ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.14: Information transfer

Every kind of transfer facility, whether used inside the organization or with outside parties, is to be covered by rules, procedures or agreements for moving information. Purpose: keep information secure while it moves internally and to or from any external interested party. Guidance: a topic-specific transfer policy is set and shared with relevant parties; protection in transit reflects the classification of what is moved, and exchanges with third parties are governed by maintained transfer agreements that include authenticating the recipient (5.10). Transfer may be electronic, by physical media or spoken. For all forms the arrangements address: protection against interception, unauthorized access, copying, alteration, misdirection, destruction and denial of service, with access levels suited to the classification and extra measures such as encryption (8.24) for sensitive material; traceability and non-repudiation including chain of custody in transit; named contacts (owners, risk owners, security officers, custodians); incident responsibilities and liabilities, for instance lost media; an agreed, instantly understood labelling system (5.13); how dependable and available the transfer service is; acceptable use of transfer facilities (5.10); retention and disposal of business records including messages, noting local law; and other legal and contractual needs such as electronic signatures (5.31 to 5.34). Electronic transfer adds malware defence (8.7), protecting sensitive attachments, stopping misaddressed messages, approval before using public messaging, social, file-sharing or cloud services, stronger authentication over public networks, restrictions such as blocking automatic forwarding to external mail, advice against putting critical content in SMS or instant messages, and warnings about fax message stores and mis-programmed numbers. Physical media transfer adds responsibility for controlling and notifying dispatch and receipt, correct addressing, protective packaging per manufacturer guidance against heat, moisture and magnetic fields with minimum standards such as opaque envelopes, management-approved reliable couriers with identification standards and verification, tamper-evident or tamper-resistant containers by classification, approved transport providers by classification, and logs of content, protection, authorized recipients, handover and arrival times. Verbal transfer: remind people not to hold confidential conversations in public or on insecure channels, not to leave confidential voicemail, to ensure listeners are cleared to the right level, to use suitable rooms (closed doors, sound-proofing) and to open sensitive discussions by stating the classification and handling rules.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 105 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 9 controls

  • 6.10.2 Information transfer
  • 7.4.9 PII transmission controls
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 7.5.3 Records of transfer of PII
  • 8.2 Conditions for collection and processing
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.3 Records of PII disclosure to third parties

SOC 2 · 7 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
  • SOC2-PI1.4 PI1.4 Controls over output delivery
  • ISM-0240 Paging, SMS and messaging apps for sensitive data
  • ISM-0269 Caveated email and distribution lists
  • ISM-0347 Write-once media for cross-domain transfers
  • ISM-0663 Data transfer processes and procedures
  • ISM-1586 Logging all data imports and exports

NIST SP 800-53 Rev 5 · 5 controls

CIS Controls v8 · 4 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-3.10 Encrypt Sensitive Data in Transit

FedRAMP High · 4 controls

  • AC-21 Information Sharing
  • CA-3 Information Exchange
  • MP-5 Media Transport
  • SC-8 Transmission Confidentiality and Integrity

FedRAMP Moderate · 4 controls

  • AC-21 Information Sharing
  • CA-3 Information Exchange
  • MP-5 Media Transport
  • SC-8 Transmission Confidentiality and Integrity

NIST SP 800-161 Rev 1 · 4 controls

PCI DSS 4.0 · 4 controls

  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 4.2.1 4.2.1 Strong cryptography safeguards PAN over public networks
  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ANSSI-HYG-18 Encrypt Sensitive Data Transmitted Over the Internet
  • ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners
  • ASD37-14 Block spoofed emails (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • CCM-DCS-04 Secure Media Transportation Policy and Procedures
  • CCM-DSP-10 Sensitive Data Transfer
  • CCM-IPY-03 Secure Interoperability and Portability Management

ETSI EN 303 645 · 3 controls

  • Provision 5.5-6 Critical security parameters encrypted in transit
  • Provision 5.5-7 Confidentiality of critical parameters over remotely accessible interfaces
  • Provision 5.8-1 Personal data in transit to associated services protected

NIST SP 800-171 Rev 3 · 3 controls

  • 0075 0075 Share classified information outside the entity only with clearance and need-to-know
  • 0076 0076 Apply the Commonwealth-State MOU when sharing with states and territories
  • 0077 0077 Agreement in place before sharing classified information outside government

APPI · 2 controls

  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A28 Provision to Third Parties in Foreign Countries
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • ASBv3-NS-9 Connect on-premises or cloud network privately
  • DP-3 Encrypt sensitive data in transit

C5 (Germany) · 2 controls

  • C5-COS-08 Policies for data transmission
  • C5-CRY-02 Encryption of data for transmission (transport encryption)

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 27018:2019 · 2 controls

  • 13.2 Information transfer
  • 13.2.1 Information transfer policies and procedures

ISO/IEC 42001:2023 · 2 controls

  • A.7 Data for AI systems
  • A.8 Information for interested parties of AI systems

MTCS (Singapore) · 2 controls

  • 17.5 Electronic messaging security
  • 23.11 Communication with cloud users

NIST SP 800-66 Rev 2 · 2 controls

PTES · 2 controls

  • PTES-2.3 Encrypt sensitive communications and the final report in transit
  • PTES-5.3 Protect credentials and sensitive content in the report
  • SEC.EIT Encryption in transit with TLS 1.3 at minimum
  • MYHR-CUD-4 Records not held or taken outside Australia
  • AEO-9 Information Exchange, Access and Confidentiality

DORA · 1 control

GDPR · 1 control

ISO 27001:2022 · 1 control

  • 5.14 Information transfer

ISO 27017:2015 · 1 control

  • 13.2 Information transfer

ISO/IEC 27010:2015 · 1 control

  • 27010-13.2 Information transfer

ISO/IEC 27037:2012 · 1 control

  • 6.9.4 6.9.4 Transporting potential digital evidence

ISO/IEC 27043:2015 · 1 control

  • ISO27043-30 Information transfer policies

ISO/SAE 21434 · 1 control

  • ISO21434-30 Information transfer policies

NIS2 Directive · 1 control

  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

NIST SP 800-172 · 1 control

  • 3.1.3e Employ Secure Information Transfer Solutions

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.14 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 105 it maps to, and the evidence behind each claim, over MCP and REST.