Control Set
In a security compliance context, a control set is the collection of controls an organization selects and implements to meet the requirements of a given framework, such as SOC 2 or ISO/IEC 27001. It represents the specific safeguards chosen based on the organization's scope, risk assessment, and the criteria or requirements that apply to its situation.
A control set is the defined grouping of controls scoped for a particular compliance engagement or management system. In a SOC 2 examination, the control set comprises the controls a service organization maps to the applicable Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional additions selected by scope; the auditor evaluates suitability of design (Type I) or design and operating effectiveness over a review period (Type II). In an ISO/IEC 27001 context, the control set typically refers to the reference controls in Annex A that an organization selects via its Statement of Applicability, informed by risk assessment, alongside the certifiable ISMS requirements in clauses 4 through 10; the number and structure of Annex A controls depend on the edition cited. The composition of a control set varies with scope, applicable criteria or requirements, and the decisions of the auditor or certification body, and it defines the boundary of what is assessed rather than any guarantee of security beyond that boundary.
Why it matters
The control set is the operational heart of any compliance engagement because it defines exactly what will be assessed and, by extension, what will not. In a SOC 2 examination, the controls a service organization maps to the applicable Trust Services Criteria determine the boundary of the CPA firm's evaluation; in an ISO/IEC 27001 context, the controls selected through the Statement of Applicability, informed by risk assessment, establish which safeguards support the certified management system. Getting this selection right is what allows an organization to demonstrate that its safeguards actually align with the criteria or requirements that apply to its situation, rather than to a generic list borrowed from elsewhere.
A well-defined control set also frames expectations honestly. A SOC 2 report attests only to the controls and the review period it covers and does not guarantee freedom from breaches; an ISO 27001 certificate covers only the defined scope of the ISMS. When stakeholders misunderstand the control set, they can overstate what a report or certificate proves. Because the composition of a control set varies with scope, applicable criteria, and the judgment of the auditor or certification body, two organizations in the same industry may legitimately maintain very different control sets, and neither is inherently more 'complete' than the other outside its stated boundary.
The control set is also where the partial nature of framework mapping becomes visible. Because SOC 2's Trust Services Criteria and ISO 27001's Annex A reference controls are structured differently, a control set built for one framework typically satisfies the other only in part. Treating a single control set as universally sufficient can create a false sense of coverage, which is why organizations pursuing both attestation and certification usually reconcile their control sets deliberately rather than assuming equivalence.
Who it's relevant to
Inside Control Set
Common questions
Answers to the questions practitioners most commonly ask about Control Set.