ISO/IEC 27002 is a generic "code of practice" for information security. It provides a comprehensive set of reference controls designed to help organizations of any size or industry manage their security risks.
The Interplay of ISO/IEC 27002 and ISO/IEC 27799: Securing Health Informatics The ISO/IEC 27002 and ISO/IEC 27799 Information...
: Organizations cannot be certified directly against ISO/IEC 27002; instead, they use it as a reference to implement the requirements of ISO/IEC 27001. ISO/IEC 27799: The Healthcare Lens ISO/IEC 27002 is a generic "code of practice"
: It provides specific guidance on protecting personal health information (PHI) in all forms—whether paper records, digital images, or audio recordings. ISO/IEC 27799: The Healthcare Lens : It provides
: It acts as a detailed supplemental guide to the broader ISO/IEC 27001 management system.
: It covers universal procedures like access control, cryptography, and physical security, but it is not tailored to any specific sector.
ISO/IEC 27799 is a sector-specific companion to ISO/IEC 27002, designed specifically for . It adapts the generic controls of 27002 to meet the unique, often life-critical needs of the healthcare environment.