A.5.14 A.5 · Organisational Controls

A.5.14 — Information transfer

Define, implement and manage rules and controls for information transfer, covering all transfer types and channels.

Also written as A5.14, Annex A 5.14, ISO 27001:2022 A.5.14, ISO27001 A.5.14.

What ISO 27001 A.5.14 requires

Information transfer is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Define, implement and manage rules and controls for information transfer, covering all transfer types and channels. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.5.14, gather artefacts such as:

  • Information transfer policy
  • Encryption standards for data in transit (TLS, SFTP, encrypted email)
  • Signed NDAs or data transfer agreements
  • Secure file transfer tool configuration and usage logs

How A.5.14 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.5.14 aligns with:

SOC 2: CC6.7 Protection of data in transmission and movement, C1.1 Identification and protection of confidential information

NIST CSF 2.0: GV.SC-05 Supply chain requirements in contracts, PR.DS-02 Data-in-transit protection

ISO 27001:2013 mapping

A.5.14 consolidates the following ISO 27001:2013 control(s): A.13.2.1, A.13.2.2, A.13.2.3. If you are transitioning an existing ISMS, map your prior evidence for these to A.5.14 in your updated SoA.

Map A.5.14 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.5.14 in the Risk Register.

Related Annex A controls

A.8.12 Data leakage prevention A.5.23 Information security for use of cloud services A.6.7 Remote working A.7.10 Storage media A.8.24 Use of cryptography A.6.6 Confidentiality or non-disclosure agreements

See all 37 Organisational Controls →

Frequently asked questions

Is ISO 27001 A.5.14 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.14 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.5.14?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.5.14 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.5.14 map to in SOC 2 and NIST CSF?

A.5.14 aligns with SOC 2 CC6.7, C1.1 and NIST CSF GV.SC-05, PR.DS-02. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

What was A.5.14 in ISO 27001:2013?

A.5.14 consolidates 3 control(s) from the 2013 edition: A.13.2.1, A.13.2.2, A.13.2.3. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.