In this guide you will learn how to implement ISO 27001 Annex A 5.13 Labelling Of Information and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.13 is an ISO 27001 control that requires an organisation to label information in line with the information classification scheme of the organisation.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.13 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.13
- ISO 27001 Templates
- How to comply
- How to audit ISO 27001 Annex A 5.13
- What the auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.13 FAQ
- Related ISO 27001 Controls and Further Reading
- ISO 27001 controls and attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.13 is a to ensure you facilitate the communication of classification of information and support automation of information processing and management.
The ISO 27001 standard defines ISO 27001 Annex A 5.13 as:
An appropriate set of procedures for information labelling should be developed and implemented in accordance with the information classification scheme adopted by the organisation.
ISO 27001:2022 Annex A 5.13 Labelling Of Information
ISO 27001 Starter Kit – ($97)
Instant download of the mandatory ISO 27001 ISMS and Polices. Auditor verifed and certification body aprroved, downloaded 5.000+ times globablly to achieve ISO 27001 certification first time.
FREE ISO 27001 Annex A 5.13 Training Video
In this free training video you will learn How to implement ISO 27001 Labelling Of Information (Annex A 5.13) and Pass Your Audit.
Implementation Guide
The prerequisite for the this annex a control is having an information classification scheme in place. We covered information classification in – ISO 27001 Annex A 5.12 Classification of Information Beginner’s Guide
Once you have your classification scheme in place you are going to then label information and assets accordingly.
You are going to have to
- Implement procedures for information labelling
- Cover information and other associated assets in all formats
It is good practice to consider where labelling is omitted such as the case of non confidential information so that we can reduce the workload on people.
The procedures that you write should give guidance on where and how labels are attached and the different types of storage media. You will look at how to label information sent by or stored on physical, electronic and because the standard likes to catch everything, on what it helpfully calls ‘any other format’. Nothing like future proofing for the unknowns.
Of course there may be situations where labelling is not possible, and this is fine, as long as you have covered how to handle those cases. How you handle it may be to tag it with meta data or put in place some other compensating controls such as having an exception list and managing it via risk management.
When you have your labelling processes and procedures you are going to train staff on how to use and follow them and be able to evidence that you did so.
Examples of labelling techniques
Examples of labelling techniques can include:
- Headers and footers
- Metadata
- Physical Labels
- Watermarks
- Rubber Stamps – if you are proper old school
Metadata
Now the standard starts to stray into implementation territory with its guidance on metadata. Metadata has its place but we have to look at the appropriateness of the control to our risk and our organisation. Remember that the annex controls are guidance for consideration and you do not HAVE to implement them, only consider them, so if metadata is not appropriate for you that is fine, just note it down and manage it via your risk management process, accepting the risk.
Where it does apply and makes sense then you are looking at metadata to identify, manage and control information, especially in relation to confidentiality. It can help if it also makes it more efficient for searching for information but you can see here how the standard starts to tell you what to do not what is expected of you. Metadata searching for example is going to be reliant on specific technologies and implementations.
If you are using metadata then your procedures are going to describe how to attach metadata to information, what labels to use and how data should be handled. You are now moving into the realm of massive ball ache territory for your fellow colleagues so think carefully and act proportionately.
ISO 27001 Information Labelling Policy Template
For labelling you need to have information classification in place first. The information classification and handling policy sets out your approach to information classification and how you handle and label data and assets for each classification.

Information Classification Summary Template
The information classification summary is a quick reference, one page guide to the classification levels and what must be done for each classification as well has how you label it.

How to implement ISO 27001 Annex A 5.13
Implementing ISO 27001 Annex A 5.13 requires a transition from simple data categorisation to a technical enforcement layer where every piece of information is visibly or digitally marked. As a Lead Auditor, I look for “The Marking Gap,” which is the space between your classification policy and the actual appearance of labels on your assets. This guide provides the action-result steps necessary to ensure your labelling scheme is audit-ready and technically robust.
