ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.13: Labelling of information

Procedures for labelling information are to be developed and put into effect in line with the classification scheme the organization has adopted. Purpose: make classifications visible to people and systems and support automated processing and management of information. Guidance: labelling procedures cover information and associated assets in every format, reflect the scheme from 5.12 and use labels that are easy to recognize. They explain where and how labels go, depending on the way people reach the information or handle the media, and can set when labelling is skipped (for example non-confidential material, to save effort), how to label information held or sent electronically, physically or otherwise, and what to do where labelling is technically impossible. Techniques include physical labels, headers and footers, metadata, watermarks and stamps. Digital information should carry metadata that supports identification, management and control, particularly for confidentiality, enables accurate searching, and lets systems act on the labels; procedures describe how metadata is attached, which labels apply and how data is handled, consistent with the information model and ICT architecture, and systems add further metadata as they process information. Staff and other interested parties are made aware of the procedures and trained to label and handle correctly. System output containing sensitive or critical information carries the right label. Other information: labels are central to information sharing; recording the creating process and time is useful; labels can also help attackers spot valuable assets; some systems protect everything at the highest level they may contain and label only on export.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 32 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

  • 0061 0061 Mark classified information with text-based markings
  • 0064 0064 Mark caveats as text with a classification
  • 0065 0065 Page and reference numbering on accountable material
  • 0068 0068 Apply the Recordkeeping Metadata Standard classification sub-property
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • SEC07-BP03 Automate identification and classification

SOC 2 · 2 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
  • ASBv3-DP-1 Discover, classify, and label sensitive data

C5 (Germany) · 1 control

  • C5-AM-06 Asset Classification and Labelling

CIS Controls v8 · 1 control

  • CIS-3.7 Establish and Maintain a Data Classification Scheme

CMMC 2.0 · 1 control

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

ISO 19011:2018 · 1 control

  • 6.4.7 Collecting and verifying information

ISO 27001:2022 · 1 control

  • 5.13 Labelling of information

ISO 27701:2019 · 1 control

  • 6.5.2 Information classification

ISO/IEC 38500:2024 · 1 control

  • 5.3 Value generation

MTCS (Singapore) · 1 control

  • 12.5 Data labelling/handling
  • NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission
  • 15.1.15.C.01 15.1.15.C.01 Query originator about unknown protective markings

PCI DSS 4.0 · 1 control

  • 9.4.2 9.4.2 Classification of media by data sensitivity

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.