ISO27001:2022 – A5.13 Labelling of information
Introduction
There’s no point classifying information (as per A5.12 – Classification of information), but you don’t tell people about it too. That’s what ISO 27001 – A5.13 is all about… it’s a simple control, but one that is so often missed.
What does ISO 27001 – A5.13 require?
tandard states that:
“An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organisation.” (A5.13 Labelling of Information)
Why is this required?
When you created your classification scheme in A5.12 – Classification of Information, you defined how information should be categorised and handled. This control ensures that those classifications are made visible and understood by the people who interact with the data.
In short: there’s no point classifying information if you don’t apply the classification to the actual documents and assets.
What the auditor is looking for
The auditor will look for evidence that labels are being applied to information in a manner that corresponds with your classification scheme. These labels can be:
- Physical – e.g. tags on laptops or printed labels
- Digital – e.g. headers or footers in documents, or footers in emails
The auditor will also expect to see a documented procedure explaining how labelling is to be performed.
A good approach includes:
- Document templates with default classification labels (e.g. “Classification: Confidential” in employment contract footers)
- Email footers with automated classification labelling (set up via group policy)
Note that labelling can sometimes introduce risk — for example, labelling a file “Highly Confidential – Payroll Data” could attract unwanted attention during data transfers (see A5.14 Information Transfer). So be thoughtful in how and where labels are applied.
Q & A
How detailed should the label be?
The label should match your classification scheme from A5.12. It doesn’t have to be complex — just clear enough for the recipient or handler to understand how the information should be treated.
Who is responsible for labelling?
Initially, you are — as the person creating the classification scheme. You should work with each department to understand their document types and apply appropriate labels. After this setup, it’s the responsibility of the content creator to label the information correctly based on its classification.
This includes documents like:
- Employee contracts
- Supplier agreements
- Email templates
- Schematics and intellectual property
Is it possible to get this wrong?
If you implement clear and simple procedures aligned with your classification scheme, it’s hard to go wrong. The most common mistake is simply not doing it at all.
Difficulty rating
We rate this control a 1 out of 5. It requires minimal technical expertise. The most important task is to create clear procedures and collaborate with information owners to determine how labelling should be applied.
More questions?
Remember that ISO27001 controls are interconnected. Review our FAQ or linked controls for broader understanding. If you’re unsure how to implement labelling or integrate it with your classification scheme, reach out — we’re here to help.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.