1. Formalise the Information Labelling Policy
- Develop a formalised policy that defines how every classification tier (Public, Internal, Confidential, Secret) is visually and technically represented.
- Assign specific responsibilities to Information Asset Owners to ensure they are accountable for the labelling of data under their jurisdiction.
- Ensure the policy explicitly covers all formats, including digital files, physical printouts, and portable storage media.
2. Define Visual Labelling Standards
- Define standardised headers, footers, and watermarks for digital documents to ensure classification levels are immediately apparent to users.
- Create visual templates for emails and slide decks that force the inclusion of a classification marker before distribution.
- Establish clear colour-coding or iconography for physical files and media to simplify identification in a physical office environment.
3. Configure Technical Metadata Tags
- Configure metadata properties within your productivity suites (such as Microsoft 365 or Google Workspace) to embed classification tags directly into file properties.
- Ensure that metadata tags are persistent, meaning the label remains attached even when the file is renamed or moved to different storage tiers.
- Enable technical tagging for databases and structured data to allow automated systems to identify sensitive records.
4. Provision Data Loss Prevention (DLP) Software
- Provision a Data Loss Prevention (DLP) solution that scans for technical metadata tags to prevent unauthorised sharing of sensitive information.
- Set up automated alerts and blocking rules that trigger when a user attempts to upload a “Confidential” or “Secret” labelled file to a public cloud or external drive.
- Result: Technical enforcement of labels significantly reduces the risk of accidental data exfiltration.
5. Apply Physical Labels to Hardware and Media
- Apply tamper-evident classification labels to physical hardware, including laptops, servers, and removable backup drives.
- Ensure that “Secret” or high-risk media is stored in labelled, secure containers within restricted zones to meet physical security requirements.
- Include classification markings on backup tapes and archived hard copies to ensure consistent protection during long-term storage.
6. Synchronise Labels with the Data Asset Register
- Synchronise every labelled asset with your centralised Data Asset Register (A.5.9) to ensure the classification level matches the inventory record.
- Update the register dynamically whenever an asset is re-labelled or its classification status is modified.
- Result: Auditors can verify the integrity of your classification scheme by cross-referencing physical labels with digital records.
7. Enshrine Handling Rules in ROE Documents
- Enshrine specific handling requirements in your Rules of Engagement (ROE) documents for every label type, such as “Confidential data must be encrypted in transit.”
- Link labelling directly to access control by requiring Multi-Factor Authentication (MFA) for any system housing data labelled “Internal” or higher.
- Define specific disposal methods for each label, such as cryptographic wiping for digital media or cross-cut shredding for labelled paper.
8. Execute Role-Based Labelling Training
- Execute mandatory training sessions that teach employees how to apply labels using your chosen technical tools and visual standards.
- Provide specific guidance for high-risk roles, such as HR or Finance, where the volume of “Confidential” labelled data is highest.
- Verify employee understanding through simulated data handling tests to ensure labels are applied correctly in practice.
9. Audit the Compliance Marking Gap
- Audit your digital and physical repositories periodically to identify assets that are classified but unlabelled.
- Use automated discovery tools to scan for “Confidential” strings in files that lack the corresponding metadata tags.
- Result: Systematic auditing identifies control failures before they result in a non-conformity during a certification audit.
10. Review and Revoke Outdated Labels
- Review classification labels annually to determine if the sensitivity of the data has decreased over time.
- Revoke or downgrade labels for project data that has entered the public domain or lost its strategic value.
- Result: Proper lifecycle management prevents “Classification Creep” and reduces the administrative burden on your security team.
Check Your Work?
You buit it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let a trained ISO 27001 auditor check your work.

ISO 27001 Templates

How to comply
To comply with ISO 27001 Annex A 5.13 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Implement your classification scheme
- Implement your asset management and record all your assets in asset registers
- Write, implement and train people on your labelling processes and procedures
- Classify all of your assets and label them appropriately
- Decide if metadata is appropriate to you, to what level and implement to that
How to audit ISO 27001 Annex A 5.13
As an ISO 27001 Lead Auditor, I have conducted hundreds of audits where the “Label Gap” is the most frequent cause of non-conformity. It is one thing to classify data in a register, but quite another to ensure that every document, email, and database entry carries a clear, actionable marker. This 10-step audit framework is designed to help you probe the effectiveness of your labelling controls, verifying that your technical metadata and visual markers align with your Information Classification Policy to guarantee a successful certification outcome.
