Information transfer
Purpose
Keep information secure when it is transferred within the organisation and to external parties.
How to meet this control
In short: Put rules, procedures and agreements in place for transferring information internally and externally.
- Step 01Publish an information transfer policy covering email, file sharing, removable media, physical post and verbal disclosure
- Step 02Mandate encryption for confidential transfers and provide approved tools (secure file share, encrypted email, SFTP)
- Step 03Use transfer agreements or DPAs with external parties and define liability if a transfer incident occurs
- Step 04For physical media, require approved couriers, tamper-evident packaging and transfer logs with chain of custody
- Step 05Guard electronic transfer against misaddressing and malware with DLP rules, recipient verification and attachment scanning
Tip: Cover email, file sharing and physical media; require encryption for confidential transfers.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Establish and communicate a topic-specific policy on information transfer covering electronic, physical media and verbal channels
- ›Set up rules, procedures or agreements that reflect the classification of the information involved, and consider the reliability and availability of the transfer method itself
- ›Protect transferred information against interception, unauthorised access, copying, modification, misrouting and destruction, using cryptography where the sensitivity warrants it
- ›Ensure traceability and non-repudiation, including a chain of custody while information is in transit
- ›Identify the contacts responsible for each transfer, such as information owners and security staff, and define responsibilities and liabilities if a transfer incident occurs
- ›Label sensitive information in an agreed way so recipients immediately understand the handling required, and set retention and disposal rules for business records including messages
- ›For electronic transfer, guard against malware, misaddressing, automatic forwarding and weak authentication on public networks, and require approval before staff use external public messaging or file sharing services
- ›For physical media use approved couriers, protective tamper-evident packaging and transfer logs, and for verbal transfer avoid confidential conversations where they can be overheard and check listeners are cleared to hear them
Audit evidence to keep
- - Information transfer policy covering electronic, physical and verbal transfer
- - Transfer agreements or DPAs with external parties exchanging data
- - Evidence that encryption is enforced for confidential transfers
- - Transfer logs or chain-of-custody records for physical media
Common mistakes
- - Classifying data once and never reviewing it
- - Allowing sensitive data into test or AI tools without approval
- - Keeping data after the business or legal need has expired
Owner, cadence, and proof
Assign one accountable owner for A.5.14. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.