Skip to content
arrow_back
search
Annex A 8.11 verified ISO/IEC 27001:2022

Data Masking for Sensitive Information

Use data masking to hide sensitive info based on policy requirements and legal obligations.

record_voice_over

Plain language

Data masking is a technique to hide sensitive information, like personal details, from those who shouldn’t see it. It’s important because if sensitive data like credit card numbers or private health details are exposed, they can lead to financial fraud or privacy breaches.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration.
verified ISO/IEC 27001:2022 Annex A 8.11
priority_high

Why it matters

Without data masking, PII and other sensitive data may be exposed in logs, reports, and test environments, causing privacy breaches and legal non-compliance.

settings

Operational notes

Review masking rules per dataset and use case (test, analytics, logging); validate formats remain usable while identifiers are obscured, and update for new fields and laws.

Mapping detail

Mapping

Direction

Controls