Skip to content
arrow_back
search
Annex A 5.14 verified ISO/IEC 27001:2022

Information Transfer Policies and Procedures

Ensure secure and controlled transfer of information within and outside the organisation.

record_voice_over

Plain language

Imagine you're sending important business information. This control makes sure all details are safely transferred within your team or to outsiders, meaning no one unwanted reads or alters it. Without these safeguards, valuable info could be leaked or tampered with, causing trust and financial losses.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties.
verified ISO/IEC 27001:2022 Annex A 5.14
priority_high

Why it matters

Without information transfer policies and agreements, data sent internally or to third parties may be intercepted, altered or misdirected, harming confidentiality and integrity.

settings

Operational notes

Maintain transfer rules and agreements for each channel (email, file sharing, APIs, removable media), including encryption, approval, labelling, and logging; review with suppliers regularly.

Mapping detail

Mapping

Direction

Controls