ISO 27001 Annex A 5.13 Labelling of information requires organisations to mark and identify data according to classification schemes. Clear labelling rules help staff identify sensitive files, follow proper handling steps, and prevent accidental data exposure.
Table of contents
Key Takeaways
- Standardise data labels: Apply clear visual and digital classification marks to all company files, documents, and assets.
- Store rules centrally: Keep information labelling guidelines, classification schemes, and handling rules in a central document repository.
- Cover physical and digital assets: Mark electronic files, database outputs, paper reports, backup media, and equipment.
- Automate labelling where possible: Use system rules to apply default classification tags and metadata to newly created documents automatically.
- Align labels with handling rules: Ensure every classification label maps directly to clear rules for sharing, encrypting, and storing files.
- Simplify label choices: Use concise, easily understood labels such as Public, Internal, Confidential, and Restricted to prevent confusion.
- Train staff on labelling: Teach workers how to mark sensitive documents and identify handling instructions from label tags.
- Review labelled assets regularly: Conduct spot checks to verify staff classify and label documents accurately according to policy.

How to Implement ISO 27001 Annex A 5.13
- Draft an information labelling policy: Write clear guidelines for labelling information and store them in your central document repository.
- Define clear label categories: Establish straightforward classification levels based on data value and potential harm if exposed.
- Apply visual markers to documents: Add standard headers, footers, and watermarks to word processing files, spreadsheets, and presentations.
- Configure digital metadata tags: Enable automated tools to embed classification tags into electronic file properties and email subjects.
- Label physical storage and printouts: Use physical sticker labels on sensitive paper binders, removable storage drives, and archive boxes.
- Set default classifications: Configure business tools to apply a standard internal label to all new documents automatically.
- Define relabelling procedures: Create a simple process for asset owners to change classification levels when data sensitivity changes.
- Train employees on marking rules: Educate workers on how to choose appropriate labels and follow associated handling safeguards.
- Audit labelling compliance: Perform periodic internal spot checks on shared drives and print areas to verify accurate labelling.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.13
- Review labelling policies: Inspect written procedures to verify standard methods exist for identifying and labelling physical and digital data.
- Sample active business documents: Inspect electronic files and email messages across departments to check for correct classification markings.
- Verify automated tagging rules: Test system configuration settings to confirm tools apply required classification metadata automatically.
- Inspect physical storage media: Check paper archives, portable drives, and backup containers to verify clear physical label placement.
- Check relabelling approvals: Review change logs to ensure asset owners formally approved requests to downgrade or upgrade classification marks.
- Interview operational staff: Speak with employees to confirm they understand what each classification label means and how to apply them.
- Check handling consistency: Verify that documents marked confidential receive appropriate controls like access restrictions and encryption.
- Review spot check reports: Inspect records from internal spot checks to confirm management tracks and resolves labelling errors.
Audit Evidence Checklist
- Information labelling policy: Maintain a documented labelling policy with complete version history in your central repository.
- Classification and labelling matrix: Provide a reference chart defining classification tiers, label formats, and handling rules.
- Automated tagging configuration logs: Supply system configuration exports showing active default labelling rules across applications.
- Sampled labelled documents: Provide examples of electronic and physical assets carrying proper classification marks.
- Relabelling request logs: Maintain records of approved classification changes and declassification reviews.
- Spot check review reports: Supply internal inspection logs checking physical desk areas and digital folders for correct labels.
- Staff training logs: Show sign-off sheets proving employees completed security awareness training on labelling information.
What to Teach Employees
- Label files at creation: Teach workers to assign a classification label as soon as they draft a new document, sheet, or email.
- Check labels before sharing: Instruct staff to review document labels to confirm external recipients are authorized to view the data.
- Do not remove classification tags: Warn employees against stripping headers, footers, or metadata tags when exporting or copying files.
- Mark physical printouts: Teach workers to place clear classification stamps or written labels on printed confidential notes and files.
- Report unlabelled sensitive files: Encourage staff to flag unlabelled files containing sensitive client or financial details to asset owners.
- Know handling rules: Ensure workers understand that higher labels require stronger safeguards like password locks and clean desks.
Common Implementation Challenges
- Too many complex labels: Using excessive classification tiers confuses staff. Keep your classification scheme to three or four simple tiers.
- Inconsistent manual labelling: Users forget to label documents manually. Deploy automated tools that apply mandatory default labels.
- Ignoring physical materials: Teams label digital files but leave printed reports unmarked. Include physical printing in labelling training.
- Over-classifying everything: Staff mark basic routine notes as confidential, creating alert fatigue. Provide clear examples for each tier.
- Static labels over time: Old confidential records remain restricted after becoming public. Set scheduled review dates to update labels.
- Stripping metadata in conversions: Converting files to different formats removes digital labels. Ensure export templates retain visible markers.
How to Measure Effectiveness (KPIs)
- Labelling compliance rate: Track the percentage of sampled files correctly marked with classification labels during spot checks.
- Automated tagging coverage: Measure the proportion of enterprise applications enforcing automated classification metadata.
- Mislabelled document incident count: Monitor the number of security events or data leaks linked to incorrect file labelling.
- Labelling training completion rate: Track the percentage of active employees who finish annual training on information labelling.
- Unlabelled file discovery rate: Track the count of unmarked sensitive documents identified across shared network locations quarterly.
- Labelling audit finding count: Monitor the number of non-conformities raised against information labelling rules during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.13 connects to several other ISO 27001 requirements:
Annex A 5.13 depends on Clause 5.12 (Classification of Information). You cannot label what you have not classified. It supports Clause 7.10 (Storage Media) by identifying how to handle physical disks. Finally: it informs Clause 8.3 (Information Access Restriction) by providing the metadata needed for access controls.
