
ISO 27002 Experts in Germany
for practical information security controls, matched in minutes with vetted freelancersHire experts who translate ISO 27002 guidance into effective controls, risk treatments, security procedures and audit-ready evidence. Work with vetted, available freelancers selected through fast, precise AI matching for your specific information security needs.
Meet FRATCH Experts in Germany, who have recently used ISO 27002
Peter D.
Last position:
Security Consultant at Public-law institution of the city administration
- Requirements management, process planning, interface function, ISMS setup, and documentation
- Setup and establishment of an ISMS according to ISO 27001 and establishment of emergency management / ITSCM
- Coordination of the circumstances with the public-sector IT service provider
- Consideration of KRITIS relevance within the scope and implementation of a B3S
- Development of requirements for document control and the continuous improvement process
- Preparation of relevant project documents
- Analysis of existing processes and preparation of guidelines
- Requirements gathering for ISMS and ITSCM and coordination with the IT service provider, including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness, and emergency response
- Redesign of the complete documentation and preparation of new relevant documents
- Development of necessary rules, policies, and concepts
- Interface between customer and service provider to ensure document quality
- Coordination of protection needs with specialist departments, particularly regarding KRITIS relevance, and planning of resulting measures
- Development of preventive measures to minimize the risk of data center outages in scenarios such as pandemics or ransomware attacks
- Definition of the test strategy for IT emergency exercises
- Initiation of necessary awareness training measures for specialist departments
- External Information Security Officer
- Introduction of document control
Stefan G.
Last position:
Senior Technical Architect / Sub-project Manager at Helaba
Sub-project management
Designing the technical architecture and implementation
MS Active Directory
MS Azure Entra ID
Omada Identity Suite
Strategic realignment of the hybrid identity architecture of a regulated bank. Consolidation and security-focused standardization of multiple Active Directory environments and building a bank-wide Microsoft Entra ID structure. Migration of users and groups into a hybrid identity architecture and integration of Entra ID into existing governance and access processes (Omada). Implementation of regulatory requirements and establishment of audit-ready lifecycle processes to reduce structural security risks.
Markus M.
Last position:
Project Manager / Senior Consultant (multiple projects) at gkv informatik
- Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
- Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
- Regular reporting to management on progress and risks.
- Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
- Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
- Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
- Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
- Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Sergey K.
Last position:
Managing Director Cybersecurity at CBA-Cybersecurity and Business Advisory GmbH
- Development of comprehensive services in cybersecurity, IT governance, and AI
- Building and delivering strategic security solutions such as vCISO service, ISMS, SOC-as-a-Service (SIEM, SOAR, use cases, playbooks, threat hunting, incident response), AI-driven risk and compliance tools, and frameworks for outsourcing and third-party risks
- Supporting companies in meeting regulatory requirements and certifications (ISMS, NIS-2, DORA, CRA, KRITIS, ISO 27001, TISAX, BSI IT Baseline Protection, EU AI Act)
- Promoting innovations in cybersecurity automation, AI governance, and secure digital transformation
- Responsible for company growth, client relations, and strategic partnerships
Florian S.
Last position:
Information Security Officer / Designated InfoSec Officer at Oil Company
