Skip to content
compliancebase
ISO 27001A.5 — Labelling of information

A.5.13

Labelling of information

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Label information according to the classification scheme so handling requirements are apparent.

Points of focus

  • Labelling methods defined per medium
  • Automated labels where feasible
  • Handling of unmarked information
  • Labels preserved through transfer

Implementation notes

Use platform features (sensitivity labels, ticket fields, bucket tags) before manual footer rituals. Define default handling for unmarked data (treat as Internal or higher). Ensure support export tools do not silently drop labels. Pair with A.5.14 transfer rules for email and tickets containing customer data.

Audit tip: Show a Confidential document with visible label and an export path that retains the mark.

Evidence auditors typically request:

  • Labelling procedure
  • Screenshots of header/footer or tool labels
  • Export workflows that carry classification
  • Exception process for unlabelled archives

Common gaps

  • Scheme exists but Drive files unmarked
  • Labels stripped when exporting CSVs
  • Inconsistent free-text tags

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.13This control

Primary sources

Frequently Asked Questions

No. Machine-readable labels and access controls can satisfy intent when people can still see classification in context.

Train against pasting Restricted data into chat; rely on DLP where available rather than labelling every message.

Prioritise active stores; document a backlog plan for archives that still hold customer data.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above