Control Attributes
In ISO/IEC 27001:2022 and its companion guidance standard ISO/IEC 27002:2022, control attributes are standardized tags assigned to each of the 93 information security controls. These controls are grouped into four themes: Organizational (37), People (8), Physical (14) and Technological (34). Attrib… In ISO/IEC 27001:2022 and its companion guidance standard ISO/IEC 27002:2022, control attributes are standardized tags assigned to each of the 93 information security controls. These controls are grouped into four themes: Organizational (37), People (8), Physical (14) and Technological (34). Attributes let organizations filter, sort and view controls from different perspectives, so they can see how the controls support their own risk treatment and business needs. ISO/IEC 27002 defines five attributes, each with hashtag-style values. First, Control type describes when a control acts relative to an incident: #Preventive, #Detective or #Corrective. Second, Information security properties show which property the control protects: #Confidentiality, #Integrity or #Availability. Third, Cybersecurity concepts align controls with the framework in ISO/IEC TS 27110, which also matches the NIST Cybersecurity Framework: #Identify, #Protect, #Detect, #Respond and #Recover. Fourth, Operational capabilities reflect the practitioner's view, with values such as #Governance, #Asset_management, #Identity_and_access_management, #Threat_and_vulnerability_management, #Continuity and #Supplier_relationships_security. Fifth, Security domains group controls into four broad areas: #Governance_and_Ecosystem, #Protection, #Defence and #Resilience. Attributes are informative, not mandatory requirements. Organizations may ignore them, use them selectively or create their own attributes, such as risk ratings, control owners or regulatory mappings. In practice, attributes help with several tasks. They support building the Statement of Applicability, identifying gaps in coverage (for example, too few detective or corrective controls), mapping controls to other frameworks and explaining security posture to stakeholders. For a Lead Auditor, understanding attributes is valuable because it supports a structured view of whether the selected controls form a balanced, risk-based defence. However, an auditor must not raise nonconformities simply because an organization does not use attributes. Conformity is judged against ISO/IEC 27001 requirements, especially risk assessment, risk treatment and the Statement of Applicability. Attributes are a tool for analysis and communication, not an audit criterion in themselves.
Control Attributes in ISO/IEC 27002:2022: A Complete Guide for ISO 27001 Lead Auditors
Introduction
When ISO/IEC 27001 and ISO/IEC 27002 were revised in 2022, one of the most visible changes was the introduction of control attributes. Each of the 93 controls in ISO/IEC 27002:2022 now carries a set of hashtag-style labels, such as #Preventive, #Confidentiality and #Protect. These labels let organizations view, filter and organize controls from several angles.
For an ISO 27001 Lead Auditor candidate, control attributes belong to the fundamental principles and concepts of an ISMS. Examiners regularly test whether you understand what they are, how they are structured, where they come from and, above all, whether they are mandatory. This guide covers each of those points and ends with practical exam tips.
1. Why Control Attributes Are Important
The 2013 edition of ISO/IEC 27002 grouped 114 controls into 14 clauses. That gave only a single, fixed view of the controls. The 2022 edition reduced the controls to 93 and placed them in just four themes. To compensate for this simpler structure, attributes were added so that controls could be viewed in many different ways.
Attributes matter for several reasons:
- Multiple perspectives: Different stakeholders can see the same control set in the way that suits them. For example, a SOC manager may filter by #Detect, while a compliance officer may filter by #Legal_and_compliance.
- Alignment with other frameworks: The cybersecurity concepts attribute (Identify, Protect, Detect, Respond, Recover) follows ISO/IEC TS 27110. This mirrors the NIST Cybersecurity Framework functions, which makes mapping and integration easier.
- Better risk treatment: During risk treatment, organizations can check that they have a balanced mix of preventive, detective and corrective controls. They can also confirm that confidentiality, integrity and availability are all addressed.
- Gap analysis and reporting: Attributes help an organization spot where its controls are weak, for example few #Recover controls or little #Supplier_relationships_security coverage.
- Communication: Attributes give management and technical teams a common vocabulary.
- Audit planning: Auditors can use attributes to sample controls, plan audit trails and understand how a control contributes to the ISMS.
2. What Control Attributes Are
A control attribute is a classification label attached to a control. Its purpose is to help users filter, sort and present controls. ISO/IEC 27002:2022 defines five attribute types, each with a fixed set of values. The values are written as hashtags, and multi-word values use underscores.
Attribute 1: Control type
This describes when and how the control acts in relation to an information security incident.
- #Preventive: stops an incident from happening.
- #Detective: identifies an incident while or after it occurs.
- #Corrective: limits the impact of an incident or restores normal operation.