- Complete overhaul of the ISMS according to ISO 27001
- Conducted a comprehensive gap analysis
- Reduced ISMS documentation by 30% through consolidation and process optimization
- Introduced a full PDCA cycle for continuous improvement
- Established the ISMS within the company
- Implemented the necessary processes
- Managed and conducted internal and external audits
- Developed and implemented a company-wide risk management system
- Deployed an ISMS tool including process design and training
- KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
- NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
- Led a cybersecurity team of 3 members
- Conducted various internal and external audits, managed providers, introduced continuous improvement
- Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
- Redesigned the security architecture, reducing administrative efforts by 20%
- Implemented ITIL processes (e.g., change management)
- Revised service agreements with internal and external providers
- Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
- Managed a budget of one million euros
Norbert S.
Last position:
Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager
- 21 projects ≥ 6 months at large and medium-sized companies
- 13 projects as project or subproject manager
- 6 international projects with English as project language
Evgenii T.
Last position:
IT-Cybersecurity Engineer at EuroTechStudy
Oliver F.
Last position:
Senior IT Enterprise Security Architect | Project Bank Migration at Deutsche Bank AG (Retail Bank)
- Merger/insourcing project in the banking sector; transferring all data, users and processes from one bank to the parent company.
- IT security architect in the Chief Security Office as part of a merger/insourcing project for Postbank.
- Created a concept for clustering all applications to be migrated regarding risk profile, protection needs and compliance.
- Considered ISMS based on ISO27001 (Deutsche Bank) and BSI Basic Protection (Postbank).
- Reviewed and adjusted protection needs analyses, risk assessments and risk management processes.
- Led consulting for all subprojects on IT security architectures and concepts according to integration patterns (batch, online/web services, MQ).
- Prepared new components for review and approval by decision-makers.
- Served as subject matter expert for technical and content-related IT security questions.
- Supported all vertical streams (Sales & Channels, Investments, Lending, Finance, Enterprise) in documentation and architecture presentations.
- IT security risk management: answered review questions, analyzed deviations from the standard and carried out threat assessments.
- Lead security architect in CSO to align action plans for risk mitigation and validate residual risks.
- Prepared identified risks and non-compliances for the risk management units.
Nikolaus B.
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Thoralf T.
Last position:
Consultant Digital Operational Resilience Act (DORA) at Swisslife Deutschland GmbH
- Auditing CIS evidence of the SOC providers T-Systems Austria and Cancom GmbH
- Mapping of VAIT, ISO:IEC 27002 and CIS 7.0 requirements for the IT realignment strategy of the German subsidiaries in threat intelligence and zero trust
- Reviewing SIEM evidence, reporting, incident management and security breaches
- Reviewing IT asset management regarding ITSCM and BCM processes
- Employee awareness and compliance training focused on CEO fraud
- Advising the chief information security officer
Ralf L.
Last position:
Chief Information Security Officer at Stadtwerke Krefeld Holding AG
- Building an information security management system for the entire group
- Supporting 2 KRITIS subsidiaries
Klaus-Dieter K.
Last position:
Executive Partner at iAP-Independent Audit Professionals GmbH
Arnd F.
Last position:
Senior Manager at Gehrke Maas Consulting
Dirk P.
Last position:
IT systems and security engineer at Self-employed consulting engineer
Discover over 15,000 top freelancers
Statistics of experts using ISO 27002
Aggregated from the professional profiles of matched freelancers.
Experience
31 years

