ISO 27001:2022 Annex A 5.14 Information Transfer Explained

ISO 27001 Annex A 5.14 Information transfer

In this guide you will learn how to implement ISO 27001 Annex A 5.14 Information Transfer and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.14 is an ISO 27001 control that requires an organisation to have rules, procedures or agreements in place for all types of transfer within the organisation and with third parties.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.14 is to ensure that you maintain the security of information transferred within an organisation and with any external interested party.

The ISO 27001 standard defines ISO 27001 Annex A 5.14 as:

Information transfer rules, procedures, or agreements should be in place for all types of transfer facilities within the organisation and between the organisation and other parties.

ISO 27001:2022 Annex A 5.14 Information Transfer

FREE ISO 27001 Annex A 5.14 Training Video

In this free training video you will learn How to implement ISO 27001 Information Transfer (Annex A 5.14 ) and Pass Your Audit.

Implementation Guide

The prerequisite for the this annex a control is having an information classification scheme in place. We covered information classification in – ISO 27001 Annex A 5.12 Classification of Information Beginner’s Guide

Once you have your classification scheme in place you are going to then implement rules, procedures and agreements to protect information in transit based on its classification and the classification scheme you have established.

You are going to have to

  • Establish and communicate a topic specific policy on information transfer
  • Implement rules, procedures and/ or agreements for information transfer to protect information in transit
  • Cover information and other associated assets in all formats

Remembering that information transfer can be done in many ways including through electronic transfer, physical storage media transfer and even verbal transfer.

Let us explore what the standard is expecting for each transfer method.

All information transfers

For all information transfer

  • Implement controls proportionate to the information classification and business risk to protect against destruction, interception, unauthorised access, copying, modification – basically to protect the confidentiality, integrity and availability of the information.
  • Put in place the ability to ensure traceability and the fancy word of non repudiation which includes a chain of custody wile in transit. Do you know who had it and what they did with it and can you prove it if you need to?
  • The standard loves having owners so you will have the usual suspects of data owners, risk owners and all the roles and responsibilities defined by the management system. Those involved in the transfer of information should really be defined along with their contact details.
  • Put in place who does what if there is a breach or an incident and who is going to be liable
  • Obviously as we covered in ISO 27001 Annex A 5.13 Labelling Of Information Beginner’s Guide – you are going to have information labelling.
  • In the top trumps of requirements the law always wins so clearly you will look at the legal register you have completed and look at relevant laws, regulations and contractual requirements that apply to you and follow them for information transfer.
  • Set out your guidelines on storage and deletion of business records, and messages.
  • Ensure the availability of the transfer service.

Electronic Transfers

There are some extra things you will have to do for electronic transfers. Nothing unusual but they are

  • Detect and protect against malware and viruses
  • If you use attachments and they include sensitive information – protect them.
  • When you send something to someone make sure it is the correct someone.
  • If you simply must use public means like instant messaging, get approval first. And then put in place some stronger measures and stricter authentication.
  • Tell people not to message or SMS critical information. You can tell them. They won’t listen. And no one can check as they are private. Still, be sure to tell them eh?

Fax Machines

I mean WTAF but still, people use them apparently. The standard is all nice and vague about advising people of the problems of using them. It omits the fact the main problem is this is not 1987 but still tell people about the problems. Apparently. The actual reality is if you do use them then you are controlling them through risk management and compensating controls.

Physical Storage Media Transfers

So we are going to move some physical media or paper about the place? If you must you must. But if you do then

  • Someone needs to be assigned responsibility for notifying it will happen, making it happen and getting a reciept that it happened. Nice work if you can get it.
  • Send it to the right person, in the right way, eh? I mean, come on.
  • Nothing stops a thief like a package so packaging is covered. Packaging has its place. Think amazon. Package that bad boy before you send it.
  • I am not a fan of Evri per se, but then this is not my call and other couriers are available so you need to have an agreed list. The standard says of reliable couriers. Which is hilarious. Just have a list of the least shit.
  • It wants you to have courier identification standards. Which is vague AF. Pick mainstreams ones and you will be ok. Or you could try asking – ‘are you a courier’ before handing over priceless data and if the answer is ‘er, yes’ then I think you are golden.
  • Log everything!

Verbal Transfers

Oh my sweet god, so we are in the realms of thought police. I wish you god speed with this one but lets look at what the standard believes people will do.

