ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.13 Labelling of information

ISO 27001 Annex A 5.13 Labelling of information

What is ISO 27001 Annex A 5.13 – Labelling of Information?

ISO 27001 Annex A 5.13 – Labelling of Information is about clearly communicating the classification of information so that people know how information should be handled.

A.5.12 determines how information is classified.

A.5.13 focuses on how that classification is communicated or displayed.

For example, if a document has been classified as:

CONFIDENTIAL

that classification should be communicated through an appropriate label, marking, metadata, or other mechanism.

Labelling helps employees understand:

  • How sensitive information is
  • Who should have access to it
  • Whether it can be shared externally
  • How it should be stored
  • How it should be transferred
  • What handling restrictions apply
  • What security precautions are required

Examples of information labels

  • PUBLIC
  • INTERNAL
  • CONFIDENTIAL
  • RESTRICTED

Depending on the organization’s classification scheme, other labels may be used.

Simple Explanation

A.5.12 decides the classification. A.5.13 makes that classification visible or understandable to the people handling the information.


Why is A.5.13 Important?

Information can be correctly classified but still mishandled if employees cannot easily identify its classification.

For example:

A company classifies a customer contract as Confidential.

However, the document has no visible indication that it is confidential.

An employee may:

  • Upload it to an unrestricted folder
  • Send it to the wrong recipient
  • Share it with an external party
  • Store it in an unauthorized application
  • Print and leave it unattended

Labelling helps reduce this risk by making the required handling level easier to recognize.


What Does A.5.13 Require?

The organization should establish appropriate procedures for labelling information in accordance with its information classification scheme.

The labelling approach should be:

  • Consistent
  • Practical
  • Understandable
  • Appropriate to the type of information
  • Applied throughout the information lifecycle where relevant
  • Supported by appropriate technical or procedural controls

The organization should determine what needs to be labelled, how it should be labelled, and where the label should appear.

ISO 27001 does not require one specific labelling format.

For example, an organization may use:

CONFIDENTIAL

in a document header and footer.

Another organization may use:

Classification: Confidential

in document metadata.

Both approaches can be appropriate if they effectively communicate the required classification.


Classification vs. Labelling

This distinction is important for an ISO 27001 audit.

A.5.12 – ClassificationA.5.13 – Labelling
Determines the sensitivity of informationCommunicates the classification
Answers “How sensitive is it?”Answers “How do people know?”
Defines classification levelsDefines labels/markings
Based on risk and information security needsBased on practical communication
Example: ConfidentialExample: “CONFIDENTIAL” in document header

Simple Example

A customer contract is assessed as:

Classification → Confidential

The document is then marked:

Label → CONFIDENTIAL

The handling rules may say:

Handling → Authorized personnel only; approved storage; controlled external sharing.


What Information Can Be Labelled?

Labelling can apply to many forms of information.

Documents

  • Policies
  • Contracts
  • Reports
  • Financial documents
  • Audit reports
  • Customer documentation

Spreadsheets

  • Customer databases
  • Financial records
  • Employee information
  • Risk registers
  • Compliance registers

Presentations

  • Investor presentations
  • Product roadmaps
  • Business strategy
  • Internal management presentations

Emails

For example:

Subject: CONFIDENTIAL – Customer Contract Review

Physical Documents

A printed document may contain:

CONFIDENTIAL

in the header or footer.

Digital Systems

Classification can also be communicated through:

  • Metadata
  • File properties
  • Document management systems
  • Data classification tools
  • DLP platforms
  • Information protection platforms

Activities Required to Implement A.5.13

Step 1: Define the Classification Scheme

A.5.13 depends on A.5.12.

For example:

LevelMeaning
PublicApproved for public disclosure
InternalIntended for internal business use
ConfidentialSensitive information requiring controlled access
RestrictedHighly sensitive information requiring strict controls

Step 2: Define Labelling Rules

Define how each classification should be displayed.

For example:

ClassificationLabel
PublicPUBLIC
InternalINTERNAL
ConfidentialCONFIDENTIAL
RestrictedRESTRICTED

The organization can define whether labels appear:

  • At the top of documents
  • At the bottom of documents
  • In headers and footers
  • In file names
  • In email subject lines
  • In metadata
  • In application interfaces

Step 3: Define Which Information Requires Labelling

Not every piece of information needs the same labelling mechanism.

For example:

Documents

Use headers and footers.

Emails

Use subject-line labels where appropriate.

Database records

Use metadata or system-level classification.

Physical documents

Use visible markings.

Cloud repositories

Use metadata, folder controls, or information-protection capabilities.

The approach should be practical for the organization’s environment.


Step 4: Define Handling Requirements

A label is useful only when employees understand what it means.

