What does ISO/IEC 27002 cover?
• •This standard is a code of practice which means it contains a set of best practice controls that are used throughout the business world. • •In addition to defining the control it also provides implementation guidance regarding the control. • •The controls given in ISO/IEC 27002 are expressed in terms of “should” statements which makes them non-compliant statements. Whereas the controls in Annex A of ISO/IEC 27001, which are the same set of controls, are expressed in terms of “shall” statements which makes them formal compliance statements which is why this standard can be used for certification purposes.