SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.14Information transfer

Protect information when it moves between people, systems or organizations, whether by email, file share, removable media or post. Agree the rules and safeguards before transfers happen.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0097Encryption in transit · PolicysupportsRequiring encryption for sensitive data crossing any network, with named approved channels and an exception path, covers the encrypted-channel safeguard A.5.14 requires, though the control also covers removable media, physical post and transfer agreements this rule does not reach.RCF-0098Encryption in transit · ProcesssupportsRoutinely sending business communications and client files only over encrypted channels is the daily practice that makes the encryption-in-transit policy real rather than aspirational.RCF-0099Encryption in transit · TechnicalsupportsSwitching off legacy unencrypted protocols on every service and remote-access path is the technical enforcement A.5.14 needs behind an encryption requirement written on paper.RCF-0178Email security · PolicysupportsEmail is one of A.5.14's named transfer channels; protecting it against spoofing and malicious content, with a clear reporting path, covers that channel specifically.RCF-0179Email security · ProcesssupportsTriaging reported suspicious emails and tuning filters from what is learned keeps the email transfer channel's protections current, not configured once at setup.RCF-0180Email security · TechnicalsupportsPublishing SPF, DKIM and DMARC and filtering inbound mail is the technical control that enforces A.5.14's expectation of safe email as a transfer channel.RCF-0370Cross-border transfers · PolicyrelatedCross-border transfer rules address the legal basis for moving personal data outside the EEA, a related concern to A.5.14's channel security but governed by a different set of safeguards.RCF-0371Cross-border transfers · ProcessrelatedVerifying every vendor receiving personal data abroad holds a valid safeguard is the legal counterpart to A.5.14's technical transfer protections, checked before and during the relationship.RCF-0372Cross-border transfers · TechnicalrelatedConfiguring systems to keep personal data in approved regions limits where a transfer can go at all, complementing A.5.14's focus on protecting transfers once they happen.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Email security configuration
The email protections against phishing and spoofing: anti-spam filtering and the domain's SPF, DKIM and DMARC records.
Local admin and removable-media controls
The rules on who may have administrator rights on their own device and on the use of USB sticks and external drives.
Encryption standards evidence
The proof that sensitive data is encrypted when stored (databases, storage) and when transmitted (encrypted connections).
From the Sekit evidence catalog

In practice

Most companies handle this by defaulting to encrypted channels for anything sensitive: TLS-enforced email, a client portal instead of open file attachments, and a documented ban on sending client data through personal messaging apps. Auditors check the encryption standards evidence against what leaves the building, then look at the email security configuration for SPF, DKIM and DMARC records that stop the domain from being spoofed in the first place. The gap that shows up most often is removable media: USB drives still used to move sensitive files between sites because nobody set up an approved alternative, despite a written rule against it.

Common gaps

Client files still travel by email attachment over unencrypted channels because staff were never given an easier, approved alternative like a secure file-share link.
SPF, DKIM and DMARC records are only partially configured, leaving the domain open to spoofing despite the email security policy claiming full coverage.
Removable media is formally restricted but no technical control blocks USB ports, so the policy has no enforcement behind it.

Questions your auditor will ask

How is sensitive information protected when it moves between people or organizations?
Point to the encryption standards evidence showing TLS enforced on email and file transfer, plus the ban on sending sensitive data over unencrypted personal channels.
What stops your email domain from being spoofed?
Show the email security configuration with SPF, DKIM and DMARC published and enforced, not only recorded as a policy intention.
Are removable media transfers controlled or blocked?
Describe the local admin and removable-media controls, whether USB use is technically restricted and what business justification an exception requires.

Where regulation demands it

NIS2 art. 9.1 (Policy and procedures for cryptography) requires the same encryption safeguards A.5.14 asks organizations to apply to information in transit.
ENS mp.s.1 (Protección del correo electrónico) sets the baseline for protecting email as a transfer channel.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.14?”
Also via MCP, free with account