A manufacturing firm has adopted ISO/IEC 27001 for its information security management system and now wants practical guidance on how to implement the individual controls it has selected in its Statement of Applicability. Which document is the most appropriate primary reference for that implementation guidance?
- AISO/IEC 27002, because it provides implementation guidance and good-practice detail for the information security controls referenced by the management-system standard. Correct
- BISO/IEC 27005, because it gives the detailed configuration steps needed to deploy each selected control consistently across the estate.
- CISO/IEC 27001 Annex A alone, because it lists the control implementation procedures in sufficient depth for an operational rollout.
- DISO/IEC 27000, because it defines the vocabulary and overview that practitioners follow when configuring controls.
Why A is correct: Correct: ISO/IEC 27002 is the code of practice that elaborates how to implement each control, making it the natural companion when the organisation has already chosen controls under ISO/IEC 27001.
Why B is wrong: Tempting because 27005 is in the same family and is widely cited, but it addresses information security risk management, not control implementation detail, so it does not answer the need.
Why C is wrong: Tempting because Annex A is where controls are selected, but it only names and briefly states controls; it deliberately leaves implementation guidance to the companion code of practice.
Why D is wrong: Tempting because 27000 underpins the whole family, but it provides terms and an overview only and contains no control implementation guidance.