

There are 93 distinct controls introduced in ISO/IEC 27002:2022. They are categorized as:
a) people, if they concern individual people;
b) physical, if they concern physical objects;
c) technological, if they concern technology;
d) otherwise they are categorized as organizational.
Control Taxonomy
Each control is associated with five attributes with corresponding attribute values (preceded by “#” to make them searchable), as follows:
- Control type: Preventive, Detective, and Corrective.
- Information security properties: Confidentiality, Integrity and Availability.
- Cybersecurity concepts: Identify, Protect, Detect, Respond and Recover.
- Operational capabilities: as the following list shows.
- Security domains: Governance_and_Ecosystem, Protection, Defence and Resilience
Operational Capabilities
- Governance
- Asset_management
- Information_protection
- Human_resource_security
- Physical_security
- System_and_network_security
- Application_security
- Secure_configuration
- Identity_and_access_management
- Threat_and_vulnerability_management
- Continuity
- Supplier_relationships_security
- Legal_and_compliance
- Information_security_event_management
- Information_security_assurance

Typo Corrected
The typo of #Information_security_assurance mentioned in 5.22 is corrected on March 24, 2022.