Attribute 2: Information security properties
This describes which characteristic of information the control helps preserve.
- #Confidentiality
- #Integrity
- #Availability
Attribute 3: Cybersecurity concepts
This places the control within the cybersecurity framework of ISO/IEC TS 27110.
- #Identify
- #Protect
- #Detect
- #Respond
- #Recover
Attribute 4: Operational capabilities
This views the control from a practitioner's point of view. There are 15 values:
- #Governance
- #Asset_management
- #Information_protection
- #Human_resource_security
- #Physical_security
- #System_and_network_security
- #Application_security
- #Secure_configuration
- #Identity_and_access_management
- #Threat_and_vulnerability_management
- #Continuity
- #Supplier_relationships_security
- #Legal_and_compliance
- #Information_security_event_management
- #Information_security_assurance
Attribute 5: Security domains
This groups controls into four broad domains:
- #Governance_and_Ecosystem: includes information system security governance and risk management, and ecosystem cybersecurity management (third parties and suppliers).
- #Protection: includes IT security architecture and administration, identity and access management, IT security maintenance, and physical and environmental security.
- #Defence: includes detection and computer security incident management.
- #Resilience: includes continuity of operations and crisis management.
Important distinction: themes are not attributes.
The four themes are the main structural grouping of controls (Clauses 5 to 8 of ISO/IEC 27002):
- Organizational controls (Clause 5): 37 controls
- People controls (Clause 6): 8 controls
- Physical controls (Clause 7): 14 controls
- Technological controls (Clause 8): 34 controls
Each control belongs to exactly one theme. A control can, however, have several values within one attribute. For example, it can be both #Preventive and #Detective.
3. How Control Attributes Work
Structure of each control in ISO/IEC 27002:2022
Every control follows the same layout:
- Control title
- Attribute table, showing the values for each of the five attributes
- Control: what the control is
- Purpose: why the control should be implemented
- Guidance: how to implement it
- Other information: related material and references
Example attribute tables
5.1 Policies for information security
- Control type: #Preventive
- Properties: #Confidentiality, #Integrity, #Availability
- Concepts: #Identify
- Capabilities: #Governance
- Domains: #Governance_and_Ecosystem, #Resilience
5.7 Threat intelligence (a new control in 2022)
- Control type: #Preventive, #Detective, #Corrective
- Properties: #Confidentiality, #Integrity, #Availability
- Concepts: #Identify, #Detect, #Respond
- Capabilities: #Threat_and_vulnerability_management
- Domains: #Defence, #Resilience
8.13 Information backup
- Control type: #Corrective
- Properties: #Integrity, #Availability
- Concepts: #Recover
- Capabilities: #Continuity
- Domains: #Protection
8.16 Monitoring activities
- Control type: #Detective, #Corrective
- Properties: #Confidentiality, #Integrity, #Availability
- Concepts: #Detect, #Respond
- Capabilities: #Information_security_event_management
- Domains: #Defence
Notice how backup is purely #Corrective and supports #Recover. It does not prevent an incident; it restores the situation afterwards. Questions often turn on reasoning of this kind.
Annex A of ISO/IEC 27002
Annex A of ISO/IEC 27002 contains a matrix of all 93 controls and their attribute values. It also explains how to use attributes to create different views. Annex B maps the 2022 controls to the 2013 controls.
Organizations can create their own attributes
The standard explicitly allows an organization to define its own attributes, such as:
- control maturity
- control owner
- related risk
- regulatory mapping
- applicable location or business unit
Attributes are a flexible tool, not a fixed requirement.
Relationship to ISO/IEC 27001
ISO/IEC 27001:2022 Annex A lists the same 93 controls, but only the control titles and control statements. Annex A of ISO/IEC 27001 does not include attributes. Attributes exist only in the guidance standard, ISO/IEC 27002.
Under ISO/IEC 27001 clause 6.1.3, organizations must:
- determine the necessary controls,
- compare them with Annex A,
- produce a Statement of Applicability (SoA).
Using attributes is not a requirement of ISO/IEC 27001. They are an optional aid.
Implications for auditors
- An auditor cannot raise a nonconformity simply because an organization does not use attributes or has not categorized its controls by attribute.
- An auditor may use attributes to understand the purpose of a control and plan sampling. For example, the auditor can check that detective controls actually generate and review evidence.
- An auditor can use attributes to judge whether the risk treatment seems balanced. Any finding must still be based on an ISO/IEC 27001 requirement, such as the adequacy of risk treatment under 6.1.3 or the effectiveness of controls.
- If an organization has chosen to use attributes in its own documented processes (for example, in its SoA or control library), the auditor can audit conformity against the organization's own documented approach.
