Certification ISO/IEC 27002: Information security controls
ISO/IEC 27002: Information security controls introduces a framework for information security controls. Key areas include control selection, implementation guidance and the protection of information assets. It is relevant to security managers, risk owners and implementation teams.
Distinguish the guidance provided by ISO/IEC 27002 from the management system requirements in ISO/IEC 27001. A useful learning objective is to explain why a control is appropriate for a particular risk, rather than treating every control as a universal checklist.
Preparing for this pathway starts with your professional context. For a management system, useful evidence includes defined responsibilities, controlled processes and a regular review of performance. For a guidance standard, concentrate on how its recommendations inform decisions in the organisation’s own context.
Use the relevant OO2 course description to check the learning objectives and expected starting level. Attendance and certification are separate: any assessment and credential requirements must be confirmed for the chosen pathway.
fr
en