Cyber Resilience

← ISO 27001 Annex A

The ISO/IEC 27002:2022 control attributes

ISO/IEC 27002:2022 tags every one of the 93 controls with a small set of structured attributes — a consistent way to slice the catalogue by more than its clause number. Each explanation below is our own plain-language summary of what an attribute means and the values it can take; the attribute scheme itself is defined in ISO/IEC 27002:2022 (referenced, not reproduced).

Control type

Classifies a control by when it acts relative to a security incident. A control can carry more than one type.

Information security properties (C · I · A)

Which of the three core security properties the control helps preserve. Most controls support more than one.

Cybersecurity concepts

Aligns the control to the five high-level functions made familiar by the NIST Cybersecurity Framework — the role the control plays across a whole security programme.

Operational capabilities

Groups controls by the practitioner area that owns and runs them — the operational “muscle” behind the control. It lets you build and assign a programme by capability rather than by clause number.

Values name an operational area — for example governance, identity & access management, asset management, information protection, secure configuration, application security, threat & vulnerability management, and continuity. Each control is tagged with the capability that carries it day to day.

Security domains

A higher-level, strategic grouping of controls into four broad domains — a boardroom-level view of where a control sits.

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.