Skip to main content
Category: Control Types and Framework

Control Attributes

Also known as: Control Attribute Tags, Attribute Tagging
Simply put

Control attributes are labels or tags attached to individual controls to describe their characteristics, making it easier to sort, filter, and organize them. In the security compliance context, they help teams group controls by qualities such as what they do or what they protect, so a large control set can be navigated and reported on more efficiently. The specific set of attributes used depends on the framework, tooling, or organizational conventions in play.

Formal definition

In quality and process contexts, 'attributes' refer to data that arise from classifying or counting observations (for example, conforming versus non-conforming units), as distinguished from measured variable data; attributes control charts monitor such count-based process characteristics. In security compliance practice, 'control attributes' more commonly denotes descriptive tags applied to controls to support categorization, selection, and reporting. Note that neither the SOC 2 Trust Services Criteria nor the ISO/IEC 27001 clause 4-10 requirements themselves prescribe a control-attribute schema; however, ISO/IEC 27002:2022 (the guidance companion to ISO/IEC 27001, not a certifiable standard itself) introduces an optional five-attribute tagging model for its reference controls to aid filtering and sorting. Because such schemes are typically optional and vary by standard edition, tooling, and organizational scope, the precise attribute set applicable to any engagement depends on the frameworks adopted and should be confirmed against the relevant edition rather than assumed universal.

Why it matters

As control sets grow to cover multiple frameworks, business units, and system components, teams need a way to navigate them efficiently. Control attributes address this by attaching descriptive tags to individual controls, allowing practitioners to sort, filter, and organize a large control library by qualities such as what a control does or what it protects. Without such tagging, mapping controls across a SOC 2 examination and an ISO 27001 ISMS, or reporting on a specific subset, becomes cumbersome and error-prone.

The practical significance is heightened by ISO/IEC 27002:2022, the guidance companion to ISO/IEC 27001, which introduces an optional five-attribute tagging model for its reference controls to aid filtering and sorting. Because ISO/IEC 27002:2022 is guidance rather than a certifiable standard, this scheme is optional; however, its existence means that in ISO-aligned engagements a recognized attribute model may already be available. Teams should confirm the applicable attribute set against the relevant edition rather than assuming a universal schema, since attribute conventions vary by standard edition, tooling, and organizational scope.

It is important to note the limits of what attributes accomplish. Attribute tags describe and organize controls; they do not by themselves assert that a control is designed suitably or operating effectively. Neither the SOC 2 Trust Services Criteria nor the ISO/IEC 27001 clause 4-10 requirements prescribe a control-attribute schema, so the presence or absence of tags is an organizational and tooling convenience rather than a compliance outcome in its own right.

Who it's relevant to

GRC and Compliance Managers
Those maintaining large, multi-framework control libraries use attributes to sort, filter, and organize controls, making it easier to navigate the set and produce targeted reports. They should confirm which attribute schema applies, since conventions vary by framework, tooling, and organizational scope.
ISO 27001 Practitioners
Teams working with ISO/IEC 27001 may draw on the optional five-attribute tagging model introduced in ISO/IEC 27002:2022 to filter and sort reference controls. Because ISO/IEC 27002:2022 is guidance rather than a certifiable standard, adopting this model is optional, and the applicable attribute set should be checked against the relevant edition.
SOC 2 Engagement Teams
Practitioners preparing for or supporting a SOC 2 examination should note that the Trust Services Criteria do not prescribe a control-attribute schema. Attribute tagging is an organizational and tooling convenience for managing and reporting on controls, not a requirement of the criteria themselves.
Quality and Process Professionals
In quality contexts, 'attributes' refers to count-based data (such as conforming versus non-conforming units) monitored on attributes control charts, a usage distinct from control tagging. Professionals should be aware that the same term carries different meanings across quality and security compliance domains.

