IEC DRAFT ISO International Standard ISO/IEC DIS 27028 Information security, cyber security ISO/IEC JTC1/SC 27 and privacy protection Guidance Secretariat: DIN on IS0/IEC 27002 attributes Voting begins on: 2025-01-15 ICS: 35.030 Voting terminates on: 2025-04-09 FORCOMMENTSANDAPPROVAL.IT ISTHEREFORE SUBIECTTO CHANGE AND MAY NOTBE REFERRED TO AS AN INTERNATIONAL STANDARD UNTIL BEING ACCEPTABLE FORINDUSTRIAL, TECHNOLOGICAL.COMMERCIAL AND MAYON OCCASION HAVETO This document is circulated as received from the committee secretariat. POTENTIAL TO BECOME STANDARDS TO NATIONALREGULATIONS F THIS DRAFT ARE INVITED WITH THEIR COMMENTS NOTIFICATION OF ANY RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE AND TO PROVIDESUPPORTING DOCUMENTATION. Reference number @ISO/IEC 2025 ISO/IEC DIS 27028:2025(en) IS0/IEC DIS 27028:2025(en) COPYRIGHT PROTECTED DOCUMENT @IS0/IEC2025 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or Iso's member body in the country ofthe requester. ISO copyright office CP 40i: Ch. de Blandonnet 8 CH-1214 Vernier, Geneva Phone: +41 22 749 01 11 Email:
[email protected] Website: www.iso.org Published in Switzerland @ IS0/IEC 2025 - All rights reserved i IS0/IEC DIS 27028:2025(en) Contents Page Foreword. .iv Introduction. 1 Scope. .1 2 Normative references 1 3 Terms and definitions 1 4 Abbreviated terms 2 5 Overview on attribute approach 2 5.1 Concept of attribute and its use 2 5.1.1 General. 5.1.2 Attributes given in IS0/IEC 27002:2022 2 5.1.3 Additionalattributesintroducedinthisdocument .2 5.2 Custom attributes 3 5.2.1 General 3 5.2.2 The method 4 5.3 Examples of using attributes. 4 5.3.1 General 4 5.3.2 Using attributes to create robust risk treatment plans 5 5.3.3 Other example of using attribute. .8 6 Additional attributes. 10 6.1 Security architecture attribute 11 6.2 Assurance attribute .11 6.3 Complexity attribute 12 6.4 Contextual-fit attribute 12 6.5 Control environment attribute 13 6.6 Failure modes attribute 13 6.7 Formality attribute. .14 6.8 Integration attribute 14 6.9 Mature attribute 14 6.10 Measurability attribute 15 6.11 Multi-functionality attribute 15 6.12 Origin attribute .16 6.13 Regulation attribute .16 6.14 Strength attribute. .17 6.15 Target attribute. 17 6.16 Transparency attribute. .17 6.17 Costattribute .18 6.18 Other custom controls and other custom attributes 19 Bibliography 20 @ IS0/IEC 2025 - All rights reserved iii IS0/IEC DIS 27028:2025(en) Foreword ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of IsO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with IsO and IEC, also take part in the work. In the field of information technology, ISO and IEC have established a joint technical committee, ISo/IEC JTC 1. The procedures used to develop this document and those intended for its further maintenance are described in the Iso/IEc Directives, Part 1. In particular the different approval criteria needed for the different types of documents should be noted. This document was drafted in accordance with the editorial rules of the IsO IEC Directives, Part 2 (see www.iso.org/directives). Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO and IEC shall no