What is ISO 27001 Annex A 5.14 – Information Transfer?
ISO 27001 Annex A 5.14 – Information Transfer is about protecting information when it is transferred within the organization or between the organization and external parties.
Information is constantly being transferred through:
- Cloud storage
- Messaging applications
- File-sharing platforms
- APIs
- SFTP
- Collaboration tools
- Customer portals
- Vendor platforms
- Physical media
- Printed documents
- Video conferencing
- Business applications
The organization needs to establish appropriate rules and controls so that information is transferred securely.
Information transfer can occur between:
- Employees
- Departments
- Customers
- Vendors
- Contractors
- Business partners
- Auditors
- Consultants
- Regulators
- Cloud service providers
Simple Explanation
A.5.14 asks: “When we send information from one place or person to another, how do we make sure it reaches the right recipient and remains protected during the transfer?”
Why is A.5.14 Important?
Information can be secure while stored but become exposed during transfer.
For example:
A company securely stores customer data in its cloud environment.
An employee downloads the data and sends it to a personal Gmail account.
The company’s storage controls may be strong, but the transfer has introduced a new risk.
Common information-transfer risks
- Sending information to the wrong recipient
- Unauthorized interception
- Accidental disclosure
- Use of personal email
- Unapproved file-sharing services
- Sending sensitive information without encryption
- Weak passwords for shared files
- Insecure APIs
- Sharing information with unauthorized third parties
- Using removable media without adequate protection
- Lack of evidence showing what was transferred
Simple Principle
Protect information not only when it is stored, but also when it is being transferred.
What Does A.5.14 Require?
The organization should establish rules, procedures, and agreements for secure information transfer.
These should address information transferred:
Internally
For example:
- Employee to employee
- Department to department
- Development to security
- Finance to management
Externally
For example:
- Customer to company
- Company to customer
- Company to vendor
- Company to auditor
- Company to business partner
The appropriate controls should depend on:
- Information classification
- Sensitivity
- Transfer method
- Recipient
- Business purpose
- Legal requirements
- Contractual requirements
- Security risks
Information Transfer and Classification
A.5.14 works closely with A.5.12 and A.5.13.
A.5.12
Determines how sensitive the information is.
A.5.13
Communicates the classification.
A.5.14
Defines how the information should be transferred securely.
For example:
Customer Security Report
↓
Classification: Confidential
↓
Transfer requirement: Approved secure file-sharing platform
↓
Recipient: Authorized customer contact
↓
Access: Restricted
This creates a practical security chain.
Types of Information Transfer
1. Email
Email is one of the most common methods of information transfer.
Organizations should define rules for sending sensitive information by email.
Possible controls include:
- Verify recipient addresses
- Use approved business email
- Avoid personal email accounts
- Encrypt sensitive attachments where required
- Use password-protected files when appropriate
- Avoid sending passwords in the same communication
- Check distribution lists before sending
- Use appropriate classification labels
2. Cloud File Sharing
Examples include:
- SharePoint
- OneDrive
- Google Drive
- Dropbox
- Other approved enterprise platforms
Controls may include:
- Access restrictions
- Expiration dates
- Password protection
- Download restrictions
- External-sharing controls
- Audit logging
- MFA
3. APIs
Modern SaaS companies frequently transfer information through APIs.
Security controls may include:
- HTTPS/TLS
- Authentication
- Authorization
- API keys
- OAuth
- Rate limiting
- Logging
- Monitoring
- Input validation
Sensitive information should not be transferred through insecure or unnecessary API channels.
4. SFTP / Secure File Transfer
SFTP may be used for larger or recurring file transfers.
Examples:
- Customer reports
- Financial files
- Payroll files
- Data exports
- Vendor data exchange
Organizations should control:
- User access
- Authentication
- Encryption
- File permissions
- Retention
- Logging
5. Physical Media
Information may be transferred through:
- USB drives
- External hard drives
- CDs/DVDs
- Printed documents
Where physical media is used, appropriate controls should be defined.
