Protect information when it moves between people, systems or organizations, whether by email, file share, removable media or post. Agree the rules and safeguards before transfers happen.
What an auditor, or Sekit's evidence engine, asks for.
Email security configuration
The email protections against phishing and spoofing: anti-spam filtering and the domain's SPF, DKIM and DMARC records.
Local admin and removable-media controls
The rules on who may have administrator rights on their own device and on the use of USB sticks and external drives.
Encryption standards evidence
The proof that sensitive data is encrypted when stored (databases, storage) and when transmitted (encrypted connections).
From the Sekit evidence catalog
In practice
Most companies handle this by defaulting to encrypted channels for anything sensitive: TLS-enforced email, a client portal instead of open file attachments, and a documented ban on sending client data through personal messaging apps. Auditors check the encryption standards evidence against what leaves the building, then look at the email security configuration for SPF, DKIM and DMARC records that stop the domain from being spoofed in the first place. The gap that shows up most often is removable media: USB drives still used to move sensitive files between sites because nobody set up an approved alternative, despite a written rule against it.
Common gaps
Client files still travel by email attachment over unencrypted channels because staff were never given an easier, approved alternative like a secure file-share link.
SPF, DKIM and DMARC records are only partially configured, leaving the domain open to spoofing despite the email security policy claiming full coverage.
Removable media is formally restricted but no technical control blocks USB ports, so the policy has no enforcement behind it.
Questions your auditor will ask
How is sensitive information protected when it moves between people or organizations?
Point to the encryption standards evidence showing TLS enforced on email and file transfer, plus the ban on sending sensitive data over unencrypted personal channels.
What stops your email domain from being spoofed?
Show the email security configuration with SPF, DKIM and DMARC published and enforced, not only recorded as a policy intention.
Are removable media transfers controlled or blocked?
Describe the local admin and removable-media controls, whether USB use is technically restricted and what business justification an exception requires.
Where regulation demands it
NIS2 art. 9.1 (Policy and procedures for cryptography) requires the same encryption safeguards A.5.14 asks organizations to apply to information in transit.
ENS mp.s.1 (Protección del correo electrónico) sets the baseline for protecting email as a transfer channel.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.