  • No confidential chit chats in public places!
  • No answer machine messages with that confidential data on. ‘Hi, this is Stuart, I am not available right now so please leave your confidential information after the beep……’
  • Screen people to the appropriate level to listen to the conversation – Bwhhahhh hhahhha hhhaaa
  • Have room controls in place like sound proofing – which is a little to 50 shades of grey for my liking. Please come into this sound proof room so I may whisper confidential information at you.
  • Begin any sensitive conversation with a disclaimer. Of course. Obvious really. Give it a try. People will love you for it.

The 3 transfer methods covered in ISO 27001

The 3 transfer methods of ISO 27001 that are now explicitly covered are

  • Electronic
  • Physical
  • Verbal

ISO 27001 Information Transfer Policy Template

The information transfer policy sets out your rules and approach for information transfers.

ISO 27001 Information Transfer Policy Template - ISO 27001 Annex A 5.14 Information Transfer Template
ISO 27001 Information Transfer Policy Template

How to implement ISO 27001 Annex A 5.14

1. Identify and Document all Transfer Facilities

Action: Conduct a thorough discovery exercise to map every method used to move data. Result: A comprehensive Asset Register that includes electronic channels, physical courier routes, and verbal communication paths.

  • Identify automated API feeds and Managed File Transfer (MFT) systems.
  • Document physical media transport protocols for hard drives or tapes.
  • Include cloud-based sharing platforms like SharePoint or Dropbox.

2. Establish a Formal Information Transfer Policy

Action: Draft and approve a topic-specific policy for information transfer. Result: Clear organisational rules that define acceptable and prohibited transfer methods for all staff.

  • Define classification levels for data allowed for external transfer.
  • Set mandatory security requirements for different types of information.
  • Establish clear disciplinary consequences for using unauthorised “Shadow IT” channels.

3. Provision Secure Communication Channels

Action: Implement technical safeguards for data in transit. Result: Technical assurance that data remains confidential and untampered during movement.

  • Enforce TLS 1.2 or higher for all web-based transfers.
  • Utilise AES-256 encryption for file-level protection.
  • Deploy Virtual Private Networks (VPNs) for site-to-site data synchronisation.

4. Formalise Information Transfer Agreements (ITAs)

Action: Execute legally binding agreements with third parties. Result: Enforceable security obligations that protect your data once it leaves your perimeter.

  • Include specific clauses for incident notification and data breach reporting.
  • Define the technical standards the recipient must maintain.
  • Specify the required protocols for data return or destruction upon contract termination.
  • Ensure ITAs are signed by both parties before any sensitive data movement occurs.

5. Implement Strict IAM Roles and Access Controls

Action: Apply the principle of least privilege to transfer systems. Result: Restricted access ensuring only authorised personnel can initiate or receive sensitive transfers.

  • Configure Identity and Access Management (IAM) roles specifically for transfer administrators.
  • Enforce Multi-Factor Authentication (MFA) for all external transfer portals.
  • Regularly review and revoke access for staff who no longer require transfer capabilities.

6. Secure Physical Media and Transit Routes

Action: Apply physical security controls to tangible data assets. Result: Protection against theft, loss, or tampering during the physical courier process.

  • Use tamper-evident packaging and serialised security seals.
  • Mandate the use of vetted, reputable couriers with GPS tracking and chain of custody logs.
  • Ensure all physical media is encrypted at rest before it leaves the secure facility.

7. Enforce Data Integrity Verification

Action: Deploy hashing and digital signature protocols. Result: Mathematical proof that the information received is identical to the information sent.

  • Generate SHA-256 checksums for large file transfers.
  • Utilise digital certificates to authenticate the identity of the sender and receiver.
  • Implement automated alerts for any transfer that fails integrity validation.
  • Maintain a log of all successful and failed integrity checks for audit evidence.

8. Monitor and Log all Transfer Activities

Action: Enable comprehensive auditing on all transfer facilities. Result: A forensic trail of “who, what, when, and where” for every piece of moved data.

  • Centralise logs in a Secure Information and Event Management (SIEM) system.
  • Monitor for unusual patterns, such as mass data exfiltration or unauthorised destination IPs.
  • Retain logs in accordance with your statutory and regulatory requirements.

9. Deliver Staff Awareness Training

Action: Train employees on secure transfer procedures. Result: A reduction in human error and a “human firewall” against social engineering or accidental leaks.

  • Provide specific guidance on the risks of verbal data disclosure in public spaces.
  • Train staff on how to use approved encrypted file-sharing tools correctly.
  • Educate employees on how to spot phishing attempts targeting transfer credentials.

