ISO 27018:2019
Communications security – ISO 27018:2019

ISO 27018:2019 13.2.1: Information transfer policies and procedures

Extends ISO/IEC 27002:2013 13.2.1. When physical media carry transfers, a system records the media containing PII coming in and going out: the media type, the authorised sender and recipients, date and time, and how many items. Where possible customers are asked to add their own measures, such as encryption, so the data can be read only at its destination and not in transit.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 6 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 5.14 Information transfer

ISO 27017:2015 · 1 control

  • 13.2 Information transfer

ISO 27701:2019 · 1 control

ISO/IEC 27010:2015 · 1 control

  • 27010-13.2 Information transfer

ISO/IEC 27043:2015 · 1 control

  • ISO27043-30 Information transfer policies

ISO/SAE 21434 · 1 control

  • ISO21434-30 Information transfer policies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 6 it maps to, and the evidence behind each claim, over MCP and REST.