ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Secure File Transfer Checklist

Secure File Transfer Checklist

1. Purpose

This checklist helps employees, contractors, consultants, and authorized third parties verify that files are transferred securely before, during, and after transmission.

It is applicable to both internal and external file transfers, with additional controls for Confidential and Restricted information.


2. When to Use This Checklist

Use this checklist when transferring:

  • Customer information
  • Personal data
  • Financial information
  • Confidential documents
  • Restricted documents
  • Audit evidence
  • Security reports
  • Vulnerability reports
  • Source code
  • Contracts
  • Business-sensitive information
  • Large data files
  • Files to customers, suppliers, auditors, consultants, or partners

3. Transfer Information

FieldDetails
Transfer ID[SFT-XXXX]
Date[DD-MMM-YYYY]
Requestor[Name]
Department[Department]
Sender[Name]
Recipient[Name]
Recipient Organization[Organization]
Business Purpose[Purpose]
File/Information[Description]
ClassificationPublic / Internal / Confidential / Restricted
Transfer Method[Approved Channel]
Expiry Date[Date]

4. Pre-Transfer Checklist

Business Purpose

  • Business purpose is clearly defined.
  • Transfer is necessary.
  • Information being transferred is relevant to the purpose.
  • No unnecessary information is included.

Information Identification

  • Correct file has been identified.
  • File contents have been reviewed.
  • Sensitive information has been identified.
  • Personal data has been identified.
  • Customer data has been identified.
  • Credentials/secrets have been identified.
  • Classification has been assigned.

5. Data Minimization

Before sending:

  • Unnecessary records removed.
  • Unnecessary fields removed.
  • Unnecessary attachments removed.
  • Personal data minimized where possible.
  • Sensitive information masked where practical.
  • Test/demo data used instead of production data where appropriate.
  • Credentials and secrets removed from the file.

6. Recipient Verification

Confirm:

  • Recipient name is correct.
  • Recipient organization is correct.
  • Email address/account is correct.
  • Recipient has a legitimate business need.
  • Recipient is authorized to receive the information.
  • External domain has been verified.
  • Recipient permissions have been checked.
  • Recipient is not accidentally included through CC/BCC or group access.

For high-risk transfers:

  • Recipient identity independently verified.
  • Recipient organization verified through an approved source.
  • Additional approval obtained.

7. Contract and Authorization Check

Where applicable:

  • NDA is in place.
  • Contract permits the transfer.
  • Data Processing Agreement is in place where required.
  • Customer approval has been obtained where required.
  • Supplier agreement requirements have been checked.
  • Regulatory requirements have been assessed.
  • Cross-border transfer requirements have been assessed.

8. Approved Transfer Channel

Confirm:

  • Transfer channel is on the Approved Information Transfer Channels Register.
  • Channel is appropriate for the information classification.
  • Channel supports required authentication.
  • Channel provides appropriate encryption.
  • Access controls are configured.
  • Logging is available where required.
  • Public/anonymous access is disabled.

Examples of Approved Channels

  • Secure file-sharing platform
  • Customer portal
  • SFTP
  • Approved cloud storage
  • Authenticated API
  • Approved collaboration platform
  • Approved source-code repository
  • Secure physical delivery

9. File Protection

Before transfer:

  • File is protected according to its classification.
  • Encryption is applied where required.
  • Password protection is applied where appropriate.
  • Password/key is communicated through a separate approved channel.
  • File permissions are restricted.
  • Download permissions are restricted where appropriate.
  • File expiry is configured where available.
  • Watermarking is applied where appropriate.
  • File has been checked for malware.

10. Confidential Information

For Confidential files:

  • Recipient is authorized.
  • Secure transfer channel is used.
  • Access is restricted.
  • Data is minimized.
  • Encryption is applied where required.
  • Access expiry is configured where appropriate.
  • Receipt confirmation is obtained where required.

11. Restricted Information

For Restricted files:

  • Explicit authorization obtained.
  • Business justification documented.
  • Risk assessed where required.
  • Named recipient access configured.
  • MFA enabled where available.
  • Strong encryption applied.
  • Restricted repository/channel used.
  • Download/copy permissions restricted where practical.
  • Access expiry defined.
  • Transfer recorded.
  • Receipt confirmed.
  • Access revoked after the business need ends.

12. Personal Data

If personal data is included:

  • Purpose of processing is identified.
  • Minimum necessary data is being transferred.
  • Recipient is authorized.
  • Applicable privacy requirements have been considered.
  • Contract/DPA requirements have been checked.
  • Data location/cross-border requirements have been considered.
  • Appropriate security controls are applied.
  • Retention/deletion requirements are understood.