10. Conduct Regular Compliance Audits

Action: Perform internal reviews of transfer controls and agreements. Result: Continuous improvement and the identification of control gaps before they lead to a breach.

  • Review a sample of Information Transfer Agreements annually for accuracy.
  • Perform penetration testing on external-facing transfer APIs and portals.
  • Verify that the Record of Processing Activities (ROPA) accurately reflects current transfer flows.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.14 Information Transfer Templates
ISO 27001 Templates

How to comply

To comply with ISO 27001 Annex A 5.14 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to

  • Get yourself a topic specific policy and communicate it
  • Implement your classification scheme
  • Define and Implement your procedures, rules and agreements for transfers
  • Communicate and make sure people follow said procedures, rules and agreements

How to audit ISO 27001 Annex A 5.14

1. Verify the existence and approval of a topic-specific Information Transfer Policy

Action: Request the latest version of the Information Transfer Policy and check for executive sign-off. Result: Ensure the organisation has established formalised rules that govern all internal and external data movements to prevent unauthorised disclosure.

  • Check that the policy covers electronic, physical, and verbal communication channels.
  • Confirm the policy defines prohibited transfer methods such as unauthorised cloud storage or personal email.
  • Validate that the policy is reviewed at least annually or upon significant changes to the technical environment.

2. Inspect the Asset Register for identified transfer facilities

Action: Cross-reference the Asset Register with the technical landscape to identify all transfer points. Result: Confirm that every electronic gateway, physical courier route, and automated API feed is documented and risk-assessed.

  • Verify that Managed File Transfer (MFT) systems and SFTP servers are listed.
  • Ensure that physical media transport assets are accounted for in the register.
  • Check for the inclusion of third-party cloud sharing platforms used for business operations.

3. Examine Information Transfer Agreements (ITAs) and NDAs

Action: Sample a selection of third-party contracts and Non-Disclosure Agreements. Result: Validate that legal and technical security requirements are baked into agreements to ensure the protection of data once it leaves the organisational perimeter.

  • Check for specific clauses regarding incident notification and data breach reporting.
  • Confirm the agreements specify the required encryption standards for the recipient.
  • Validate that procedures for data return or destruction upon contract termination are clearly defined.

4. Analyse cryptographic configurations for electronic transfers

Action: Perform a technical review of the encryption protocols used for data in transit. Result: Ensure that information is protected using modern standards like TLS 1.3 or AES-256 and that legacy, insecure protocols are disabled.

  • Inspect SSL/TLS certificates to ensure they are valid and issued by a trusted authority.
  • Verify that Multi-Factor Authentication (MFA) is enforced for all external-facing transfer portals.
  • Check for the use of end-to-end encryption for sensitive file transfers between departments.

5. Audit the chain of custody for physical media transfers

Action: Review logs and receipts for the physical transport of hard drives or tapes. Result: Verify that physical transport utilizes tamper-evident packaging and vetted personnel to prevent loss or interception.

  • Check for signed handover records that document the movement of media from sender to courier.
  • Confirm that all physical media is encrypted at rest before being dispatched.
  • Verify the use of reputable couriers with GPS tracking capabilities for high-sensitivity assets.

6. Review Identity and Access Management (IAM) roles for transfer systems

Action: Sample the user access list for Managed File Transfer (MFT) and administrative consoles. Result: Confirm that access follows the principle of least privilege and that administrative rights are strictly controlled.

  • Check for the presence of MFA for all users with administrative access to transfer facilities.
  • Verify that access is revoked promptly for leavers or those changing roles.
  • Ensure that generic or shared accounts are not used to initiate data transfers.

7. Test data integrity verification protocols

Action: Request evidence of integrity checks performed during or after transfers. Result: Provide mathematical proof that the organisation utilises checksums, digital signatures, or hashing algorithms to detect data tampering.

  • Review logs for SHA-256 or similar hash verifications on large file batches.
  • Check that digital signatures are used to authenticate the sender for sensitive communications.
  • Verify that automated alerts are triggered if a transfer fails an integrity check.

8. Evaluate monitoring logs and SIEM alerts for transfer facilities

Action: Review the audit trails and security alerts generated by transfer gateways. Result: Determine if unauthorised data exfiltration or misdirected transfers are detected and escalated in real-time.

  • Check for logs detailing the date, time, sender, recipient, and volume of data moved.
  • Verify that transfer logs are integrated into a central SIEM for correlation.
  • Confirm that logs are protected from unauthorised modification or deletion.

