What it is
What ISO 27002 is
ISO 27001 tells you that you need an information security management system and lists the controls you may select in Annex A. It does not tell you how to implement any of them. ISO/IEC 27002 is the companion that does: guidance, control by control, on what the control is for, how it is typically implemented and what to consider when you apply it.
The 2022 revision reorganised the controls into four themes - organisational, people, physical and technological - and gave each control a set of attributes you can filter by. That structure is the useful part: it lets you talk about your controls as a coherent set rather than a numbered list inherited from an annex.
It is guidance, not a certification
You are certified against ISO 27001. ISO 27002 is not a certifiable standard and there is no such thing as an ISO 27002 certificate. What it gives you is the reasoning behind each control, which is what an auditor is testing when they ask why you implemented one the way you did.
The four themes, and why the regrouping helps
The 2022 revision moved the controls from fourteen clauses into four themes. Organisational controls cover policy, roles, supplier relationships and incident management. People controls cover screening, terms of employment, awareness and what happens when someone leaves. Physical controls cover premises, equipment and media. Technological controls cover access, cryptography, logging, secure development and everything most people picture first.
The regrouping matters more than it sounds. A control set organised by theme can be assigned to the people who own that theme, which a numbered list inherited from an annex cannot. It also makes the gaps visible: an organisation with forty technological controls and three people controls has told you something about itself.
Each control also carries attributes - control type, information security properties, cybersecurity concepts, operational capabilities and security domains. They exist so you can view the same set through whichever lens the conversation needs, which is useful when a customer asks a question framed differently from your documentation.