Inside Control Attributes

ISO/IEC 27002:2022 Five-Attribute Scheme
ISO/IEC 27002:2022 introduces a standardised set of attributes that can be assigned to each of the 93 reference controls to aid filtering, sorting, and presentation. The five attribute types are Control type, Information security properties, Cybersecurity concepts, Operational capabilities, and Security domains. These attributes are provided as an optional aid and can be extended or adapted by an organisation to suit its own views and reporting needs.
Control Type
An attribute in ISO/IEC 27002:2022 that characterises a control by when and how it modifies risk relative to a security incident. The associated attribute values are Preventive, Detective, and Corrective, reflecting whether the control acts before, during, or after an event.
Information Security Properties
An ISO/IEC 27002:2022 attribute that indicates which of Confidentiality, Integrity, and Availability a control helps preserve. A single control may map to one or more of these properties.
Cybersecurity Concepts
An ISO/IEC 27002:2022 attribute that associates controls with recognised cybersecurity functions such as Identify, Protect, Detect, Respond, and Recover, supporting alignment with function-oriented views of a security programme.
Operational Capabilities and Security Domains
Two further ISO/IEC 27002:2022 attributes. Operational capabilities group controls from a practitioner's operational perspective (for example governance, asset management, or identity and access management), while Security domains group controls into broader fields such as governance and ecosystem, protection, defence, and resilience. Both are intended to help organisations navigate and organise the Annex A reference controls.
Relationship to ISO/IEC 27001 Annex A
The attribute scheme is defined in ISO/IEC 27002:2022, the guidance standard, and applies to the same reference controls listed in ISO/IEC 27001:2022 Annex A. The attributes themselves are not certifiable requirements; the certifiable ISMS requirements remain in clauses 4 through 10, and controls are selected via the Statement of Applicability informed by risk assessment.
SOC 2 Context
SOC 2, an attestation examination performed by a licensed CPA firm under SSAE 18, does not define an equivalent formal attribute-tagging model. Practitioners typically describe SOC 2 controls using informal characteristics (such as preventive versus detective, or automated versus manual) and by mapping them to the applicable Trust Services Criteria, but this is a practice convention rather than a prescribed schema within the Trust Services Criteria themselves.

Common questions

Answers to the questions practitioners most commonly ask about Control Attributes.

Is it true that neither SOC 2 nor ISO 27001 defines a standard set of control attributes?
That framing is incomplete. It is accurate that the AICPA Trust Services Criteria underlying a SOC 2 examination do not impose a fixed schema of control attributes, and that ISO/IEC 27001 itself (the certifiable clauses 4 through 10 and the Annex A reference controls) does not mandate an attribute-tagging scheme. However, the companion guidance standard ISO/IEC 27002:2022 introduces an optional but standardised model that assigns five attributes to each control, so it is not correct to say no framework offers any defined attribute structure. When discussing control attributes, distinguish clearly between the certifiable ISO/IEC 27001 requirements and the ISO/IEC 27002:2022 guidance that provides the attribute scheme.
Does ISO/IEC 27001 provide a framework-specific definition of control attributes?
The certifiable ISO/IEC 27001 standard does not itself define control attributes as a required element of the ISMS. The attribute concept is introduced in ISO/IEC 27002:2022, the associated guidance standard, which tags each of its reference controls with five attributes to help organisations sort, filter, and view controls from different perspectives. Because ISO/IEC 27002 is guidance rather than the certification standard, use of these attributes is typically optional and depends on how an organisation chooses to apply them; specify which standard and edition you are citing, since the attribute model belongs to the 2022 revision.
How can control attributes help when preparing a Statement of Applicability for ISO 27001?
In most implementations, the attributes provided in ISO/IEC 27002:2022 can be used alongside your risk assessment to organise and justify control selections that feed the Statement of Applicability. Because the attributes let you view controls from multiple perspectives, teams often use them to check coverage across those perspectives and to document rationale. Note that the Statement of Applicability is a requirement of ISO/IEC 27001, while the attribute tagging is an optional aid from ISO/IEC 27002; the attributes support but do not replace the risk-based selection the standard requires.
Can the same control attributes be reused across a SOC 2 examination and an ISO 27001 program?
You can maintain a common internal set of attributes to describe controls that support both a SOC 2 examination and an ISO 27001 ISMS, and many organisations do this to reduce duplicated effort. However, keep in mind that a SOC 2 report attests to controls against the Trust Services Criteria over the period and scope covered, while ISO 27001 certification addresses the defined ISMS scope. Mapping is possible but partial, so shared attributes help with organisation and traceability but do not make satisfaction of one framework automatically satisfy the other.
Who typically decides what control attributes to capture in an engagement?
Attribute definitions and usage generally depend on scoping decisions made by the organisation, in consultation with the service auditor for a SOC 2 examination or the certification body and internal ISMS owners for ISO 27001. For ISO work, teams may adopt the ISO/IEC 27002:2022 attribute scheme directly or extend it; for SOC 2, attributes are usually internal organising conventions rather than prescribed elements. Because there is no single mandated schema across both frameworks, expect the specific attributes to vary by scope, auditor, and certification body.
Do control attributes affect the outcome of a SOC 2 report or an ISO 27001 certificate?
Control attributes are primarily an organising and traceability aid and do not themselves determine outcomes. A SOC 2 report reflects the auditor's evaluation of design suitability, and for a Type II also operating effectiveness, over the covered period; it does not guarantee freedom from breaches. An ISO 27001 certificate reflects conformity of the defined ISMS scope as assessed by the certification body. Attributes can make evidence easier to manage and review, but the conclusions rest on the applicable criteria, the risk assessment, and the assessor's judgement rather than on any attribute scheme.

