1. Purpose
This checklist helps employees, contractors, consultants, and authorized third parties verify that files are transferred securely before, during, and after transmission.
It is applicable to both internal and external file transfers, with additional controls for Confidential and Restricted information.
2. When to Use This Checklist
Use this checklist when transferring:
- Customer information
- Personal data
- Financial information
- Confidential documents
- Restricted documents
- Audit evidence
- Security reports
- Vulnerability reports
- Source code
- Contracts
- Business-sensitive information
- Large data files
- Files to customers, suppliers, auditors, consultants, or partners
3. Transfer Information
| Field | Details |
|---|---|
| Transfer ID | [SFT-XXXX] |
| Date | [DD-MMM-YYYY] |
| Requestor | [Name] |
| Department | [Department] |
| Sender | [Name] |
| Recipient | [Name] |
| Recipient Organization | [Organization] |
| Business Purpose | [Purpose] |
| File/Information | [Description] |
| Classification | Public / Internal / Confidential / Restricted |
| Transfer Method | [Approved Channel] |
| Expiry Date | [Date] |
4. Pre-Transfer Checklist
Business Purpose
- Business purpose is clearly defined.
- Transfer is necessary.
- Information being transferred is relevant to the purpose.
- No unnecessary information is included.
Information Identification
- Correct file has been identified.
- File contents have been reviewed.
- Sensitive information has been identified.
- Personal data has been identified.
- Customer data has been identified.
- Credentials/secrets have been identified.
- Classification has been assigned.
5. Data Minimization
Before sending:
- Unnecessary records removed.
- Unnecessary fields removed.
- Unnecessary attachments removed.
- Personal data minimized where possible.
- Sensitive information masked where practical.
- Test/demo data used instead of production data where appropriate.
- Credentials and secrets removed from the file.
6. Recipient Verification
Confirm:
- Recipient name is correct.
- Recipient organization is correct.
- Email address/account is correct.
- Recipient has a legitimate business need.
- Recipient is authorized to receive the information.
- External domain has been verified.
- Recipient permissions have been checked.
- Recipient is not accidentally included through CC/BCC or group access.
For high-risk transfers:
- Recipient identity independently verified.
- Recipient organization verified through an approved source.
- Additional approval obtained.
7. Contract and Authorization Check
Where applicable:
- NDA is in place.
- Contract permits the transfer.
- Data Processing Agreement is in place where required.
- Customer approval has been obtained where required.
- Supplier agreement requirements have been checked.
- Regulatory requirements have been assessed.
- Cross-border transfer requirements have been assessed.
8. Approved Transfer Channel
Confirm:
- Transfer channel is on the Approved Information Transfer Channels Register.
- Channel is appropriate for the information classification.
- Channel supports required authentication.
- Channel provides appropriate encryption.
- Access controls are configured.
- Logging is available where required.
- Public/anonymous access is disabled.
Examples of Approved Channels
- Secure file-sharing platform
- Customer portal
- SFTP
- Approved cloud storage
- Authenticated API
- Approved collaboration platform
- Approved source-code repository
- Secure physical delivery
9. File Protection
Before transfer:
- File is protected according to its classification.
- Encryption is applied where required.
- Password protection is applied where appropriate.
- Password/key is communicated through a separate approved channel.
- File permissions are restricted.
- Download permissions are restricted where appropriate.
- File expiry is configured where available.
- Watermarking is applied where appropriate.
- File has been checked for malware.
10. Confidential Information
For Confidential files:
- Recipient is authorized.
- Secure transfer channel is used.
- Access is restricted.
- Data is minimized.
- Encryption is applied where required.
- Access expiry is configured where appropriate.
- Receipt confirmation is obtained where required.
11. Restricted Information
For Restricted files:
- Explicit authorization obtained.
- Business justification documented.
- Risk assessed where required.
- Named recipient access configured.
- MFA enabled where available.
- Strong encryption applied.
- Restricted repository/channel used.
- Download/copy permissions restricted where practical.
- Access expiry defined.
- Transfer recorded.
- Receipt confirmed.
- Access revoked after the business need ends.
12. Personal Data
If personal data is included:
- Purpose of processing is identified.
- Minimum necessary data is being transferred.
- Recipient is authorized.
- Applicable privacy requirements have been considered.
- Contract/DPA requirements have been checked.
- Data location/cross-border requirements have been considered.
- Appropriate security controls are applied.
- Retention/deletion requirements are understood.
13. Customer Data
If customer data is included:
- Customer authorization/contract permits sharing.
