What is ISO 27001 Annex A 5.13 – Labelling of Information?
ISO 27001 Annex A 5.13 – Labelling of Information is about clearly communicating the classification of information so that people know how information should be handled.
A.5.12 determines how information is classified.
A.5.13 focuses on how that classification is communicated or displayed.
For example, if a document has been classified as:
CONFIDENTIAL
that classification should be communicated through an appropriate label, marking, metadata, or other mechanism.
Labelling helps employees understand:
- How sensitive information is
- Who should have access to it
- Whether it can be shared externally
- How it should be stored
- How it should be transferred
- What handling restrictions apply
- What security precautions are required
Examples of information labels
- PUBLIC
- INTERNAL
- CONFIDENTIAL
- RESTRICTED
Depending on the organization’s classification scheme, other labels may be used.
Simple Explanation
A.5.12 decides the classification. A.5.13 makes that classification visible or understandable to the people handling the information.
Why is A.5.13 Important?
Information can be correctly classified but still mishandled if employees cannot easily identify its classification.
For example:
A company classifies a customer contract as Confidential.
However, the document has no visible indication that it is confidential.
An employee may:
- Upload it to an unrestricted folder
- Send it to the wrong recipient
- Share it with an external party
- Store it in an unauthorized application
- Print and leave it unattended
Labelling helps reduce this risk by making the required handling level easier to recognize.
What Does A.5.13 Require?
The organization should establish appropriate procedures for labelling information in accordance with its information classification scheme.
The labelling approach should be:
- Consistent
- Practical
- Understandable
- Appropriate to the type of information
- Applied throughout the information lifecycle where relevant
- Supported by appropriate technical or procedural controls
The organization should determine what needs to be labelled, how it should be labelled, and where the label should appear.
ISO 27001 does not require one specific labelling format.
For example, an organization may use:
CONFIDENTIAL
in a document header and footer.
Another organization may use:
Classification: Confidential
in document metadata.
Both approaches can be appropriate if they effectively communicate the required classification.
Classification vs. Labelling
This distinction is important for an ISO 27001 audit.
| A.5.12 – Classification | A.5.13 – Labelling |
|---|---|
| Determines the sensitivity of information | Communicates the classification |
| Answers “How sensitive is it?” | Answers “How do people know?” |
| Defines classification levels | Defines labels/markings |
| Based on risk and information security needs | Based on practical communication |
| Example: Confidential | Example: “CONFIDENTIAL” in document header |
Simple Example
A customer contract is assessed as:
Classification → Confidential
The document is then marked:
Label → CONFIDENTIAL
The handling rules may say:
Handling → Authorized personnel only; approved storage; controlled external sharing.
What Information Can Be Labelled?
Labelling can apply to many forms of information.
Documents
- Policies
- Contracts
- Reports
- Financial documents
- Audit reports
- Customer documentation
Spreadsheets
- Customer databases
- Financial records
- Employee information
- Risk registers
- Compliance registers
Presentations
- Investor presentations
- Product roadmaps
- Business strategy
- Internal management presentations
Emails
For example:
Subject: CONFIDENTIAL – Customer Contract Review
Physical Documents
A printed document may contain:
CONFIDENTIAL
in the header or footer.
Digital Systems
Classification can also be communicated through:
- Metadata
- File properties
- Document management systems
- Data classification tools
- DLP platforms
- Information protection platforms
Activities Required to Implement A.5.13
Step 1: Define the Classification Scheme
A.5.13 depends on A.5.12.
For example:
| Level | Meaning |
|---|---|
| Public | Approved for public disclosure |
| Internal | Intended for internal business use |
| Confidential | Sensitive information requiring controlled access |
| Restricted | Highly sensitive information requiring strict controls |
Step 2: Define Labelling Rules
Define how each classification should be displayed.
For example:
| Classification | Label |
|---|---|
| Public | PUBLIC |
| Internal | INTERNAL |
| Confidential | CONFIDENTIAL |
| Restricted | RESTRICTED |
The organization can define whether labels appear:
- At the top of documents
- At the bottom of documents
- In headers and footers
- In file names
- In email subject lines
- In metadata
- In application interfaces
Step 3: Define Which Information Requires Labelling
Not every piece of information needs the same labelling mechanism.
For example:
Documents
Use headers and footers.
Emails
Use subject-line labels where appropriate.
Database records
Use metadata or system-level classification.
Physical documents
Use visible markings.
Cloud repositories
Use metadata, folder controls, or information-protection capabilities.
The approach should be practical for the organization’s environment.
Step 4: Define Handling Requirements
A label is useful only when employees understand what it means.
For example:
CONFIDENTIAL
Employees may be required to:
- Store it only in approved systems
- Share it only with authorized personnel
- Avoid using personal email
- Avoid uploading it to unauthorized applications
- Use approved methods for external transfer
RESTRICTED
Additional controls may include:
- Strict need-to-know access
- Strong authentication
- Encryption
- Restricted external sharing
- Additional monitoring
Step 5: Implement Labelling
Depending on the organization’s technology, labelling can be:
Manual
Employees select the classification when creating or saving a document.