Common misconceptions

No framework defines control attributes, so the term is purely informal.
ISO/IEC 27002:2022 formally introduces a standardised five-attribute scheme (Control type, Information security properties, Cybersecurity concepts, Operational capabilities, and Security domains) that can be applied to each of the 93 controls. It is optional to use but is a defined, published model, not merely informal usage.
Applying ISO/IEC 27002:2022 control attributes is a mandatory part of achieving ISO/IEC 27001 certification.
The attribute scheme is provided as an optional aid for filtering and organising controls. The certifiable requirements sit in ISO/IEC 27001 clauses 4 through 10, and control selection is driven by risk assessment and documented in the Statement of Applicability. Using or not using the attribute tags does not, in itself, determine certification.
SOC 2 uses the same attribute model as ISO/IEC 27002:2022.
SOC 2 does not adopt the ISO/IEC 27002:2022 five-attribute scheme. While practitioners often informally describe SOC 2 controls as preventive or detective and map them to Trust Services Criteria, the Trust Services Criteria and ISO 27002 attributes are distinct and should not be conflated; mapping between the two frameworks is partial.

Best practices

When citing control attributes for ISO 27001-aligned work, specify that the five-attribute scheme originates in ISO/IEC 27002:2022 and reference the version, since attribute definitions and the underlying 93-control set are specific to the 2022 edition.
Treat the ISO/IEC 27002:2022 attributes as an optional organising and filtering aid rather than a certifiable requirement, and keep control selection anchored in your risk assessment and Statement of Applicability.
Where useful, extend or adapt the standard attribute values to fit your organisation's own reporting views, as the standard explicitly allows, but document any customisation so auditors can follow your reasoning.
Keep SOC 2 and ISO 27001 attribute usage distinct: describe SOC 2 controls in terms of the applicable Trust Services Criteria and informal characteristics, and reserve the formal five-attribute scheme for ISO/IEC 27002:2022 contexts.
When mapping controls across the two frameworks, use the attributes to support comparison but recognise the mapping is partial; satisfying attribute-based grouping in one framework does not automatically satisfy the other.
Verify attribute-related control counts and definitions against the specific standard edition before publishing or presenting to auditors, and describe figures qualitatively where the exact value depends on scope or version.