A.8.11
    Technological Controls

    Data masking

    Data masking should be used in accordance with the organization's topic-specific policy on access control and other related topic-specific policies and business requirements, taking applicable legislation into consideration.

    Purpose

    To limit exposure of sensitive data while maintaining usability for testing and development.

    Implementation Guidance

    Identify sensitive data requiring masking

    Implement masking in non-production environments

    Use appropriate masking techniques (tokenization, anonymization)

    Test masked data for usability

    Document masking procedures

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.11 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.11 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.11 Data masking. Built for compliance professionals.

    Try ISMS Copilot free