1. Define the Audit Scope and Sampling Criteria
- Identify the primary repositories of classified information, including cloud storage, local servers, and physical filing systems.
- Select a representative sample of assets from the Data Asset Register across all classification tiers: Public, Internal, Confidential, and Secret.
- Ensure the audit scope includes both structured data, such as databases, and unstructured data, such as ad hoc emails and chat logs.
2. Evaluate the Information Labelling Procedure
- Review the formalised labelling procedure to ensure it provides specific instructions for different media types and formats.
- Verify that the procedure defines responsibilities for labelling, specifically for the Information Asset Owner.
- Check that the labelling rules are consistent with the requirements of relevant laws, such as GDPR or the UK Data Act 2025.
3. Inspect Visual Labelling on Digital Documents
- Examine a sample of Confidential and Secret documents to verify the presence of clear visual markers, such as headers, footers, or watermarks.
- Confirm that the visual labels match the classification level recorded in the Data Asset Register for that specific file.
- Validate that templates for internal reports and presentations include pre-defined labelling fields to reduce human error.
4. Validate Technical Metadata and Automated Tagging
- Probe the file properties of sensitive documents to verify that classification metadata is correctly embedded.
- Check that automated labelling tools, such as those within Microsoft Purview or similar suites, are correctly applying tags based on content sensitivity.
- Ensure that metadata persists when files are converted between formats, such as moving from a Word document to a PDF.
5. Audit Email Transmission and Marking
- Inspect a sample of outgoing emails to verify that classification markers are included in the subject line or body when sensitive data is attached.
- Confirm that Data Loss Prevention (DLP) rules are configured to trigger warnings or blocks when unlabelled sensitive information is sent externally.
- Verify that encryption is automatically applied to emails carrying labels designated as Confidential or Secret.
6. Examine Physical Media and Hard Copy Controls
- Audit physical media, such as USB drives and backup tapes, to ensure they carry a permanent, visible classification label.
- Inspect printed reports containing sensitive data to verify that the classification is visible on every page, not just the cover.
- Verify that secure disposal bins are labelled and used correctly for the destruction of classified hard copies.
- Check that the Rules of Engagement (ROE) for physical handling are understood by staff working in high-security zones.
7. Probe Information Owner Accountability
- Interview selected Asset Owners to verify they have reviewed and authorised the labels applied to the assets under their control.
- Check that the Asset Owner has approved any deviations from standard labelling rules for specific technical or operational reasons.
- Review the Data Asset Register to ensure that labelling status is a documented field for every critical asset.
8. Test Staff Competency and Awareness
- Conduct random interviews with employees to test their understanding of the organisation’s labelling symbols and terminology.
- Ask employees to demonstrate how they would apply a label to a newly created Confidential asset.
- Review training logs to confirm that all staff have completed recent modules on Information Labelling and Annex A 5.13 requirements.
9. Verify Integration with Access Control Mechanisms
- Confirm that Identity and Access Management (IAM) roles are restricted based on the labels applied to data repositories.
- Verify that Multi-Factor Authentication (MFA) is required to access any system or folder containing data labelled as Confidential or Secret.
- Check that system logs record attempts to access or modify labelling metadata by unauthorised users.
10. Document Findings and Remediation Actions
- Formalise the audit results into a clear report, identifying any instances of the “Label Gap” where assets are unlabelled or mislabelled.
- Categorise non-conformities by risk level to prioritise the remediation of the most sensitive data exposures.
- Schedule a follow-up audit to verify that corrective actions, such as updated DLP rules or staff re-training, have been successfully implemented.
