To answer your question, those attributes are not all required on the form element. From the docs on ngApp[1]:
Use this directive to auto-bootstrap an application. Only
one ngApp directive can be used per HTML document. The
directive designates the root of the application and is
typically placed at the root of the page.
The ngController directive gives behavior to a scope. So, in this example, the behavior of the LoginController is available to everything within the form element. ngController could be placed on a div that encapsulated the form and the result would be the same.The only thing really required on the form element for this example is the ngSubmit directive. The other two tags can be placed elsewhere.