isms.coach
← All controls

A.5.14 · Organizational

Information transfer

Why it matters

Most real breaches involve information moving somewhere it shouldn't — email, file share, or a partner's system.

How a self-led small team implements it

Document how sensitive data moves between you, customers, and vendors, and what's encrypted in transit.

What auditors expect to see

Data flow diagram, encryption-in-transit confirmation.

Track A.5.14 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls