Skip to main content
Category: Control Types and Framework

Control Set

Simply put

In a security compliance context, a control set is the collection of controls an organization selects and implements to meet the requirements of a given framework, such as SOC 2 or ISO/IEC 27001. It represents the specific safeguards chosen based on the organization's scope, risk assessment, and the criteria or requirements that apply to its situation.

Formal definition

A control set is the defined grouping of controls scoped for a particular compliance engagement or management system. In a SOC 2 examination, the control set comprises the controls a service organization maps to the applicable Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional additions selected by scope; the auditor evaluates suitability of design (Type I) or design and operating effectiveness over a review period (Type II). In an ISO/IEC 27001 context, the control set typically refers to the reference controls in Annex A that an organization selects via its Statement of Applicability, informed by risk assessment, alongside the certifiable ISMS requirements in clauses 4 through 10; the number and structure of Annex A controls depend on the edition cited. The composition of a control set varies with scope, applicable criteria or requirements, and the decisions of the auditor or certification body, and it defines the boundary of what is assessed rather than any guarantee of security beyond that boundary.

Why it matters

The control set is the operational heart of any compliance engagement because it defines exactly what will be assessed and, by extension, what will not. In a SOC 2 examination, the controls a service organization maps to the applicable Trust Services Criteria determine the boundary of the CPA firm's evaluation; in an ISO/IEC 27001 context, the controls selected through the Statement of Applicability, informed by risk assessment, establish which safeguards support the certified management system. Getting this selection right is what allows an organization to demonstrate that its safeguards actually align with the criteria or requirements that apply to its situation, rather than to a generic list borrowed from elsewhere.

A well-defined control set also frames expectations honestly. A SOC 2 report attests only to the controls and the review period it covers and does not guarantee freedom from breaches; an ISO 27001 certificate covers only the defined scope of the ISMS. When stakeholders misunderstand the control set, they can overstate what a report or certificate proves. Because the composition of a control set varies with scope, applicable criteria, and the judgment of the auditor or certification body, two organizations in the same industry may legitimately maintain very different control sets, and neither is inherently more 'complete' than the other outside its stated boundary.

The control set is also where the partial nature of framework mapping becomes visible. Because SOC 2's Trust Services Criteria and ISO 27001's Annex A reference controls are structured differently, a control set built for one framework typically satisfies the other only in part. Treating a single control set as universally sufficient can create a false sense of coverage, which is why organizations pursuing both attestation and certification usually reconcile their control sets deliberately rather than assuming equivalence.

Who it's relevant to

Compliance and GRC Managers
These professionals define and maintain the control set that governs an engagement. They align selected controls to the applicable Trust Services Criteria or Annex A reference controls, coordinate the Statement of Applicability in an ISO 27001 context, and ensure the control set reflects the organization's actual scope and risk decisions rather than a generic template.
Auditors and Certification Bodies
For a SOC 2 examination, the CPA firm evaluates the control set against the applicable criteria, assessing suitability of design (Type I) or design and operating effectiveness over a review period (Type II). For ISO 27001, an accredited certification body assesses the ISMS and the selected controls within the defined scope. In both cases, the control set frames precisely what the professional is and is not expressing an opinion on.
Security Engineers and Control Owners
These individuals implement and operate the specific safeguards within the control set. Their work produces the evidence that demonstrates whether a control is designed suitably and, for a SOC 2 Type II or an ISMS, operating effectively over time within the scoped boundary.
Organizations Pursuing Both SOC 2 and ISO 27001
Teams working toward both a SOC 2 report and an ISO 27001 certificate must reconcile their control sets deliberately. Because mapping between the frameworks is partial and satisfying one does not automatically satisfy the other, understanding how each control set is scoped helps avoid assuming coverage that does not exist.

Inside Control Set

Control Objectives or Criteria
The intended outcomes each control is designed to achieve. In a SOC 2 examination, controls are mapped to the Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on scope. In an ISO/IEC 27001 context, controls support the ISMS requirements in clauses 4 through 10 and are drawn from the Annex A reference controls.
Individual Controls
The specific safeguards, activities, or mechanisms (for example, access provisioning, change management, logging, or encryption practices) that make up the set. The precise composition depends on the framework, the scope, and the risk assessment rather than being a fixed universal list.
Scope and Boundary Definition
The systems, processes, locations, and time period the control set applies to. A SOC 2 report attests only to the controls and period covered; an ISO 27001 certificate covers only the defined scope of the ISMS. Controls outside the stated boundary are not addressed by the outcome.
Selection and Justification Basis
The rationale for including or excluding controls. Under ISO/IEC 27001, Annex A controls are selected via a Statement of Applicability informed by risk assessment. Under SOC 2, the controls chosen reflect scoping decisions and the Trust Services Criteria categories in scope.
Design and Operating Effectiveness Dimension
How the control set is evaluated. A SOC 2 Type I assesses the suitability of design at a point in time, while a SOC 2 Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions and varies.