For example:
- Encryption
- Physical protection
- Authorized personnel
- Secure transportation
- Tracking
- Secure disposal
6. Messaging Applications
Employees may use:
- Microsoft Teams
- Slack
- Business messaging platforms
- Other collaboration tools
The organization should define what information can be shared through these platforms.
For example:
Public → Generally acceptable
Internal → Approved business collaboration platform
Confidential → Only approved channels
Restricted → May require additional controls
The exact rules should depend on the organization’s risk assessment.
Activities Required to Implement A.5.14
Step 1: Identify Information Transfer Methods
Identify how information moves in the organization.
For example:
| Method | Internal/External | Example |
|---|---|---|
| Both | Customer communication | |
| Cloud storage | Both | Document sharing |
| API | Both | SaaS integration |
| SFTP | External | Customer file exchange |
| Teams/Slack | Internal/External | Collaboration |
| Physical media | Both | Data transfer |
| Customer portal | External | Report delivery |
Step 2: Identify Sensitive Information
Use the organization’s classification scheme.
For example:
- Public
- Internal
- Confidential
- Restricted
The transfer requirements should become stronger as information sensitivity increases.
Step 3: Define Approved Transfer Methods
Create an approved-channel list.
Example:
| Information | Approved Transfer Method |
|---|---|
| Public | Email, website, approved public platforms |
| Internal | Corporate email, approved collaboration tools |
| Confidential | Approved secure file sharing, encrypted transfer |
| Restricted | Controlled secure transfer with additional authorization |
Step 4: Define Transfer Rules
The organization should establish practical rules.
Examples:
Before transferring information
- Confirm the recipient
- Confirm the business purpose
- Check classification
- Verify authorization
During transfer
- Use approved channels
- Apply encryption where required
- Protect credentials
- Avoid unauthorized platforms
After transfer
- Remove unnecessary access
- Expire sharing links
- Maintain logs where appropriate
- Follow retention requirements
Step 5: Define External Transfer Requirements
External information transfers should receive particular attention.
Before sending confidential information to a third party, consider:
- Is the recipient authorized?
- Is there a valid business purpose?
- Is a contract or NDA required?
- Is the transfer legally permitted?
- Is the transfer method secure?
- Is encryption required?
- Is the recipient’s identity verified?
- How long will the recipient retain the information?
Step 6: Establish Agreements
Where appropriate, information-transfer requirements should be included in agreements with:
- Customers
- Vendors
- Partners
- Contractors
- Service providers
- Auditors
Agreements may address:
- Information classification
- Security requirements
- Confidentiality
- Approved transfer mechanisms
- Encryption
- Data retention
- Incident notification
- Data deletion
Step 7: Protect Information During Transfer
Depending on the risk, controls may include:
- TLS
- Encryption
- VPN
- SFTP
- Secure portals
- MFA
- Password-protected files
- Access-controlled cloud links
- Digital signatures
- Authentication
- Authorization
The control should be appropriate to the sensitivity and risk.
Step 8: Prevent Accidental Disclosure
Employees should be trained to check:
Recipient
Is this the correct person?
Attachment
Is this the correct file?
Classification
Is the information sensitive?
Channel
Am I using an approved method?
Authorization
Is the recipient authorized to receive it?
This simple check can prevent many information-transfer incidents.
Step 9: Monitor and Maintain Evidence
Where appropriate, organizations should maintain:
- Transfer logs
- Email security logs
- File-sharing logs
- API logs
- SFTP logs
- Access logs
- Approval records
- Data-transfer agreements
Not every transfer needs to be manually recorded.
The organization should determine what logging and evidence are appropriate based on risk.
Startup Example
Consider a SaaS startup that needs to send a SOC 2 evidence package to an external auditor.
The evidence contains confidential company information.
Incorrect approach
Employee downloads all documents and sends them through personal email.
Better approach
1. Identify information
SOC 2 evidence package.
↓
2. Determine classification
Confidential.
