ISO 27001A.5 — Information transfer
A.5.14
Information transfer
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Maintain security of information transferred inside the organization and with external parties.
Points of focus
- Approved transfer channels defined
- Protection in transit
- Rules for external recipients
- Logging of sensitive transfers where feasible
Implementation notes
Ban ad-hoc personal email for production data. Prefer ticketed exports with expiry links and encryption. Document API and webhook transfer security. Align with A.8.24 cryptography and A.5.10 acceptable use. When GDPR applies, ensure transfers match lawful basis and processor instructions — link readers to Article 28/32 pages without claiming legal clearance.
Audit tip: Sample a support data export: channel used, approval, and whether encryption/access expiry applied.
Evidence auditors typically request:
- Information transfer / data-handling procedure
- TLS and secure file-share configuration
- Support export approval tickets
- Partner data-sharing agreements references
Common gaps
- Customer data emailed as open CSV
- Personal Gmail used for production exports
- No guidance for AI tools pasting customer content
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.14 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.14)
Frequently Asked Questions
Often for transit; still control who receives the file, retention, and whether the payload should have been exported at all.
Use a documented path with identity verification, least data, and secure delivery — do not improvise over chat.
Overlaps CC6.7 transmission restrictions; keep one transfer standard for both.