- Customer-specific security requirements checked.
- Customer-approved transfer mechanism used where required.
- Recipient is authorized.
- Data minimization applied.
- Access is restricted.
- Transfer evidence retained where required.
14. Credentials and Secrets
Before transfer:
- No password is included in the file.
- No API key is included.
- No private key is included.
- No production credential is included.
- No access token is included.
- No encryption key is included.
If a secret must be transferred:
- Approved secrets-management mechanism used.
- Recipient identity verified.
- Access is time-limited where possible.
- Secret is rotated after exposure where required.
15. Source Code
If source code is being transferred:
- Approved repository/channel used.
- Recipient access is authorized.
- Repository permissions reviewed.
- Secrets removed.
- API keys removed.
- Credentials removed.
- Confidential configuration reviewed.
- Third-party license requirements considered.
- External collaborator access is controlled.
16. Cloud File Transfer
For cloud-based file sharing:
- Approved cloud service used.
- Correct tenant/account selected.
- File classification checked.
- Recipient permissions verified.
- Public access disabled.
- Anonymous access disabled.
- MFA enabled where applicable.
- Link expiry configured.
- Download permissions restricted where appropriate.
- Access logs available.
- Access removed after completion.
17. Email Transfer
If email is approved for the transfer:
- Correct recipient email address verified.
- Attachment is correct.
- No unnecessary recipients included.
- Classification checked.
- Encryption applied where required.
- Secure link used instead of attachment where appropriate.
- Password/key is not sent in the same email.
- Email is sent from an approved corporate account.
18. SFTP / Secure File Transfer
For SFTP or similar mechanisms:
- Approved server confirmed.
- Recipient account verified.
- Strong authentication configured.
- Encryption enabled.
- Directory permissions restricted.
- File integrity checked where required.
- Transfer logs available.
- Temporary accounts configured with expiry.
- Files removed according to retention requirements.
19. API / System-to-System Transfer
For automated transfers:
- API is approved.
- Authentication is configured.
- Authorization is restricted.
- TLS/encryption is enabled.
- API credentials are securely stored.
- Least privilege applied.
- Logging enabled.
- Monitoring enabled.
- Rate limiting applied where appropriate.
- Error handling does not expose sensitive information.
- Credentials can be revoked/rotated.
20. Physical File Transfer
For physical files/media:
- Information classification identified.
- Authorized recipient confirmed.
- Secure packaging used.
- Tamper protection used where required.
- Authorized courier used.
- Tracking number recorded.
- Chain of custody maintained where required.
- Recipient identity verified.
- Receipt confirmed.
- Temporary copies removed securely.
21. Final Pre-Send Review
Before clicking Send / Upload / Share:
- Correct file.
- Correct recipient.
- Correct organization.
- Correct classification.
- Correct purpose.
- Correct transfer channel.
- Minimum necessary data.
- Required encryption.
- Required approval.
- Correct permissions.
- Correct expiry.
- No unintended recipients.
- No credentials/secrets.
- No unnecessary attachments.
Final Question
If this file reaches the wrong person, what could happen?
If the answer indicates significant risk, stop and reassess before transferring.
22. Transfer Execution
During transfer:
- Use the approved account.
- Use the approved channel.
- Confirm recipient permissions.
- Upload/send the correct file.
- Verify successful transfer.
- Avoid creating unnecessary copies.
- Record the transfer where required.
23. Receipt Confirmation
After transfer:
- Recipient confirmed receipt where required.
- File was accessible to the intended recipient.
- No unintended access identified.
- Transfer log retained where required.
- Any temporary sharing link remains active only as necessary.
24. Post-Transfer Access Removal
After the business requirement ends:
- Temporary access removed.
- Sharing link disabled.
- External account disabled if no longer required.
- Download permissions removed where applicable.
- Temporary files deleted.
- Credentials revoked/rotated where necessary.
- Data return/deletion confirmed where required.
25. Accidental or Unauthorized Transfer
If a file is sent to the wrong recipient or shared through an unauthorized channel:
Immediately:
- Stop further sharing.
- Revoke the link/access.
- Attempt to recall/delete the file where technically possible.
- Notify Security/ISMS.
- Notify the Information Owner.
- Preserve relevant evidence.
- Identify what information was exposed.
- Identify who received/accessed it.
- Determine whether personal/customer data was involved.
- Assess contractual/regulatory notification requirements.
- Record as a security incident where applicable.
Do not conceal the incident or delete relevant evidence.
