implemented. Selection should follow Risk Assessment and organisational needs.