For example:

CONFIDENTIAL

Employees may be required to:

  • Store it only in approved systems
  • Share it only with authorized personnel
  • Avoid using personal email
  • Avoid uploading it to unauthorized applications
  • Use approved methods for external transfer

RESTRICTED

Additional controls may include:

  • Strict need-to-know access
  • Strong authentication
  • Encryption
  • Restricted external sharing
  • Additional monitoring

Step 5: Implement Labelling

Depending on the organization’s technology, labelling can be:

Manual

Employees select the classification when creating or saving a document.

Template-Based

Templates automatically include:

CONFIDENTIAL

in the header/footer.

Automated

Technology automatically classifies or labels information based on:

  • Data patterns
  • Content
  • Metadata
  • User selection
  • Document type
  • Business rules

For startups, manual or template-based labelling may be sufficient initially.


Step 6: Train Employees

Employees should understand:

  • What the labels mean
  • When to apply them
  • How to apply them
  • How labelled information should be handled
  • When information can be reclassified
  • What to do if classification is unclear

Training should include real examples.


Step 7: Address Information Sharing

Employees should understand what each label means when sharing information.

For example:

PUBLIC

May be shared externally if approved.

INTERNAL

Should generally remain within the organization.

CONFIDENTIAL

External sharing may require authorization.

RESTRICTED

External sharing may require explicit approval and additional security controls.


Step 8: Consider the Full Information Lifecycle

Labelling should not only apply when information is created.

Consider:

Create → Store → Use → Share → Archive → Dispose

For example:

A confidential customer report should remain appropriately identified when:

  • Stored
  • Downloaded
  • Emailed
  • Printed
  • Archived
  • Transferred to another system

Startup Example

Consider a SaaS startup that has implemented four classification levels:

Public → Internal → Confidential → Restricted

The company creates a customer contract.

Step 1 – Classification

The contract is classified as:

CONFIDENTIAL

Step 2 – Labelling

The document automatically displays:

CONFIDENTIAL

in the header and footer.

Step 3 – Storage

The contract is stored in the company’s approved document repository.

Step 4 – Access

Only authorized Sales, Legal, Finance, and Management users have access.

Step 5 – Sharing

If the contract needs to be shared externally, employees follow the approved information-sharing process.

Step 6 – Retention/Disposal

The contract is retained according to the applicable retention requirements and securely disposed of when no longer required.

Practical Flow

Classify → Label → Store → Access → Share → Retain/Dispose


Example Document Labelling

A confidential document could look like:

CONFIDENTIAL

Customer Security Assessment Report

Prepared for: ABC Technologies

Classification: Confidential


At the bottom:

CONFIDENTIAL – Authorized use only

The exact wording can be defined by the organization.


Example Email Labelling

For sensitive information, the organization may use:

Subject: CONFIDENTIAL – Customer Security Assessment

The email body could include:

This information is intended only for authorized recipients. Please do not forward or share without appropriate authorization.

The exact wording should be defined by the organization’s information handling requirements.


Example File Naming Convention

An organization could use:

CONFIDENTIAL_Customer_Contract_ABC_2026.pdf

or:

Restricted_Production_Access_List.xlsx

However, file naming should not be the organization’s only protection mechanism.

A filename can communicate classification, but it does not enforce access control.


Startup-Focused Quick Summary

A startup can implement A.5.13 without buying expensive software.

Basic approach:

1. Define classification levels

Public / Internal / Confidential / Restricted

2. Define labels

PUBLIC / INTERNAL / CONFIDENTIAL / RESTRICTED

3. Add labels to important documents

Use templates and document headers/footers.

4. Define email handling

Use classification in subject lines where appropriate.

5. Define handling rules

Explain what employees can and cannot do with each classification.

6. Train employees

Show real examples.

7. Keep evidence

Maintain labelled documents, templates, training records, and procedures.


Example Information Labelling Matrix

Information TypeClassificationLabelling MethodExample
Website contentPublicNone/optionalPublic
Internal procedureInternalHeader/footerINTERNAL
Customer contractConfidentialHeader/footer + metadataCONFIDENTIAL
Product roadmapConfidentialHeader/footerCONFIDENTIAL
Production credentialsRestrictedSystem metadata/access controlsRESTRICTED
Customer sensitive dataConfidential/RestrictedSystem-level classificationCONFIDENTIAL / RESTRICTED

Audit Evidence for A.5.13

An auditor may ask:

“How do employees know the classification of information they are handling?”