26. Transfer Record
For significant transfers, record:
| Field | Details |
|---|---|
| Transfer ID | [SFT-001] |
| Date/Time | [Date/Time] |
| Sender | [Name] |
| Recipient | [Name] |
| Organization | [Organization] |
| Information | [Description] |
| Classification | [Classification] |
| Purpose | [Purpose] |
| Channel | [Channel] |
| Protection | [Encryption/MFA/etc.] |
| Approval | [Name] |
| Expiry | [Date] |
| Receipt | Confirmed / Not Required |
| Access Revoked | Yes/No/N/A |
| Evidence | [Reference] |
| Status | Completed/Open |
27. AWS SaaS Example
A SaaS company needs to provide an external auditor with security evidence.
Before Transfer
- Identify audit evidence.
- Classify documents as Confidential/Restricted depending on content.
- Confirm auditor organization and personnel.
- Verify NDA/contract requirements.
- Obtain approval.
- Use the approved audit repository.
Transfer
- Create named auditor account.
- Enable MFA.
- Grant read-only access.
- Upload only requested evidence.
- Apply access expiry.
- Record the transfer.
After Audit
- Confirm access is no longer required.
- Revoke auditor access.
- Remove temporary sharing.
- Retain required audit evidence internally.
- Update the transfer record.
Process:
Identify → Classify → Verify → Approve → Secure Transfer → Confirm → Monitor → Revoke → Record
28. Evidence
Potential evidence includes:
- Completed Secure File Transfer Checklist
- Transfer register
- Approval record
- Secure-sharing logs
- SFTP logs
- API logs
- Cloud access logs
- Recipient confirmation
- Encryption evidence
- MFA/access records
- Access review
- Access revocation
- Data deletion/return confirmation
- Incident records
- Contract/NDA/DPA
29. Responsibilities
| Role | Responsibility |
|---|---|
| Sender | Verify information, recipient, purpose, and channel |
| Information Owner | Approve sensitive sharing |
| Security/ISMS | Define/verify security requirements |
| IT/Cloud | Maintain secure transfer mechanisms |
| Privacy/Legal | Review privacy/legal requirements |
| Recipient | Protect information after receipt |
| Management | Approve significant/high-risk transfers |
| Internal Audit | Verify applicable controls |
30. Common Mistakes
Avoid:
- Sending the wrong attachment.
- Sending to the wrong email address.
- Using personal email.
- Creating public cloud links.
- Sharing more information than required.
- Sending passwords in the same email as the file.
- Uploading confidential files to unauthorized AI tools.
- Forgetting to set access expiry.
- Forgetting to revoke external access.
- Sending customer data without checking contractual requirements.
- Sending credentials in spreadsheets or documents.
- Failing to report accidental transfers.
31. Quick Secure Transfer Checklist
Before
- Identify data.
- Classify data.
- Confirm purpose.
- Verify recipient.
- Minimize data.
- Check authorization.
- Check contract/privacy requirements.
- Select approved channel.
During
- Apply encryption.
- Restrict access.
- Use MFA where appropriate.
- Transfer securely.
- Verify successful delivery.
After
- Confirm receipt.
- Remove temporary access.
- Delete temporary copies.
- Retain required evidence.
- Record the transfer.
- Report incidents if something went wrong.
32. Relationship With Other ISMS Documents
This checklist should be used with:
- Information Transfer Policy
- Approved Information Transfer Channels
- External Data Sharing Procedure
- Third-Party Information Sharing Agreement
- Information Classification Policy
- Data Handling Guidelines
- Information Handling Procedure
- Access Control Policy
- Data Inventory
- Supplier Security Assessment
- AI Acceptable Use Policy
- Incident Response Plan
- Data Breach Response Procedure
The overall control chain is:
Identify → Classify → Minimize → Verify → Approve → Select Channel → Protect → Transfer → Confirm → Revoke → Record
33. ISO 27001 Connection
This checklist supports applicable requirements relating to:
- Information transfer
- Information classification
- Access control
- Data leakage prevention
- Secure authentication
- Supplier relationships
- Cloud services
- Protection of personal information
- Logging and monitoring
- Incident management
The exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability (SoA).
34. Final Audit Trail
A secure file transfer should be demonstrable through:
Business Purpose → Data Identified → Classification → Recipient Verification → Authorization → Approved Channel → Data Minimization → Security Controls → Transfer → Receipt → Access Removal → Evidence
Final Principle
Before sending a file, verify the data, recipient, purpose, channel, protection, and authorization. After sending it, verify receipt and remove access when it is no longer required.
