ISO27001:2022 – A5.14 Information transfer
Annex 5.14 Information Transfer
As we’ve seen many times, ISO27001 controls rarely exist in isolation. Following on from A5.12 (Classification of Information) and A5.13 (Labelling of Information), ISO27001 requires organisations to carefully plan and control how information is transferred and that’s what ISO 27001 – A5.14 is all about.
What does ISO 27001 – A5.14 require?
The standard states that:
“Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organisation and between the organisation and other parties.” (ISO 27001 – A5.14 -Information Transfer)
Why is this required?
To maintain the security of information transferred both internally and externally, appropriate controls must be in place. Information ‘in transit’ is at its highest risk of loss or compromise. Based on the classification assigned in A5.12, you must apply suitable safeguards to protect data from:
- Disclosure
- Interception
- Copying
- Misrouting
- Destruction
- Modification
Why is this important?
We’ve seen organisations who haven’t considered this important control get it so very wrong. We’ve seen information placed in the wrong envelopes and sent to the wrong address. Not just ANY information… we’re talking about medical records. We’re talking about financial records sent to the neighbours house, and thereby revealing sensitive commercial information about a person.
We once worked with an organisation who had a major breach because they didn’t use a reputable courier, and the courier lost a huge amount of data when it fell out of the back of their (unlocked) van!! Hundreds of personal health records was spread over several lanes on the M1, when the doors opened… and it all fell out!!!
HOW you transfer data is of vital importance (and that includes WHO does the transferring!)
What the auditor is looking for
This control explicitly requires that information transfer rules, procedures, or agreements be in place. The auditor will expect to see:
- A topic-specific policy related to Information Transfer
- Procedures outlining how information will be transferred
- Supplier contracts or agreements specifying information handling and transfer expectations
Information transfer includes:
- Electronic – email, file transfers, cloud sharing
- Physical – printed records, USBs, postal delivery
- Verbal – in-person or over the phone conversations
The Information Transfer Policy
Your policy should cover electronic, physical, and verbal forms of information. For example:
- Emails containing “Confidential” information must be encrypted
- Physical records should be sent via recorded delivery
- Verbal discussions of classified information should only occur in secure locations
Procedures
Procedures provide the detailed steps. Examples might include:
- How to encrypt and digitally sign emails
- Use of delivery or read receipts
- Process for handling physical mail, including logging and selecting couriers
Agreements
Supplier contracts should explicitly state how data may or may not be transferred. This may include:
- Direct access to internal systems only
- No data export without written approval
- Obligations to use encryption or secure channels
Q & A
Do I need a written policy?
Yes. A topic-specific policy is essential as audit evidence. Procedures and agreements should support this policy depending on your business needs. It shows how information should be handled as it flows in and out of your organisation.
Is it possible to get this wrong?
The biggest mistake is ignoring the control entirely. Even internal sharing is considered information transfer. Think about how data moves across your organisation and document how you mitigate risks throughout its journey.
Difficulty rating
We rate this a 1 out of 5. You don’t need technical skills to implement this — just a clear understanding of how information flows through your organisation and how to protect it.
More questions?
As with all ISO27001 controls, this one interrelates with others. Review our FAQ or reach out for help with developing your Information Transfer Policy, procedures, or agreements.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.