What the auditor will check
The audit is going to check a number of areas. Lets go through them
1. That you have implemented metadata
Remember where I said above the standard has a real hard on now for metadata, well you can bet your bottom dollar that auditors are going to go metadata obsessed. They love a literal interpretation of the standards as if it were handed down by god to Moses. If it is appropriate to you do it, of course. But there is cost in time, resources, money, technology that may just not be appropriate. And that is ok. Document what you are doing, cover it in risk management, have a record of your decision, and what ever level of implementation you do show that you accepted the risk. The argument will come that you have included the control in your SOA and that it applies to you and therefore all of it applies to you. This is partly correct in that you have considered that the control applies to you because labelling information that is confidential and marking information and being able to control information based on labelling makes sense but you did not necessarily sign up carte blanche to an enterprise level metadata solution. Be prepared to fight your corner, it is a risk based system, so manage the risk, don’t just implement controls where they make no sense.
2. That you have processes, have followed them and have trained people
This is obvious but they are going to look that you have documented what you say you do, that you follow it and that you have trained people.
3. Documentation
They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Doing anything else would be a massive own goal.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.13 are
1. Your information is not labelled
This is such an easy win for an auditor to check. You will put information in front of them. You will have forgotten to label something. This maybe a HR org chart, a presentation, a PDF, a Visio diagram. Something, somewhere that you have that is confidential will not have been labelled and you will either show it to the auditor or they will ask you for it. Sods law. Check everything before you get audited. Then check it again.
2. One or more members of your team haven’t done what they should have done
Prior to the audit check that all members of the team have done what they should have, understand how to label information and have been trained in it.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.13 FAQ
Yes, if your risk assessment identifies that information assets require classification to ensure secure handling, then labelling becomes a mandatory requirement under Annex A 5.13.
Essential for maintaining the Confidentiality, Integrity, and Availability of data.
Required to satisfy Clause 8.2 (Information Classification) in the 2013 standard and 5.12 in the 2022 standard.
A primary requirement for organisations handling PII, intellectual property, or government data.
The primary difference is that Annex A 5.12 (Classification) defines the hierarchy and levels of sensitivity, whereas Annex A 5.13 (Labelling) defines the visual or metadata markers used to communicate those levels.
Annex A 5.12: The “What” – Categorising data (e.g., Public, Internal, Secret).
Annex A 5.13: The “How” – The actual stickers, headers, footers, or tags applied to that data.
They are dependent controls; you cannot label information without a classification scheme in place.
Digital information should be labelled using a combination of visual markers and embedded metadata to ensure the classification persists regardless of how the file is shared.
Visual cues: Headers, footers, and watermarks within documents or emails.
Metadata: File properties or “X-headers” in emails that allow automated systems to enforce security.
Naming conventions: Including the classification level in the file or folder name.
Automation tools: Using software like Microsoft Purview or Google Workspace Labels.
Yes, physical information such as printed documents, removable media, and storage devices must be labelled to ensure they are handled correctly in non-digital environments.
Physical stickers or stamps on folders and envelopes.
Labels on USB drives, external hard drives, and backup tapes.
Markings on hardware that stores sensitive information.
Secure disposal instructions printed on highly classified physical assets.
Yes, automated labelling is highly recommended for large organisations as it reduces the risk of human error and ensures high levels of consistency.
Data Loss Prevention (DLP) tools can scan content for keywords and apply labels.
Email gateways can automatically tag outbound messages based on recipient domains.
Cloud storage platforms can apply default labels to specific folders or departments.
Automation ensures that “Confidential” content is never left unlabelled.
Auditors expect to see a documented Labelling Procedure and verifiable evidence that the policy is being followed in day-to-day operations.
The Information Labelling Policy/Procedure document.
Samples of labelled emails, spreadsheets, and physical documents.
Screenshots of automated labelling configurations in IAM or DLP tools.
Evidence of staff training and awareness regarding the labelling scheme.
Related ISO 27001 Controls and Further Reading
ISO 27001 controls and attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Protect | Information_protection | Defence |
| Integrity | Protection | |||
| Availability |
