Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
ISO/IEC 27002: The 93 Information Security Controls
Rating: 4.4 out of 5(1,603 ratings)
7,904 students

ISO/IEC 27002: The 93 Information Security Controls

All 93 ISMS controls explained — organizational, people, physical and technological — for ISO/IEC 27001 implementation
Last updated 7/2026
English
Arabic [Auto],German [Auto],

What you'll learn

  • Implement an effective information security programme
  • Determine and apply appropriate security controls
  • Achieve compliance with ISO/IEC 27001
  • Understand information security best practices
  • Manage information security risks

Course content

6 sections105 lectures6h 51m total length
  • Introduction3:17

    Explore ISO/IEC 27002:2022 guidelines for 93 information security controls. See how these controls span organizational, people, physical, and technological domains, including incident management, classification and labeling, and cryptography.

  • Information security, cybersecurity and privacy4:12

    About the three concepts: information security, cybersecurity and privacy. The CIA triad (Confidentiality, Integrity, Availability).

  • The ISO/IEC 27000 series of standards4:35

    About the standards in the ISO/IEC 27000 series of standards. Which are the most popular standards in this family and what is their purpose.

    Standards on information security you can find here: https://www.iso.org/committee/45306/x/catalogue/p/1/u/0/w/0/d/0

  • An ISMS according to ISO/IEC 270013:53

    What is a management system and what is an ISMS (Information Security Management System). What does an ISMS consist of. What is the purpose of ISO/IEC 27001 and ISO/IEC 27002.

  • About ISO/IEC 270027:21

    A short history of ISO/IEC 27002. The structure of the standard. The four categories of controls (or themes): Organizational controls, People controls, Physical controls and Technological controls. About the attributes associated to each control in the standard.

Requirements

  • Familiarity with the ISO/IEC 27000 framework is useful, but not mandatory
  • An understanding of information security management principles

Description

ISO/IEC 27002 is the international standard that explains the 93 information security controls of ISO/IEC 27001 — what each control means, what it is for, and how it can be implemented. Where ISO/IEC 27001 lists the controls (in its Annex A), ISO/IEC 27002 is the implementation guidance: the reference every ISMS implementer, security officer and auditor works with daily.

This course details all 93 controls, organized by the four themes of the standard.

Course structure

  • Introduction — the ISO/IEC 27000 family of standards, the position and purpose of ISO/IEC 27002, definitions of information security, cybersecurity and privacy, and what an information security management system (ISMS) consists of

  • The 37 organizational controls — including information security roles and responsibilities, segregation of duties, threat intelligence, information security in project management, information classification and labelling, access control, information transfer, supplier relationships, ICT continuity, privacy and protection of PII, and documented operating procedures

  • The 8 people controls — screening, terms and conditions of employment, security awareness and training, the disciplinary process, and remote working

  • The 14 physical controls — secure areas, physical entry controls, clear desk and clear screen, storage media, supporting utilities, and the secure re-use and disposal of equipment

  • The 34 technological controls — endpoint devices, data masking, information deletion, backup, cryptography, logging and monitoring, network security, secure development and secure coding, protection of test information, web filtering, secure authentication, access to source code, and privileged utility programs

  • Certification — how ISO/IEC 27001 certification works for organizations, and the certification paths available to individuals working with ISO/IEC 27001 and 27002

How this course relates to ISO/IEC 27001

ISO/IEC 27001 sets the requirements for an ISMS and is the standard organizations certify against; ISO/IEC 27002 provides the detailed guidance for implementing its controls. If you are implementing an ISMS, preparing for certification, or selecting controls for your Statement of Applicability (SoA), this course gives you the control-by-control understanding that ISO/IEC 27001 itself does not provide.

Who this course is for

  • ISMS implementers and information security officers selecting and implementing controls

  • IT and cybersecurity professionals mapping their technical work to ISO/IEC 27001 requirements

  • Internal auditors and consultants who need to understand what good control implementation looks like

  • Anyone preparing their organization for ISO/IEC 27001 certification

Who this course is for:

  • Information security managers
  • ISMS auditors and consultants
  • Information security management practitioners and enthusiasts
  • Cybersecurity and privacy practitioners
  • Those interested in the ISO 27k framework