ISO/IEC 27001:2022 Annex A · Control 5.14
Information Transfer: A Practical Implementation Guide
Protect information whenever it moves between people, systems, organizations or physical locations.
This control covers rules, agreements and safeguards for transferring information through electronic, physical and verbal channels.
What should the control achieve?
- Transfer methods are approved by classification and risk.
- Recipients and destinations are verified.
- External transfers have suitable agreements.
- Transfers are traceable and incidents are handled.
Step-by-step implementation
Map transfer scenarios
Include email, APIs, file sharing, removable media, couriers, calls and in-person disclosure.
Define channel rules
Match classification to encryption, authentication, approval and tracking requirements.
Verify recipients
Use address checks, callback procedures, access expiry and least privilege.
Establish agreements
Cover purpose, security, onward transfer, retention, breach reporting and deletion.
Protect physical transfer
Use packaging, trusted couriers, tracking and chain of custody.
Monitor and improve
Review logs, misdirected transfers, exceptions and supplier performance.
What this could look like in practice
A legal team sends Restricted case files through an approved encrypted portal with MFA and 14-day expiry. The recipient is confirmed by phone using a known number. Email attachments are prohibited for this class.
| Activity | Practical implementation | Evidence |
|---|---|---|
| External file transfer | Approved portal, named recipients and expiry. | Portal audit log |
| API exchange | Mutual authentication and contract-defined fields. | API configuration and agreement |
| Physical media | Encrypted media, tamper-evident packaging and tracked courier. | Chain-of-custody record |
Implementation evidence
- Transfer policy
- Approved-channel matrix
- Data-sharing agreements
- Recipient-verification procedure
- Encryption configuration
- Transfer logs
- Courier records
- Transfer incident reviews
Useful metrics
- Transfers using approved channels
- Misdirected information incidents
- Expired shares still active
- Supplier transfer exceptions
Common mistakes
- Allowing convenience tools without assessment.
- Sending passwords in the same channel as files.
- Failing to verify auto-completed recipients.
- Ignoring verbal and physical transfers.
- Leaving external links open indefinitely.
Questions an auditor may ask
- Which channels are approved for each classification?
- How are recipients verified?
- Show an external transfer agreement.
- How are transfer logs and incidents reviewed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.