13. Customer Data

If customer data is included:

  • Customer authorization/contract permits sharing.
  • Customer-specific security requirements checked.
  • Customer-approved transfer mechanism used where required.
  • Recipient is authorized.
  • Data minimization applied.
  • Access is restricted.
  • Transfer evidence retained where required.

14. Credentials and Secrets

Before transfer:

  • No password is included in the file.
  • No API key is included.
  • No private key is included.
  • No production credential is included.
  • No access token is included.
  • No encryption key is included.

If a secret must be transferred:

  • Approved secrets-management mechanism used.
  • Recipient identity verified.
  • Access is time-limited where possible.
  • Secret is rotated after exposure where required.

15. Source Code

If source code is being transferred:

  • Approved repository/channel used.
  • Recipient access is authorized.
  • Repository permissions reviewed.
  • Secrets removed.
  • API keys removed.
  • Credentials removed.
  • Confidential configuration reviewed.
  • Third-party license requirements considered.
  • External collaborator access is controlled.

16. Cloud File Transfer

For cloud-based file sharing:

  • Approved cloud service used.
  • Correct tenant/account selected.
  • File classification checked.
  • Recipient permissions verified.
  • Public access disabled.
  • Anonymous access disabled.
  • MFA enabled where applicable.
  • Link expiry configured.
  • Download permissions restricted where appropriate.
  • Access logs available.
  • Access removed after completion.

17. Email Transfer

If email is approved for the transfer:

  • Correct recipient email address verified.
  • Attachment is correct.
  • No unnecessary recipients included.
  • Classification checked.
  • Encryption applied where required.
  • Secure link used instead of attachment where appropriate.
  • Password/key is not sent in the same email.
  • Email is sent from an approved corporate account.

18. SFTP / Secure File Transfer

For SFTP or similar mechanisms:

  • Approved server confirmed.
  • Recipient account verified.
  • Strong authentication configured.
  • Encryption enabled.
  • Directory permissions restricted.
  • File integrity checked where required.
  • Transfer logs available.
  • Temporary accounts configured with expiry.
  • Files removed according to retention requirements.

19. API / System-to-System Transfer

For automated transfers:

  • API is approved.
  • Authentication is configured.
  • Authorization is restricted.
  • TLS/encryption is enabled.
  • API credentials are securely stored.
  • Least privilege applied.
  • Logging enabled.
  • Monitoring enabled.
  • Rate limiting applied where appropriate.
  • Error handling does not expose sensitive information.
  • Credentials can be revoked/rotated.

20. Physical File Transfer

For physical files/media:

  • Information classification identified.
  • Authorized recipient confirmed.
  • Secure packaging used.
  • Tamper protection used where required.
  • Authorized courier used.
  • Tracking number recorded.
  • Chain of custody maintained where required.
  • Recipient identity verified.
  • Receipt confirmed.
  • Temporary copies removed securely.

21. Final Pre-Send Review

Before clicking Send / Upload / Share:

  • Correct file.
  • Correct recipient.
  • Correct organization.
  • Correct classification.
  • Correct purpose.
  • Correct transfer channel.
  • Minimum necessary data.
  • Required encryption.
  • Required approval.
  • Correct permissions.
  • Correct expiry.
  • No unintended recipients.
  • No credentials/secrets.
  • No unnecessary attachments.

Final Question

If this file reaches the wrong person, what could happen?

If the answer indicates significant risk, stop and reassess before transferring.


22. Transfer Execution

During transfer:

  • Use the approved account.
  • Use the approved channel.
  • Confirm recipient permissions.
  • Upload/send the correct file.
  • Verify successful transfer.
  • Avoid creating unnecessary copies.
  • Record the transfer where required.

23. Receipt Confirmation

After transfer:

  • Recipient confirmed receipt where required.
  • File was accessible to the intended recipient.
  • No unintended access identified.
  • Transfer log retained where required.
  • Any temporary sharing link remains active only as necessary.

24. Post-Transfer Access Removal

After the business requirement ends:

  • Temporary access removed.
  • Sharing link disabled.
  • External account disabled if no longer required.
  • Download permissions removed where applicable.
  • Temporary files deleted.
  • Credentials revoked/rotated where necessary.
  • Data return/deletion confirmed where required.

25. Accidental or Unauthorized Transfer

If a file is sent to the wrong recipient or shared through an unauthorized channel:

Immediately:

  • Stop further sharing.
  • Revoke the link/access.
  • Attempt to recall/delete the file where technically possible.
  • Notify Security/ISMS.
  • Notify the Information Owner.
  • Preserve relevant evidence.
  • Identify what information was exposed.
  • Identify who received/accessed it.
  • Determine whether personal/customer data was involved.
  • Assess contractual/regulatory notification requirements.
  • Record as a security incident where applicable.

