Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.13

Labelling of Information: A Practical Implementation Guide

Make information sensitivity visible and machine-readable so handling rules follow the information.

Labelling translates classification decisions into markings or metadata that help people and systems apply appropriate protection.

Practical interpretation: Labels must be consistent, usable and connected to action. A watermark that nobody understands or metadata that systems ignore adds little value.

What should the control achieve?

  • Labelling rules correspond to the classification scheme.
  • Labels are applied at suitable points in the lifecycle.
  • People understand visible labels.
  • Systems use metadata where practical to enforce handling.

Step-by-step implementation

1

Define label formats

Choose visible markings, headers, footers, metadata or repository fields by information type.

2

Set responsibility

Clarify when authors, owners or automated systems apply and change labels.

3

Integrate tools

Configure office suites, email, repositories and DLP where proportionate.

4

Address unlabeled information

Define default treatment and a process for legacy data.

5

Train users

Demonstrate how labels affect sharing, storage and disposal.

6

Monitor quality

Sample records for missing, incorrect or inconsistent labels.

What this could look like in practice

Documents use visible classification in the header while email and cloud files carry metadata. Restricted files cannot be shared externally without approval. Public labels are applied only after content owner release.

ActivityPractical implementationEvidence
DocumentTemplate prompts for classification and displays a header.File and metadata
EmailSensitivity selection triggers external-recipient warning.Mail audit log
Legacy repositoryOwner samples and bulk-labels high-risk folders.Migration record

Implementation evidence

  • Labelling procedure
  • Approved label set
  • Templates
  • Tool configuration
  • Labeled samples
  • User guidance
  • Quality reviews
  • Exception records

Useful metrics

  • Required records labeled
  • Incorrect-label rate
  • DLP actions triggered by labels
  • Legacy data reviewed

Common mistakes

  • Labels that do not match classification levels.
  • Relying only on visual markings.
  • No process to change labels.
  • Making labels so burdensome users avoid them.
  • Ignoring paper and exported data.

Questions an auditor may ask

  • When must information be labeled?
  • How do systems use labels?
  • How is legacy information treated?
  • Show a label change after reclassification.
Implementation test: Trace one labeled file through email, cloud storage, export and disposal and verify protection follows it.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.