Procedures for labelling information are to be developed and put into effect in line with the classification scheme the organization has adopted. Purpose: make classifications visible to people and systems and support automated processing and management of information. Guidance: labelling procedures cover information and associated assets in every format, reflect the scheme from 5.12 and use labels that are easy to recognize. They explain where and how labels go, depending on the way people reach the information or handle the media, and can set when labelling is skipped (for example non-confidential material, to save effort), how to label information held or sent electronically, physically or otherwise, and what to do where labelling is technically impossible. Techniques include physical labels, headers and footers, metadata, watermarks and stamps. Digital information should carry metadata that supports identification, management and control, particularly for confidentiality, enables accurate searching, and lets systems act on the labels; procedures describe how metadata is attached, which labels apply and how data is handled, consistent with the information model and ICT architecture, and systems add further metadata as they process information. Staff and other interested parties are made aware of the procedures and trained to label and handle correctly. System output containing sensitive or critical information carries the right label. Other information: labels are central to information sharing; recording the creating process and time is useful; labels can also help attackers spot valuable assets; some systems protect everything at the highest level they may contain and label only on export.
This control maps to 32 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 5.13 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.