Useful evidence includes:

Policies

  • Information Classification Policy
  • Information Labelling Policy
  • Information Handling Policy

Procedures

  • Information Labelling Procedure
  • Document Handling Procedure
  • Information Sharing Procedure

Templates

  • Confidential document template
  • Restricted document template
  • Approved report templates
  • Email templates

Operational Evidence

  • Sample labelled documents
  • Sample confidential reports
  • Sample contracts
  • Email examples
  • Screenshots of classification settings
  • Document management configurations

Training Evidence

  • Security awareness training
  • Information classification training
  • Employee acknowledgement

Technical Evidence

  • Microsoft Purview or equivalent classification configuration
  • DLP configuration
  • Document-management metadata
  • Automated classification rules
  • Access-control configuration

A.5.13 Audit Checklist

Audit QuestionEvidence
Has the organization defined information classification levels?Classification policy
Has the organization defined labelling requirements?Labelling procedure
Are labels consistent with the classification scheme?Policy + samples
Are sensitive documents labelled appropriately?Sample documents
Are employees trained on information labels?Training records
Are handling requirements linked to classifications?Handling procedure
Are physical documents addressed where applicable?Physical document procedure
Are emails and electronic communications addressed?Email handling guidance
Are cloud systems and SaaS platforms considered?System configuration
Are labels retained when information is shared or transferred?Sample evidence
Is automated labelling used where appropriate?Technical configuration
Are exceptions or unclear classifications addressed?Procedure/records

Common Mistakes in A.5.13

1. Confusing Classification with Labelling

Classification determines the sensitivity.

Labelling communicates it.

They are related but not identical.


2. Adding “Confidential” Without Defining What It Means

A label by itself does not provide security.

Employees need to know:

“What am I supposed to do because this is confidential?”


3. Relying Only on File Names

Adding CONFIDENTIAL to a filename does not prevent unauthorized access.

Access controls, storage controls, and sharing restrictions are still required.


4. No Consistent Labelling

One employee writes:

CONFIDENTIAL

Another writes:

PRIVATE

Another writes:

SECRET

This creates confusion.

Use a defined organizational classification vocabulary.


5. Labelling Everything

If every document is labelled CONFIDENTIAL, employees may stop paying attention.

Classification and labelling should be risk-based.


6. Forgetting Physical Information

Organizations sometimes implement digital labelling but ignore:

  • Printed contracts
  • Printed audit reports
  • Meeting documents
  • Physical records

Where physical information exists, appropriate labelling should be considered.


7. No Employee Training

Employees cannot consistently apply labels if they do not understand the classification system.


8. No Relationship Between Labels and Controls

The organization labels information as Restricted but does not restrict access.

This creates a gap between the documented process and actual security.


9. Ignoring Third-Party Information

Customer or partner information may already have contractual or classification requirements.

The organization should consider these requirements when handling and labelling such information.


Practical Startup Implementation Model

A simple startup implementation can use:

Define → Classify → Label → Handle → Train → Monitor

Define

Create classification levels and labelling rules.

↓

Classify

Determine the sensitivity of information.

↓

Label

Clearly communicate the classification.

↓

Handle

Apply appropriate storage, access, sharing, and transfer controls.

↓

Train

Teach employees how to recognize and handle labels.

↓

Monitor

Review samples and improve the process when necessary.


Policy vs. Process vs. Evidence

ComponentExample
PolicyDefines the organization’s information labelling principles
Classification SchemePublic / Internal / Confidential / Restricted
Labelling StandardDefines the exact labels and placement
ProcedureExplains when and how labels are applied
Handling RulesDefines what users can do with each classification
TemplatesAutomatically include appropriate labels
TrainingTeaches employees to recognize and use labels
Technical ControlsDLP, metadata, access controls, automated classification
EvidenceLabelled documents, configurations, training records, review results

Relationship with Other ISO 27001 Controls

A.5.12 – Classification of Information

Determines the appropriate classification.

A.5.13 – Labelling of Information

Communicates the classification.

A.5.14 – Information Transfer

Defines how information should be protected when transferred.

A.5.15 – Access Control

Helps determine who should have access to sensitive information.

A.5.18 – Access Rights

Ensures access rights are appropriately assigned and reviewed.

A.7.10 – Storage Media

Addresses protection of information stored on media.

A.8.12 – Data Leakage Prevention

Helps prevent unauthorized disclosure of sensitive information.

A.8.10 – Information Deletion

Supports secure disposal of information when it is no longer required.


Useful Resources

Recommended Documents

  • [Insert Draft Document Link – Information Classification Policy]
  • [Insert Draft Document Link – Information Labelling Standard]
  • [Insert Draft Document Link – Information Handling Procedure]
  • [Insert Draft Document Link – Information Classification Register]
  • [Insert Draft Document Link – Confidential Document Template]
  • [Insert Draft Document Link – Restricted Document Template]
  • [Insert Draft Document Link – Information Classification Training]

Final Takeaway

ISO 27001 Annex A 5.13 ensures that the classification of information is clearly communicated to people who create, access, use, store, or share that information.

A simple relationship is:

A.5.12 = Decide the classification
A.5.13 = Communicate the classification
A.5.14 = Protect information when it is transferred

For a startup, the implementation does not need to be complicated.

A practical approach is:

Classify → Label → Handle → Train → Monitor

The key audit question is not simply:

“Do your documents have labels?”

It is:

“Can you demonstrate that your information classification is clearly communicated and that employees understand what those labels require them to do?”

That connection between classification, labelling, handling requirements, and actual employee behaviour is what makes A.5.13 an effective security control rather than just a document exercise.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *