Skip to content
arrow_back
search
Annex A 5.13 verified ISO/IEC 27001:2022

Labelling of Information

Create and use clear labels to show how sensitive information is, so it is correctly handled.

record_voice_over

Plain language

This control is about putting labels on information to show how sensitive it is. This matters because the labels help people know how to handle the information properly. Without clear labels, sensitive information could be mishandled or exposed, leading to data breaches or privacy violations.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organization.
verified ISO/IEC 27001:2022 Annex A 5.13
priority_high

Why it matters

Without classification-based labels, staff and systems may apply the wrong handling and sharing rules, increasing the chance of inadvertent disclosure.

settings

Operational notes

Embed classification labels in documents/emails via templates and auto-tagging; ensure labels and handling instructions are updated immediately after reclassification.

Mapping detail

Mapping

Direction

Controls