Common questions

Answers to the questions practitioners most commonly ask about Control Set.

Is the SOC 2 control set the same as the ISO 27001 Annex A control set?
No. The two are distinct and should not be conflated. A SOC 2 control set is organized around the Trust Services Criteria, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on scope. An ISO/IEC 27001 control set draws on the Annex A reference controls, which are selected through a Statement of Applicability informed by risk assessment. Because the frameworks structure and describe controls differently, mapping between them is possible but only partial, and building a control set that satisfies one does not automatically satisfy the other.
Does having a defined control set guarantee that no breach will occur or that certification is automatic?
No. A control set describes the controls an organization has designed and intends to operate; it does not by itself guarantee freedom from breaches. In a SOC 2 examination, the resulting report attests only to the controls and the period covered, and in an ISO 27001 certification the certificate covers only the defined scope of the ISMS. A control set is an input to these outcomes rather than a guarantee of them, and its adequacy still depends on the auditor, the certification body, the scope, and the applicable criteria.
How do you decide which controls belong in the control set for a given engagement?
Selection typically flows from scope and, for ISO 27001, from the risk assessment. In a SOC 2 engagement, the control set is shaped by which Trust Services Criteria categories are in scope, Security is always included, and the optional categories are added depending on the services and commitments being assessed. In an ISO 27001 context, Annex A reference controls are considered and selected through the Statement of Applicability, with inclusions and exclusions justified against the results of the risk assessment. In most engagements the final set reflects the organization's environment rather than a fixed universal list.
How should a control set be documented so it holds up in an assessment?
Documentation typically links each control to the criterion or requirement it addresses, so an assessor can trace coverage. For ISO 27001, the Statement of Applicability records which Annex A reference controls are included or excluded and the rationale, and it ties back to the risk assessment. For SOC 2, controls are typically mapped to the relevant Trust Services Criteria. Clear ownership, descriptions of how each control operates, and evidence of operation help demonstrate both design and, where applicable, operating effectiveness. The exact expectations depend on the auditor or certification body and the applicable criteria.
Can one control set be used to support both a SOC 2 report and an ISO 27001 certificate?
In many organizations a common underlying control environment supports work toward both frameworks, and mapping between them is often used to reduce duplicated effort. However, that mapping is partial. A control set arranged for the Trust Services Criteria will not align one-to-one with Annex A reference controls, and the ISO 27001 ISMS requirements sit outside Annex A. Depending on scope, additional or restated controls may be needed for each framework, and satisfying one does not automatically satisfy the other.
How is a control set maintained over time rather than treated as a one-time exercise?
A control set is typically reviewed and updated as scope, risks, and the environment change. In an ISO 27001 context the Statement of Applicability and control selection are revisited in step with the risk assessment and the ongoing operation of the ISMS. In a SOC 2 context, controls need to operate over the review period for a Type II examination, so their continued operation and any changes are tracked across that period, whose length is set by scoping decisions rather than fixed. In most engagements maintenance also accounts for framework revisions, since control references and counts depend on the edition in use.

Common misconceptions

A single, standardized control set exists that satisfies both SOC 2 and ISO/IEC 27001 at once.
The two frameworks are distinct: SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18 resulting in a report, while ISO/IEC 27001 is a certification issued by an accredited certification body against a management system standard. Mapping between the two control sets is possible but only partial, and satisfying one does not automatically satisfy the other.
The SOC 2 Trust Services Criteria and the ISO 27001 Annex A controls are the same set of controls.
They are separate constructs. The Trust Services Criteria organize SOC 2 around Security (Common Criteria) plus optional categories, whereas Annex A provides reference controls selected through a Statement of Applicability. They should not be conflated, and control counts differ by edition, for example, Annex A was restructured in the 2022 revision into four themes, differing from the earlier 2013 version.
Implementing a defined control set guarantees the organization is secure and free from breaches.
A control set attests only to the controls and, for a Type II, the period covered within the defined scope. It does not guarantee freedom from breaches, and it says nothing about systems or activities outside the stated boundary.

Best practices

Define and document the scope and boundary of the control set explicitly, since both a SOC 2 report and an ISO 27001 certificate address only what falls within the stated scope and period.
Base control selection on a documented risk assessment; for ISO/IEC 27001, record inclusions and exclusions in the Statement of Applicability rather than adopting Annex A wholesale.
Map controls to the applicable criteria before an engagement, the Trust Services Criteria categories in scope for SOC 2, or the ISMS requirements in clauses 4 through 10 for ISO 27001.
Specify the framework edition when referencing Annex A control counts, since precise numbers depend on the version (for example, the 2022 revision restructured the controls into four themes).
When pursuing both frameworks, treat any crosswalk between SOC 2 and ISO 27001 as partial and validate each control against its native framework rather than assuming equivalence.
For a SOC 2 Type II, confirm the review period with the CPA firm during scoping, recognizing that the period length varies and is a scoping decision rather than a fixed duration.