Template-Based
Templates automatically include:
CONFIDENTIAL
in the header/footer.
Automated
Technology automatically classifies or labels information based on:
- Data patterns
- Content
- Metadata
- User selection
- Document type
- Business rules
For startups, manual or template-based labelling may be sufficient initially.
Step 6: Train Employees
Employees should understand:
- What the labels mean
- When to apply them
- How to apply them
- How labelled information should be handled
- When information can be reclassified
- What to do if classification is unclear
Training should include real examples.
Step 7: Address Information Sharing
Employees should understand what each label means when sharing information.
For example:
PUBLIC
May be shared externally if approved.
INTERNAL
Should generally remain within the organization.
CONFIDENTIAL
External sharing may require authorization.
RESTRICTED
External sharing may require explicit approval and additional security controls.
Step 8: Consider the Full Information Lifecycle
Labelling should not only apply when information is created.
Consider:
Create → Store → Use → Share → Archive → Dispose
For example:
A confidential customer report should remain appropriately identified when:
- Stored
- Downloaded
- Emailed
- Printed
- Archived
- Transferred to another system
Startup Example
Consider a SaaS startup that has implemented four classification levels:
Public → Internal → Confidential → Restricted
The company creates a customer contract.
Step 1 – Classification
The contract is classified as:
CONFIDENTIAL
Step 2 – Labelling
The document automatically displays:
CONFIDENTIAL
in the header and footer.
Step 3 – Storage
The contract is stored in the company’s approved document repository.
Step 4 – Access
Only authorized Sales, Legal, Finance, and Management users have access.
Step 5 – Sharing
If the contract needs to be shared externally, employees follow the approved information-sharing process.
Step 6 – Retention/Disposal
The contract is retained according to the applicable retention requirements and securely disposed of when no longer required.
Practical Flow
Classify → Label → Store → Access → Share → Retain/Dispose
Example Document Labelling
A confidential document could look like:
CONFIDENTIAL
Customer Security Assessment Report
Prepared for: ABC Technologies
Classification: Confidential
At the bottom:
CONFIDENTIAL – Authorized use only
The exact wording can be defined by the organization.
Example Email Labelling
For sensitive information, the organization may use:
Subject: CONFIDENTIAL – Customer Security Assessment
The email body could include:
This information is intended only for authorized recipients. Please do not forward or share without appropriate authorization.
The exact wording should be defined by the organization’s information handling requirements.
Example File Naming Convention
An organization could use:
CONFIDENTIAL_Customer_Contract_ABC_2026.pdf
or:
Restricted_Production_Access_List.xlsx
However, file naming should not be the organization’s only protection mechanism.
A filename can communicate classification, but it does not enforce access control.
Startup-Focused Quick Summary
A startup can implement A.5.13 without buying expensive software.
Basic approach:
1. Define classification levels
Public / Internal / Confidential / Restricted
2. Define labels
PUBLIC / INTERNAL / CONFIDENTIAL / RESTRICTED
3. Add labels to important documents
Use templates and document headers/footers.
4. Define email handling
Use classification in subject lines where appropriate.
5. Define handling rules
Explain what employees can and cannot do with each classification.
6. Train employees
Show real examples.
7. Keep evidence
Maintain labelled documents, templates, training records, and procedures.
Example Information Labelling Matrix
| Information Type | Classification | Labelling Method | Example |
|---|---|---|---|
| Website content | Public | None/optional | Public |
| Internal procedure | Internal | Header/footer | INTERNAL |
| Customer contract | Confidential | Header/footer + metadata | CONFIDENTIAL |
| Product roadmap | Confidential | Header/footer | CONFIDENTIAL |
| Production credentials | Restricted | System metadata/access controls | RESTRICTED |
| Customer sensitive data | Confidential/Restricted | System-level classification | CONFIDENTIAL / RESTRICTED |
Audit Evidence for A.5.13
An auditor may ask:
“How do employees know the classification of information they are handling?”