Position duration
4.4 years

Positions per freelancer
14

Top business areas
Information Technology, Operations, Project Management

Top industries
Information Technology, Manufacturing, Banking and Finance

Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
100%
Master's degree or higher
57%
Doctorate
14%

Certifications per freelancer
8

Most common languages
German, English, French

Speak two or more languages
100%
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using ISO 27002
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
ISO 27002 experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (86%)
- Manufacturing (79%)
- Banking and Finance (64%)
- Aerospace and Defense (43%)
- Automotive (43%)
- Professional Services (43%)
- Energy (36%)
- Healthcare (36%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What ISO 27002 covers
ISO/IEC 27002 is a practical reference for information security controls. It explains how organisations can design, implement and improve safeguards for people, processes, technology and physical environments. The standard supports ISO 27001 programmes but does not itself provide the requirements for certification.
Controls in practice
Professionals use ISO 27002 to interpret control guidance and turn it into workable measures across an organisation. Typical activities include:
- Mapping controls to business risks and existing safeguards
- Defining policies, procedures, ownership and operating evidence
- Improving access control, incident response and asset management
- Aligning supplier, cloud, endpoint and continuity practices
Ecosystem and skills
Strong work with ISO 27002 combines information security governance with risk management, internal controls and audit preparation. Relevant knowledge may include ISO 27001, ISO 31000, business continuity, privacy requirements, security architecture and governance, risk and compliance tooling. Specialists should also be able to communicate control expectations clearly to technical and business teams.
When companies need support
Companies bring in freelance expertise when a control framework is inconsistent, a certification programme needs practical structure or an audit has exposed gaps. Specialists can assess current practices, create a statement of applicability input, document evidence requirements and establish a repeatable improvement plan. In Germany, they may also support organisations that need clear coordination across local teams, international groups and external auditors.
Deliverables and collaboration
Assignments can include control gap assessments, policy libraries, risk and control registers, supplier security reviews, audit evidence packs and remediation tracking. Remote work is often effective when documentation and ownership are well organised; on-site workshops can help with interviews, process mapping and stakeholder alignment. German and English communication may both matter in internationally structured organisations.
What strong specialists bring
The best professionals do more than quote control statements. They connect ISO 27002 guidance to business processes, explain why a safeguard matters and define evidence that teams can maintain without unnecessary administration. Look for experience with control implementation, interviews, risk-based prioritisation, audit dialogue and measurable remediation, along with the judgement to distinguish a useful control from paperwork that only appears compliant.
Frequently asked questions
Need clarity? These are the questions we hear most often about ISO 27002.
ISO 27002 is used to interpret and implement information security controls in a practical way. It helps organisations structure policies, responsibilities, safeguards and evidence, often alongside ISO 27001, which sets the requirements for an information security management system.
ISO/IEC 27002 provides guidance on information security controls and their implementation. ISO 27001 defines the requirements for an information security management system and is the standard associated with certification, while 27002 helps organisations apply suitable controls in context.
A strong ISO 27002 specialist usually understands risk assessment, ISO 27001, internal audit and security governance. Depending on the assignment, knowledge of cloud security, supplier assurance, privacy, business continuity, identity management or governance, risk and compliance tools is also valuable.
The right level depends on the scope and maturity of the organisation. A focused control review may need a specialist who can assess evidence and prioritise gaps, while a broad implementation requires experience with risk workshops, policy design, stakeholder engagement and audit preparation.
Yes, much of ISO 27002 work can be performed remotely through document reviews, interviews, workshops and collaboration tools. On-site sessions in Germany can still be useful for process walkthroughs, sensitive stakeholder discussions and validating how controls operate in practice.
A code of practice for information security, commonly referred to as ISO/IEC 27002, can lead to deliverables such as a control gap assessment, policy updates, risk and control mappings, evidence requirements and remediation plans. The exact outputs should reflect the organisation’s risks, operating model and audit objectives.
Ask how the specialist would connect controls to business risks, owners, operating procedures and reliable evidence. Strong professionals explain trade-offs clearly, avoid copy-and-paste documentation and can show how they have supported implementation, audit discussions or sustained control improvement.
ISO/IEC 17799, the former name associated with the guidance, evolved into the ISO/IEC 27002 standard used today. Its control guidance remains relevant to cloud services and outsourcing when teams address supplier assurance, access, data protection, service continuity, incident handling and clearly defined responsibilities.
The average hourly rate of freelancers in Germany who have used ISO 27002 in their recent projects is 122 €, which corresponds to a daily rate of about 979 € based on an 8-hour working day.
Of the freelancers in Germany who have used ISO 27002 in their recent projects, 100% hold at least a Bachelor's degree, 57% hold at least a Master's degree, and 14% hold a doctorate.
On average, freelancers in Germany who have used ISO 27002 in their recent projects have 31 years of professional experience, with a single engagement typically lasting around 4.4 years.
The most common languages among freelancers in Germany who have used ISO 27002 in their recent projects are German (100%), English (100%), and French (21%).
The most common industries among freelancers in Germany who have used ISO 27002 in their recent projects are Information Technology (86%), Manufacturing (79%), and Banking and Finance (64%).
The most common business areas among freelancers in Germany who have used ISO 27002 in their recent projects are Information Technology (93%), Operations (71%), and Project Management (71%).
Main locations of FRATCH Experts, who have recently used ISO 27002
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
