A.5.14
    Organizational Controls

    Information transfer

    Information transfer rules, procedures, or agreements should be in place for all types of transfer facilities within the organization and between the organization and other parties.

    Purpose

    To maintain the security of information transferred within an organization and with external parties.

    Implementation Guidance

    Define policies for secure information transfer methods

    Use encryption for sensitive data in transit

    Implement secure file transfer protocols (SFTP, HTTPS)

    Establish procedures for physical media transfer

    Monitor and log information transfers where appropriate

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.14 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.14 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.14 Information transfer. Built for compliance professionals.

    Try ISMS Copilot free