Skip to content
compliancebase
ISO 27001A.5 — Information transfer

A.5.14

Information transfer

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Maintain security of information transferred inside the organization and with external parties.

Points of focus

  • Approved transfer channels defined
  • Protection in transit
  • Rules for external recipients
  • Logging of sensitive transfers where feasible

Implementation notes

Ban ad-hoc personal email for production data. Prefer ticketed exports with expiry links and encryption. Document API and webhook transfer security. Align with A.8.24 cryptography and A.5.10 acceptable use. When GDPR applies, ensure transfers match lawful basis and processor instructions — link readers to Article 28/32 pages without claiming legal clearance.

Audit tip: Sample a support data export: channel used, approval, and whether encryption/access expiry applied.

Evidence auditors typically request:

  • Information transfer / data-handling procedure
  • TLS and secure file-share configuration
  • Support export approval tickets
  • Partner data-sharing agreements references

Common gaps

  • Customer data emailed as open CSV
  • Personal Gmail used for production exports
  • No guidance for AI tools pasting customer content

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.14This control

Primary sources

Frequently Asked Questions

Often for transit; still control who receives the file, retention, and whether the payload should have been exported at all.

Use a documented path with identity verification, least data, and secure delivery — do not improvise over chat.

Overlaps CC6.7 transmission restrictions; keep one transfer standard for both.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above