Information security controls are often managed within organisations by different teams, through different records and via different processes. Access authorisations, supplier controls, incident response procedures, backup processes or awareness campaigns may be in place, but it is not always clear which risk each control addresses, which security objective it supports, and what evidence is used to monitor it.
ISO/IEC 27028 essentially focuses on enabling organisations to use the attributes and themes approach which has become more prominent with ISO/IEC 27002:2022 in a more systematic manner. Thanks to this approach, information security controls can be managed in conjunction with their relationships to risk, processes, responsibilities, security objectives, operational needs and traceability.
Why is ISO/IEC 27028 Important?
In organisations implementing ISO/IEC 27001, the selection, implementation, monitoring and regular review of controls are key components of the information security management system. During this process, it must be clearly demonstrated why controls are selected, which risks they mitigate and which records are used to track them.
ISO/IEC 27002:2022 provides guidance on the implementation of information security controls. The ISO statement notes that ISO/IEC 27002 sets out best practices and control objectives in key cybersecurity areas such as access control, cryptography, human resources security and incident response.
ISO/IEC 27028 provides guidance on the clearer and more consistent use of the control attributes set out in ISO/IEC 27002:2022 within an organisation. According to ISO’s online explanation, the standard serves as a general guide for the use of information security control attributes. Organisations may also define new control attributes tailored to their processes and needs when existing attributes are insufficient for their purposes. This structure makes it clearer what purpose the controls serve, which security area they support, and which risk management need they address.
Key Features and Scope of ISO/IEC 27028
ISO/IEC 27028 focuses on the more systematic classification, use and management of information security controls through attributes. This framework makes control management more comprehensible, particularly in organisations where a large number of controls are implemented.
ISO/IEC 27002:2022 highlights five key attribute types used for controls:
- Control type: Indicates when and how the control affects the risk. It may be preventive, detective or corrective in nature.
- Information security attributes: These indicate the control’s contribution to confidentiality, integrity and availability.
- Cybersecurity concepts: These clarify the control’s function within cybersecurity management.
- Operational capabilities: These indicate which information security operation or capability the control relates to.
- Security domains: These highlight the control’s connection to security domains such as governance, protection, defence and resilience.
Thanks to these attributes, organisations do not merely track controls based on standard clauses. The control’s risk mitigation objective, process link, security objective, operational counterpart and reporting value can be seen more clearly.
ISO/IEC 27028 also guides organisations in creating custom attributes and values tailored to their own needs, rather than being limited to predefined attributes. Organisations can develop their own control attributes in line with their departmental structure, asset groups, process priorities, maturity level, critical services or regulatory obligations.
What Do Control Attributes Bring to an Organisation?
Information security controls serve different purposes. Some controls help prevent risk, some help detect incidents, and others contribute to taking corrective action following an incident. Similarly, a single control may relate to different areas such as confidentiality, integrity, availability, compliance, supplier management, incident response or business continuity.
This framework enables organisations to provide more structured answers to the following questions:
- Which risk does a control mitigate?
- Which information security objective does it support?
- Who is responsible for the control?
- To which process, asset or service is it related?
- How is the control’s effectiveness monitored?
- What records or evidence are used to track it?
- Are there any control gaps or weaknesses in the current framework?
Mapping controls against these attributes helps to identify gaps in risk treatment plans more easily. The organisation can assess more systematically which risks the existing controls address, in which areas they are concentrated, and where there is a need for improvement.
This framework also contributes to assessing the system’s resilience against potential control failures. It becomes clearer which risks might be left exposed should a control be disabled, function inadequately, or fail to produce the expected effect.
Relationship with ISO/IEC 27001 and ISO/IEC 27002
- ISO/IEC 27001 defines the requirements for an information security management system. It sets out how an organisation should identify its risks, select controls to address those risks, monitor performance and continuously improve the system.
- ISO/IEC 27002 provides guidance on the implementation of information security controls. This guidance helps organisations to assess applicable controls more systematically when addressing information security risks.
- ISO/IEC 27028 focuses on the more effective use of control attributes within this framework. It provides a more structured approach to the selection, justification, classification, monitoring and reporting of controls.
Therefore, ISO/IEC 27028 should be regarded as a guidance standard that strengthens the management of information security controls, rather than a direct certification standard.
International sources indicate that work on ISO/IEC 27028 began in 2021 and focused on the need for guidance regarding the control attributes approach introduced by ISO/IEC 27002:2022.
According to ISO’s latest information, it is currently designated as ISO/IEC FDIS 27028. FDIS indicates that the standard is at the final draft stage and is undergoing the final approval process prior to official publication.
For Whom Is ISO/IEC 27028 of Critical Importance?
ISO/IEC 27028 is important for all organisations seeking to manage information security controls in a more structured and traceable manner. The ISO record states that the document is applicable to organisations of all types, sizes and structures.
- For organisations implementing ISO/IEC 27001, it helps establish stronger links between control selection, the statement of applicability, the risk treatment plan, audit records and management reporting.
- For information security managers, it provides a clearer indication of which risks, processes and security objectives the controls address.
- For internal audit teams and auditors, it helps to assess not only the existence of controls but also their effectiveness and their relationship to organisational risks.
- For risk management teams, it makes control gaps, control weaknesses and control dependencies more visible.
- For compliance and governance teams, it supports the establishment of stronger links between information security controls and regulatory requirements, standards, customer expectations and internal policy requirements.
- For cybersecurity and IT teams, it makes the relationship between technical controls and organisational risks, processes and management objectives clearer.
ISO/IEC 27028 is a current standard developed for the classification, assessment and management of information security controls based on their characteristics. It contributes to the clearer management of controls implemented under ISO/IEC 27001 and ISO/IEC 27002 through their relationship with risk, accountability, security objectives and processes.
At CFECERT, we provide training and certification services to help organisations establish a more traceable and robust control framework in the areas of information security, risk management, internal audits, compliance and certification. For further information, please contact us at info@cfecert.co.uk.