Control attributes describe a measure using shared workspace catalogs. They support consistent filtering and comparison across policies.
Select catalog values
Open Policies, select the control in an editable version and choose Attributes. Expand the relevant group and select every value that applies. Selected values remain visible in the group's summary.
The ten groups cover business units, control categories, control functions, control types, functional domains, information security properties, operational capabilities, privacy control functions, security control baselines and security domains.
The completion indicator counts groups with at least one selection. It does not judge whether the selections are appropriate or prove that the control is implemented. Leave an unsupported classification unrecorded rather than selecting an arbitrary value to fill the indicator.
Choose Save changes for modified attributes, or Cancel to restore the saved selections. If a required choice is missing, ask an authorised workspace administrator to review its catalog in Databases.
Distinguish raw properties
The standalone Controls detail also contains Control properties, whose editor accepts a JSON object. That object is separate from these ten catalog relationships. Use Policies → Attributes for ordinary catalog classification; entering catalog labels into the raw object does not assign the corresponding relationships.