4. How to Answer Exam Questions on Control Attributes
Questions on this topic in Lead Auditor exams, such as PECB, IRCA/CQI or similar schemes, usually take one of these forms:
- Definition and recall: How many attribute types are there? Which value belongs to which attribute? Where are attributes defined?
- Classification: Given a control or scenario, is it preventive, detective or corrective? Which cybersecurity concept applies?
- Mandatory or optional: Is the auditee required to use attributes? Should the auditor raise a nonconformity?
- Scenario application: An organization wants to see all controls supporting incident response. Which attribute helps?
- Distinguishing themes from attributes: Is Physical a theme or an attribute? (Physical is a theme; #Physical_security is an operational capability value.)
Step-by-step approach
1. Identify what the question really asks: a definition, a classification, or an audit judgement.
2. For classification questions, ask when the control acts: before the incident (preventive), during or after to discover it (detective), or after to limit or repair it (corrective).
3. For audit judgement questions, always link back to ISO/IEC 27001 requirements. Attributes alone never create a nonconformity.
4. Eliminate answers that confuse ISO/IEC 27001 with ISO/IEC 27002, or themes with attributes.
Exam Tips: Answering Questions on Control Attributes
Tip 1: Memorize the five attributes.
Use the mnemonic "Tiny Penguins Can Organize Snow":
- Type (control type)
- Properties (information security properties)
- Concepts (cybersecurity concepts)
- Operational capabilities
- Security domains
Tip 2: Know the value counts.
- Control type: 3
- Properties: 3
- Cybersecurity concepts: 5
- Operational capabilities: 15
- Security domains: 4
Tip 3: Attributes are in ISO/IEC 27002, not ISO/IEC 27001.
If an option says ISO/IEC 27001 Annex A defines attributes, it is wrong.
Tip 4: Attributes are optional and extendable.
Any answer suggesting that organizations must use the five attributes, or may not add their own, is incorrect.
Tip 5: Do not raise a nonconformity for not using attributes.
A nonconformity is raised only against requirements. These come from ISO/IEC 27001, legal or contractual obligations, or the organization's own documented ISMS. Not using attributes is at most an opportunity for improvement.
Tip 6: Do not confuse themes with attributes.
- Themes: Organizational, People, Physical, Technological.
- Attributes: the five hashtag classifications.
Each control has one theme but can have several values per attribute.
Tip 7: Reason through the control type.
- Backups, restoration and disaster recovery are corrective.
- Logging and monitoring are detective.
- Access control, encryption and awareness are mainly preventive.
Many controls carry more than one type.
Tip 8: Link cybersecurity concepts to ISO/IEC TS 27110 and NIST CSF.
If a question mentions aligning with the NIST Cybersecurity Framework, the relevant attribute is cybersecurity concepts.
Tip 9: Use the right attribute for practitioner views.
Operational capabilities give a practitioner's view, for example everything related to identity and access management. Security domains give a high-level, four-domain view.
Tip 10: Watch for absolute wording.
Words like always, must or only attached to attributes usually signal a wrong option, because attributes are guidance-based and flexible.
Tip 11: In scenario questions, think as an auditor.
Attributes help you understand intent and plan sampling. Your finding should still be about whether controls are determined, implemented, effective and justified in the SoA.
Tip 12: Remember the key numbers.
- 93 controls in total (37 / 8 / 14 / 34 across the four themes)
- 11 new controls in 2022, including threat intelligence, cloud services security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding
- Annex A of ISO/IEC 27002 holds the attribute matrix
Sample exam question
An auditor finds that an organization's SoA lists all applicable Annex A controls with justifications. The organization has not classified the controls using the ISO/IEC 27002 attributes. What should the auditor do?
A) Raise a major nonconformity against clause 6.1.3
B) Raise a minor nonconformity because attributes are missing
C) Not raise a nonconformity; attributes are optional, and the auditor may note it as an opportunity for improvement if relevant
D) Suspend the audit
Correct answer: C. ISO/IEC 27001 does not require attributes, so their absence is not a nonconformity.
Summary
Control attributes are optional, hashtag-based classifications in ISO/IEC 27002:2022. There are five attribute types:
- Control type
- Information security properties
- Cybersecurity concepts
- Operational capabilities
- Security domains
They give multiple views of the 93 controls, support alignment with other frameworks, and help with risk treatment and audit planning. They are not requirements of ISO/IEC 27001, and organizations may add their own. In the exam, know the five attributes and their values, keep themes and attributes separate, reason carefully about control types, and never treat the absence of attributes as a nonconformity.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!