Do not conceal the incident or delete relevant evidence.


26. Transfer Record

For significant transfers, record:

FieldDetails
Transfer ID[SFT-001]
Date/Time[Date/Time]
Sender[Name]
Recipient[Name]
Organization[Organization]
Information[Description]
Classification[Classification]
Purpose[Purpose]
Channel[Channel]
Protection[Encryption/MFA/etc.]
Approval[Name]
Expiry[Date]
ReceiptConfirmed / Not Required
Access RevokedYes/No/N/A
Evidence[Reference]
StatusCompleted/Open

27. AWS SaaS Example

A SaaS company needs to provide an external auditor with security evidence.

Before Transfer

  • Identify audit evidence.
  • Classify documents as Confidential/Restricted depending on content.
  • Confirm auditor organization and personnel.
  • Verify NDA/contract requirements.
  • Obtain approval.
  • Use the approved audit repository.

Transfer

  • Create named auditor account.
  • Enable MFA.
  • Grant read-only access.
  • Upload only requested evidence.
  • Apply access expiry.
  • Record the transfer.

After Audit

  • Confirm access is no longer required.
  • Revoke auditor access.
  • Remove temporary sharing.
  • Retain required audit evidence internally.
  • Update the transfer record.

Process:

Identify → Classify → Verify → Approve → Secure Transfer → Confirm → Monitor → Revoke → Record


28. Evidence

Potential evidence includes:

  • Completed Secure File Transfer Checklist
  • Transfer register
  • Approval record
  • Secure-sharing logs
  • SFTP logs
  • API logs
  • Cloud access logs
  • Recipient confirmation
  • Encryption evidence
  • MFA/access records
  • Access review
  • Access revocation
  • Data deletion/return confirmation
  • Incident records
  • Contract/NDA/DPA

29. Responsibilities

RoleResponsibility
SenderVerify information, recipient, purpose, and channel
Information OwnerApprove sensitive sharing
Security/ISMSDefine/verify security requirements
IT/CloudMaintain secure transfer mechanisms
Privacy/LegalReview privacy/legal requirements
RecipientProtect information after receipt
ManagementApprove significant/high-risk transfers
Internal AuditVerify applicable controls

30. Common Mistakes

Avoid:

  • Sending the wrong attachment.
  • Sending to the wrong email address.
  • Using personal email.
  • Creating public cloud links.
  • Sharing more information than required.
  • Sending passwords in the same email as the file.
  • Uploading confidential files to unauthorized AI tools.
  • Forgetting to set access expiry.
  • Forgetting to revoke external access.
  • Sending customer data without checking contractual requirements.
  • Sending credentials in spreadsheets or documents.
  • Failing to report accidental transfers.

31. Quick Secure Transfer Checklist

Before

  • Identify data.
  • Classify data.
  • Confirm purpose.
  • Verify recipient.
  • Minimize data.
  • Check authorization.
  • Check contract/privacy requirements.
  • Select approved channel.

During

  • Apply encryption.
  • Restrict access.
  • Use MFA where appropriate.
  • Transfer securely.
  • Verify successful delivery.

After

  • Confirm receipt.
  • Remove temporary access.
  • Delete temporary copies.
  • Retain required evidence.
  • Record the transfer.
  • Report incidents if something went wrong.

32. Relationship With Other ISMS Documents

This checklist should be used with:

  • Information Transfer Policy
  • Approved Information Transfer Channels
  • External Data Sharing Procedure
  • Third-Party Information Sharing Agreement
  • Information Classification Policy
  • Data Handling Guidelines
  • Information Handling Procedure
  • Access Control Policy
  • Data Inventory
  • Supplier Security Assessment
  • AI Acceptable Use Policy
  • Incident Response Plan
  • Data Breach Response Procedure

The overall control chain is:

Identify → Classify → Minimize → Verify → Approve → Select Channel → Protect → Transfer → Confirm → Revoke → Record


33. ISO 27001 Connection

This checklist supports applicable requirements relating to:

  • Information transfer
  • Information classification
  • Access control
  • Data leakage prevention
  • Secure authentication
  • Supplier relationships
  • Cloud services
  • Protection of personal information
  • Logging and monitoring
  • Incident management

The exact applicable controls should be determined through the organization’s risk assessment and Statement of Applicability (SoA).


34. Final Audit Trail

A secure file transfer should be demonstrable through:

Business Purpose → Data Identified → Classification → Recipient Verification → Authorization → Approved Channel → Data Minimization → Security Controls → Transfer → Receipt → Access Removal → Evidence

Final Principle

Before sending a file, verify the data, recipient, purpose, channel, protection, and authorization. After sending it, verify receipt and remove access when it is no longer required.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *