The ISO/IEC 27002:2022 control attributes
ISO/IEC 27002:2022 tags every one of the 93 controls with a small set of structured attributes — a consistent way to slice the catalogue by more than its clause number. Each explanation below is our own plain-language summary of what an attribute means and the values it can take; the attribute scheme itself is defined in ISO/IEC 27002:2022 (referenced, not reproduced).
Control type
Classifies a control by when it acts relative to a security incident. A control can carry more than one type.
- Preventive — Acts before an incident, to stop it happening.
- Detective — Acts during or after an incident, to reveal that something is wrong.
- Corrective — Acts after an incident, to limit the damage and restore normal operation.
Information security properties (C · I · A)
Which of the three core security properties the control helps preserve. Most controls support more than one.
- Confidentiality — Keeps information from being seen by anyone not authorised to see it.
- Integrity — Keeps information accurate and complete, changed only by authorised means.
- Availability — Keeps information and systems usable when they are needed.
Cybersecurity concepts
Aligns the control to the five high-level functions made familiar by the NIST Cybersecurity Framework — the role the control plays across a whole security programme.
- Identify — Understand your assets, risks and business context.
- Protect — Put safeguards in place to prevent or limit harm.
- Detect — Notice events and anomalies as they occur.
- Respond — Take action once an incident is detected.
- Recover — Restore capabilities and services after an incident.
Operational capabilities
Groups controls by the practitioner area that owns and runs them — the operational “muscle” behind the control. It lets you build and assign a programme by capability rather than by clause number.
Values name an operational area — for example governance, identity & access management, asset management, information protection, secure configuration, application security, threat & vulnerability management, and continuity. Each control is tagged with the capability that carries it day to day.
Security domains
A higher-level, strategic grouping of controls into four broad domains — a boardroom-level view of where a control sits.
- Governance and ecosystem — Setting direction, managing risk, and the relationships with suppliers and partners.
- Protection — The safeguards that keep assets secure day to day.
- Defence — Actively watching for and countering attacks.
- Resilience — Absorbing disruption and recovering from it.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.