↓
3. Identify authorized recipient
Approved auditor contact.
↓
4. Select approved transfer method
Secure company file-sharing platform.
↓
5. Restrict access
Only the auditor receives access.
↓
6. Protect the transfer
MFA / access-controlled link / encryption where appropriate.
↓
7. Expire access
Remove access after the engagement or when no longer required.
Practical Flow
Classify → Verify → Approve → Transfer Securely → Monitor → Remove Access
Example Information Transfer Matrix
| Scenario | Information | Classification | Recommended Approach |
|---|---|---|---|
| Marketing team publishes blog | Blog | Public | Approved public channel |
| HR sends employee document internally | Employee information | Confidential | Approved corporate system |
| Sales sends contract to customer | Contract | Confidential | Approved secure email/file sharing |
| Security team sends credentials | Credentials | Restricted | Approved secrets-management mechanism |
| Engineering sends API data | Customer/system data | Based on classification | Authenticated encrypted API |
| Company sends audit evidence to auditor | Audit evidence | Confidential | Secure file-sharing platform |
Startup-Focused Quick Summary
A startup does not need complicated information-transfer procedures.
Start with five questions:
1. What are we transferring?
Identify the information.
2. How sensitive is it?
Check the classification.
3. Who is receiving it?
Verify the recipient and authorization.
4. Which channel are we using?
Use an approved transfer method.
5. How do we protect it?
Apply appropriate controls such as encryption, authentication, access restrictions, and expiration.
Simple Startup Rule
Never transfer sensitive information simply because a particular communication method is convenient.
Example Secure Information Transfer Procedure
A simple procedure could require employees to:
- Confirm the information classification.
- Confirm the recipient’s identity.
- Confirm the recipient is authorized.
- Select an approved transfer method.
- Apply encryption or other protection when required.
- Verify the correct file or information is being sent.
- Remove temporary access after the transfer when appropriate.
- Report accidental or unauthorized transfers immediately.
Audit Evidence for A.5.14
An auditor may ask:
“How does your organization ensure information is transferred securely?”
Useful evidence includes:
Policies
- Information Transfer Policy
- Information Security Policy
- Data Handling Policy
- Acceptable Use Policy
Procedures
- Secure Information Transfer Procedure
- External Data Sharing Procedure
- Secure File Transfer Procedure
Agreements
- NDA
- Customer agreements
- Vendor agreements
- Data Processing Agreements
- Information-sharing agreements
Technical Evidence
- Email encryption configuration
- TLS configuration
- SFTP configuration
- Secure file-sharing configuration
- DLP configuration
- Access-control settings
- API security configuration
- MFA configuration
Operational Evidence
- File-sharing logs
- SFTP logs
- API logs
- Email security logs
- Transfer approvals
- Access-expiration records
A.5.14 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has the organization identified important information-transfer methods? | Transfer inventory |
| Is there a secure information-transfer procedure? | Procedure |
| Are transfer requirements based on information classification? | Classification/handling rules |
| Are approved transfer channels defined? | Approved-channel list |
| Are external transfers controlled? | External transfer procedure |
| Are recipients verified before sensitive information is transferred? | Procedure/training |
| Is encryption used where required? | Technical configuration |
| Are third-party transfer requirements documented? | Contracts/NDA/DPA |
| Are employees trained on secure information transfer? | Training records |
| Are information-transfer activities logged where appropriate? | System logs |
| Are temporary sharing permissions removed when no longer required? | Access records |
| Are accidental transfers reported and handled? | Incident records |
| Are legal and contractual requirements considered? | Compliance/contract review |
Common Mistakes in A.5.14
1. Assuming Email Is Always Secure Enough
Business email may have appropriate security controls, but the sensitivity of the information and transfer requirements should still be considered.
2. Sending Sensitive Files to Personal Email
This bypasses organizational security controls and can create significant information leakage risks.
3. Using Personal Cloud Storage
Employees may upload company information to personal:
- Google Drive
- Dropbox
- OneDrive
- Other storage accounts
Organizations should define approved storage and transfer platforms.
