11 min read

ISO 27001 and ISO 27002: Controls Mapping for CISA

A detailed guide to ISO 27001 information security management systems and ISO 27002 controls, with practical mapping guidance for CISA professionals.

CISAPractice|

ISO 27001 and ISO 27002 form the cornerstone of international information security management standards. ISO 27001 specifies the requirements for an information security management system (ISMS), while ISO 27002 provides detailed guidance on implementing security controls. For CISA professionals, understanding these standards is essential for auditing organizations that maintain or pursue ISO 27001 certification.

ISO 27001 Overview

ISO 27001 defines a systematic approach to managing sensitive company information so that it remains secure. The standard follows a Plan-Do-Check-Act (PDCA) cycle and requires organizations to:

  • Establish the context and scope of the ISMS
  • Conduct a comprehensive risk assessment
  • Select and implement appropriate controls
  • Monitor, measure, and evaluate ISMS performance
  • Continually improve the management system

Key Clauses for Auditors

Clauses 4 through 10 define the mandatory requirements. Clause 4 (Context of the Organization) requires understanding internal and external factors. Clause 5 (Leadership) mandates top management commitment. Clause 6 (Planning) covers risk assessment and treatment. Clause 7 (Support) addresses resources, competence, and communication. Clause 8 (Operation) covers risk treatment plan implementation. Clause 9 (Performance Evaluation) requires monitoring and internal audits. Clause 10 (Improvement) addresses nonconformities and continual improvement.

ISO 27002 Control Categories

The 2022 revision of ISO 27002 reorganized controls into four themes:

Organizational Controls (37 controls)

Covering information security policies, roles and responsibilities, segregation of duties, management responsibilities, contact with authorities, threat intelligence, information security in project management, and asset management.

People Controls (8 controls)

Addressing screening, terms and conditions of employment, information security awareness and training, disciplinary processes, responsibilities after termination, confidentiality agreements, and remote working.

Physical Controls (14 controls)

Including security perimeters, physical entry controls, securing offices and facilities, physical security monitoring, protection against environmental threats, working in secure areas, clear desk and clear screen, and equipment protection.

Technological Controls (34 controls)

Covering user endpoint devices, privileged access rights, information access restriction, secure authentication, capacity management, malware protection, vulnerability management, configuration management, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

Mapping ISO 27002 to CISA Domains

  • Domain 1 (Audit Process): ISO 27001 Clause 9 on internal audit aligns with CISA audit methodology
  • Domain 2 (Governance): Clauses 4, 5, and 6 map to IT governance concepts tested in CISA
  • Domain 3 (Acquisition and Development): Technological controls on secure development and change management
  • Domain 4 (Operations): DSS-related controls for operations, monitoring, and incident management
  • Domain 5 (Protection of Information Assets): The majority of ISO 27002 controls directly support this domain

Practical Audit Approach

When auditing against ISO 27001, focus on three areas: the management system itself (clauses 4 through 10), the Statement of Applicability (which documents which controls are selected and why), and the operating effectiveness of implemented controls. Use ISO 27002 as guidance for evaluating control implementation quality.

Common Findings

  • Incomplete risk assessments that do not cover all assets in scope
  • Statements of Applicability that do not clearly justify control exclusions
  • Insufficient evidence of management review and continual improvement
  • Controls implemented without documented procedures or responsibilities

ISO 27001 and ISO 27002 provide IT auditors with a robust framework for evaluating information security practices. CISA professionals who master these standards can effectively assess ISMS implementations and provide valuable assurance to organizations pursuing or maintaining certification.

Related Tags

Technical Deep DiveISO 27001ISO 27002Information Security

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free