Useful evidence includes:
Policies
- Information Classification Policy
- Information Labelling Policy
- Information Handling Policy
Procedures
- Information Labelling Procedure
- Document Handling Procedure
- Information Sharing Procedure
Templates
- Confidential document template
- Restricted document template
- Approved report templates
- Email templates
Operational Evidence
- Sample labelled documents
- Sample confidential reports
- Sample contracts
- Email examples
- Screenshots of classification settings
- Document management configurations
Training Evidence
- Security awareness training
- Information classification training
- Employee acknowledgement
Technical Evidence
- Microsoft Purview or equivalent classification configuration
- DLP configuration
- Document-management metadata
- Automated classification rules
- Access-control configuration
A.5.13 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has the organization defined information classification levels? | Classification policy |
| Has the organization defined labelling requirements? | Labelling procedure |
| Are labels consistent with the classification scheme? | Policy + samples |
| Are sensitive documents labelled appropriately? | Sample documents |
| Are employees trained on information labels? | Training records |
| Are handling requirements linked to classifications? | Handling procedure |
| Are physical documents addressed where applicable? | Physical document procedure |
| Are emails and electronic communications addressed? | Email handling guidance |
| Are cloud systems and SaaS platforms considered? | System configuration |
| Are labels retained when information is shared or transferred? | Sample evidence |
| Is automated labelling used where appropriate? | Technical configuration |
| Are exceptions or unclear classifications addressed? | Procedure/records |
Common Mistakes in A.5.13
1. Confusing Classification with Labelling
Classification determines the sensitivity.
Labelling communicates it.
They are related but not identical.
2. Adding “Confidential” Without Defining What It Means
A label by itself does not provide security.
Employees need to know:
“What am I supposed to do because this is confidential?”
3. Relying Only on File Names
Adding CONFIDENTIAL to a filename does not prevent unauthorized access.
Access controls, storage controls, and sharing restrictions are still required.
4. No Consistent Labelling
One employee writes:
CONFIDENTIAL
Another writes:
PRIVATE
Another writes:
SECRET
This creates confusion.
Use a defined organizational classification vocabulary.
5. Labelling Everything
If every document is labelled CONFIDENTIAL, employees may stop paying attention.
Classification and labelling should be risk-based.
6. Forgetting Physical Information
Organizations sometimes implement digital labelling but ignore:
- Printed contracts
- Printed audit reports
- Meeting documents
- Physical records
Where physical information exists, appropriate labelling should be considered.
7. No Employee Training
Employees cannot consistently apply labels if they do not understand the classification system.
8. No Relationship Between Labels and Controls
The organization labels information as Restricted but does not restrict access.
This creates a gap between the documented process and actual security.
9. Ignoring Third-Party Information
Customer or partner information may already have contractual or classification requirements.
The organization should consider these requirements when handling and labelling such information.
Practical Startup Implementation Model
A simple startup implementation can use:
Define → Classify → Label → Handle → Train → Monitor
Define
Create classification levels and labelling rules.
↓
Classify
Determine the sensitivity of information.
↓
Label
Clearly communicate the classification.
↓
Handle
Apply appropriate storage, access, sharing, and transfer controls.
↓
Train
Teach employees how to recognize and handle labels.
↓
Monitor
Review samples and improve the process when necessary.
Policy vs. Process vs. Evidence
| Component | Example |
|---|---|
| Policy | Defines the organization’s information labelling principles |
| Classification Scheme | Public / Internal / Confidential / Restricted |
| Labelling Standard | Defines the exact labels and placement |
| Procedure | Explains when and how labels are applied |
| Handling Rules | Defines what users can do with each classification |
| Templates | Automatically include appropriate labels |
| Training | Teaches employees to recognize and use labels |
| Technical Controls | DLP, metadata, access controls, automated classification |
| Evidence | Labelled documents, configurations, training records, review results |
Relationship with Other ISO 27001 Controls
A.5.12 – Classification of Information
Determines the appropriate classification.
A.5.13 – Labelling of Information
Communicates the classification.
A.5.14 – Information Transfer
Defines how information should be protected when transferred.
A.5.15 – Access Control
Helps determine who should have access to sensitive information.
A.5.18 – Access Rights
Ensures access rights are appropriately assigned and reviewed.
A.7.10 – Storage Media
Addresses protection of information stored on media.
A.8.12 – Data Leakage Prevention
Helps prevent unauthorized disclosure of sensitive information.
A.8.10 – Information Deletion
Supports secure disposal of information when it is no longer required.
Useful Resources
Recommended Documents
- [Insert Draft Document Link – Information Classification Policy]
- [Insert Draft Document Link – Information Labelling Standard]
- [Insert Draft Document Link – Information Handling Procedure]
- [Insert Draft Document Link – Information Classification Register]
- [Insert Draft Document Link – Confidential Document Template]
- [Insert Draft Document Link – Restricted Document Template]
- [Insert Draft Document Link – Information Classification Training]
Final Takeaway
ISO 27001 Annex A 5.13 ensures that the classification of information is clearly communicated to people who create, access, use, store, or share that information.
A simple relationship is:
A.5.12 = Decide the classification
A.5.13 = Communicate the classification
A.5.14 = Protect information when it is transferred
For a startup, the implementation does not need to be complicated.
A practical approach is:
Classify → Label → Handle → Train → Monitor
The key audit question is not simply:
“Do your documents have labels?”
It is:
“Can you demonstrate that your information classification is clearly communicated and that employees understand what those labels require them to do?”
That connection between classification, labelling, handling requirements, and actual employee behaviour is what makes A.5.13 an effective security control rather than just a document exercise.
