ISO/IEC 27001:2022 Annex A · Control 5.13
Labelling of Information: A Practical Implementation Guide
Make information sensitivity visible and machine-readable so handling rules follow the information.
Labelling translates classification decisions into markings or metadata that help people and systems apply appropriate protection.
What should the control achieve?
- Labelling rules correspond to the classification scheme.
- Labels are applied at suitable points in the lifecycle.
- People understand visible labels.
- Systems use metadata where practical to enforce handling.
Step-by-step implementation
Define label formats
Choose visible markings, headers, footers, metadata or repository fields by information type.
Set responsibility
Clarify when authors, owners or automated systems apply and change labels.
Integrate tools
Configure office suites, email, repositories and DLP where proportionate.
Address unlabeled information
Define default treatment and a process for legacy data.
Train users
Demonstrate how labels affect sharing, storage and disposal.
Monitor quality
Sample records for missing, incorrect or inconsistent labels.
What this could look like in practice
Documents use visible classification in the header while email and cloud files carry metadata. Restricted files cannot be shared externally without approval. Public labels are applied only after content owner release.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Document | Template prompts for classification and displays a header. | File and metadata |
| Sensitivity selection triggers external-recipient warning. | Mail audit log | |
| Legacy repository | Owner samples and bulk-labels high-risk folders. | Migration record |
Implementation evidence
- Labelling procedure
- Approved label set
- Templates
- Tool configuration
- Labeled samples
- User guidance
- Quality reviews
- Exception records
Useful metrics
- Required records labeled
- Incorrect-label rate
- DLP actions triggered by labels
- Legacy data reviewed
Common mistakes
- Labels that do not match classification levels.
- Relying only on visual markings.
- No process to change labels.
- Making labels so burdensome users avoid them.
- Ignoring paper and exported data.
Questions an auditor may ask
- When must information be labeled?
- How do systems use labels?
- How is legacy information treated?
- Show a label change after reclassification.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.