4. Sending Password and File Together
For sensitive files protected by a password, sending the password through the same channel as the file may reduce the effectiveness of the protection.
Use an appropriately separate communication method where required.
5. No Recipient Verification
A single incorrect email address can result in a data disclosure.
Employees should verify recipients before sending sensitive information.
6. Using Public Links
A link such as:
“Anyone with the link can access”
may be inappropriate for confidential information.
Use named recipients and restricted access where appropriate.
7. No Expiration of Temporary Access
If an external party only needs access for five days, leaving access open indefinitely creates unnecessary risk.
8. Ignoring APIs
Modern organizations frequently transfer information through APIs.
API-based transfers should also be considered within the organization’s information-transfer controls.
9. No Third-Party Requirements
A company may have strong internal transfer controls but fail to define how vendors or partners should receive sensitive information.
10. No Evidence
A company may have a secure-transfer policy but be unable to demonstrate that employees actually use approved methods.
Practical Startup Implementation Model
A simple startup model is:
Identify → Classify → Verify → Protect → Transfer → Monitor
Identify
What information is being transferred?
↓
Classify
How sensitive is it?
↓
Verify
Who is receiving it and are they authorized?
↓
Protect
What controls are required?
↓
Transfer
Use an approved channel.
↓
Monitor
Maintain appropriate logs, review access, and remove temporary permissions.
Policy vs. Process vs. Evidence
| Component | Example |
|---|---|
| Policy | Defines secure information-transfer principles |
| Classification Rules | Defines requirements based on information sensitivity |
| Procedure | Explains how employees securely transfer information |
| Approved Channels | Corporate email, secure file sharing, SFTP, approved APIs |
| Agreements | NDA, DPA, customer/vendor security requirements |
| Technical Controls | Encryption, MFA, TLS, DLP, access restrictions |
| Training | Teaches employees how to transfer information securely |
| Evidence | Logs, approvals, configurations, agreements, training records |
Relationship with Other ISO 27001 Controls
A.5.12 – Classification of Information
Determines how sensitive information is.
A.5.13 – Labelling of Information
Communicates the classification.
A.5.14 – Information Transfer
Defines how information should be securely transferred.
A.5.10 – Acceptable Use of Information and Other Associated Assets
Defines appropriate use of organizational information.
A.5.15 – Access Control
Ensures information is accessible only to authorized users.
A.5.19 – Information Security in Supplier Relationships
Addresses security requirements involving suppliers.
A.5.20 – Addressing Information Security Within Supplier Agreements
Helps establish security requirements for information shared with suppliers.
A.5.31 – Legal, Statutory, Regulatory and Contractual Requirements
Transfer requirements may be influenced by legal, regulatory, and contractual obligations.
A.8.12 – Data Leakage Prevention
Supports prevention and detection of unauthorized information transfers.
Useful Resources
Recommended Documents
- [Insert Draft Document Link – Information Transfer Policy]
- [Insert Draft Document Link – Secure Information Transfer Procedure]
- [Insert Draft Document Link – External Data Sharing Procedure]
- [Insert Draft Document Link – Approved Information Transfer Channels]
- [Insert Draft Document Link – Third-Party Information Sharing Agreement]
- [Insert Draft Document Link – Secure File Transfer Checklist]
- [Insert Draft Document Link – Information Transfer Training]
Final Takeaway
ISO 27001 Annex A 5.14 is about protecting information while it moves.
An organization should be able to answer:
What information are we transferring?
How sensitive is it?
Who is receiving it?
Are they authorized?
Which transfer method are we using?
What security controls protect the transfer?
A practical implementation is:
Identify → Classify → Verify → Protect → Transfer → Monitor
For startups, A.5.14 does not mean creating complicated bureaucracy around every email or file transfer.
It means establishing clear, risk-based rules for transferring sensitive information through approved channels, while ensuring employees understand how to protect information when sharing it internally or externally.
