Every kind of transfer facility, whether used inside the organization or with outside parties, is to be covered by rules, procedures or agreements for moving information. Purpose: keep information secure while it moves internally and to or from any external interested party. Guidance: a topic-specific transfer policy is set and shared with relevant parties; protection in transit reflects the classification of what is moved, and exchanges with third parties are governed by maintained transfer agreements that include authenticating the recipient (5.10). Transfer may be electronic, by physical media or spoken. For all forms the arrangements address: protection against interception, unauthorized access, copying, alteration, misdirection, destruction and denial of service, with access levels suited to the classification and extra measures such as encryption (8.24) for sensitive material; traceability and non-repudiation including chain of custody in transit; named contacts (owners, risk owners, security officers, custodians); incident responsibilities and liabilities, for instance lost media; an agreed, instantly understood labelling system (5.13); how dependable and available the transfer service is; acceptable use of transfer facilities (5.10); retention and disposal of business records including messages, noting local law; and other legal and contractual needs such as electronic signatures (5.31 to 5.34). Electronic transfer adds malware defence (8.7), protecting sensitive attachments, stopping misaddressed messages, approval before using public messaging, social, file-sharing or cloud services, stronger authentication over public networks, restrictions such as blocking automatic forwarding to external mail, advice against putting critical content in SMS or instant messages, and warnings about fax message stores and mis-programmed numbers. Physical media transfer adds responsibility for controlling and notifying dispatch and receipt, correct addressing, protective packaging per manufacturer guidance against heat, moisture and magnetic fields with minimum standards such as opaque envelopes, management-approved reliable couriers with identification standards and verification, tamper-evident or tamper-resistant containers by classification, approved transport providers by classification, and logs of content, protection, authorized recipients, handover and arrival times. Verbal transfer: remind people not to hold confidential conversations in public or on insecure channels, not to leave confidential voicemail, to ensure listeners are cleared to the right level, to use suitable rooms (closed doors, sound-proofing) and to open sensitive discussions by stating the classification and handling rules.
This control maps to 105 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 5.14 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 105 it maps to, and the evidence behind each claim, over MCP and REST.