9. Validate staff awareness and training for verbal transfer protocols

Action: Review training records and interview staff regarding non-disclosure requirements. Result: Confirm that employees understand the risks of discussing sensitive data in public and adhere to verbal transfer rules.

  • Verify that staff have completed training on the secure use of communication tools.
  • Check for awareness of the “Clear Desk and Clear Screen” policy in the context of data transfer.
  • Ensure staff know how to report an accidental misdirected transfer or potential interception.

Action: Review the incident register for any entries related to Annex A 5.14. Result: Confirm that transfer-related incidents are reported within the statutory thresholds required by GDPR, NIS2, or CIRCIA.

  • Check that root cause analysis was performed for any data-in-transit breaches.
  • Verify that lessons learned were incorporated into the Information Transfer Policy.
  • Ensure that the reporting window (e.g. 72 hours) was met for any reportable personal data breaches.

What the auditor will check

The audit is going to check a number of areas. Lets go through them

1. That you have not done something stupid

The auditor is going to check the rules, procedures and agreements and make sure you followed them. As with everything having documented evidence of anything you can is going to be your friend. So practical things like physical media transfer logs, risk register items and evidences of training. Work through each transfer type and look for the gotchas. Sure you use a secure courier but did you agree it and have them listed some where? Sure you start every conversation with a disclaimer, and now for shits and giggles, with the auditor would be the time to polish off and demonstrate your unique verbal skills.

2. That you have rules, processes, agreement and you have followed them and have trained people

This is obvious but they are going to look that you have documented what you say you do, that you follow it and that you have trained people.

3. Documentation

They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Doing anything else would be a massive own goal.

Top 3 Mistakes People Make and How to Avoid Them

The top 3 Mistakes People Make For ISO 27001 Annex A 5.14 are

1. Your teams go around you and do what they want because your controls make their life a living hell

Be practical and realistic in what you put in place. No one likes a smart arse but they hate people who make their job more difficult way more. If you make it too hard they will just go around you. You have ZERO way to check, audit or impose on private conversations or private communications over things like WhatsApp and text. It just isn’t realistic. Don’t be a dick, be someone who takes the spirit of what is required and implements in with reasoned appropriateness. This is a risk based management system. Not a rule based system. Controls are for consideration and the level you implement is down to you and the risk to your business.

2. One or more members of your team haven’t done what they should have done

Prior to the audit check that all members of the team have done what they should have, understand how to transfer information and have been trained in it.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 5.14 FAQ

Is an Information Transfer Agreement (ITA) mandatory?

Yes, for transfers involving high-risk or sensitive data, a formalised Information Transfer Agreement (ITA) is necessary to define the security obligations of all parties.
Sets the ground rules for how data should be handled by the recipient.
Defines the technical requirements for the transfer (e.g., specific encryption standards).
Establishes legal liability and incident reporting requirements.
Must be signed by both the sender and the receiver before data movement occurs.

How does Annex A 5.14 protect data in transit?

Annex A 5.14 protects data in transit by mandating the implementation of technical safeguards that ensure confidentiality, integrity, and availability.
Encryption: Utilising TLS for web traffic and AES-256 for file-level protection.
Access Controls: Restricting transfer capabilities to authorised personnel only.
Verification: Using digital signatures or checksums to ensure data hasn’t been tampered with.
Audit Trails: Logging all transfer activities for forensic review and compliance verification.

Does Annex A 5.14 cover physical data transfers?

Yes, the control explicitly includes the physical transport of information, such as the courier of hard drives, tapes, or printed documentation.
Requires secure packaging and tampering-evident seals for physical media.
Mandates the use of trusted couriers with a formalised chain of custody.
Requires that physical media be encrypted at rest before transport.
Includes protocols for the secure handover and receipt of physical assets.

What are the common risks addressed by Annex A 5.14?

The primary objective is to mitigate risks associated with the movement of data across internal and external network boundaries.
Interception: Preventing attackers from “sniffing” data while it moves across a network.
Misdirection: Ensuring data is sent to the correct recipient and not a malicious actor.
Data Corruption: Preventing technical failures or malicious acts from altering the data.
Unauthorised Copying: Controlling the creation of shadow data during the transfer process.

ISO 27001 controls and attribute values

Control typeInformation
security properties
Cybersecurity
concepts
Operational
capabilities
Security domains
PreventiveConfidentialityProtectInformation protectionProtection
IntegrityAsset management
Availability

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top