ISO 27001A.5 — Labelling of information
A.5.13
Labelling of information
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Label information according to the classification scheme so handling requirements are apparent.
Points of focus
- Labelling methods defined per medium
- Automated labels where feasible
- Handling of unmarked information
- Labels preserved through transfer
Implementation notes
Use platform features (sensitivity labels, ticket fields, bucket tags) before manual footer rituals. Define default handling for unmarked data (treat as Internal or higher). Ensure support export tools do not silently drop labels. Pair with A.5.14 transfer rules for email and tickets containing customer data.
Audit tip: Show a Confidential document with visible label and an export path that retains the mark.
Evidence auditors typically request:
- Labelling procedure
- Screenshots of header/footer or tool labels
- Export workflows that carry classification
- Exception process for unlabelled archives
Common gaps
- Scheme exists but Drive files unmarked
- Labels stripped when exporting CSVs
- Inconsistent free-text tags
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.13 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.13)
Frequently Asked Questions
No. Machine-readable labels and access controls can satisfy intent when people can still see classification in context.
Train against pasting Restricted data into chat; rely on DLP where available rather than labelling every message.
Prioritise active stores; document a backlog plan for archives that still hold customer data.