A.5.13 Organizational
Labelling of information
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-16mostlyaligns with — Both controls establish and enforce the use of security attributes (labels) on information to support consistent handling, access decisions, and automated processing across formats and systems.
- MP-3mostlyaligns with — Both require marking media and information with classification labels so that handling, storage, and transport decisions reflect the organization's sensitivity scheme.
- AT-2partialaligns with — Both require personnel awareness and training so that staff correctly apply and respect classification labels when creating, processing, or sharing information.
- SC-16partialaligns with — Both emphasize embedding classification attributes (via metadata or other means) so that systems can transmit and act on security-relevant properties during information exchange.
- SI-12partialaligns with — Both rely on classification labels to determine appropriate retention, handling, and disposal actions for information throughout its lifecycle.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-07mostlyaligns with — The ISO control requires metadata labels that identify data types and their security properties so inventories can accurately reflect classification and handling requirements.
- PR.DS-01mostlyaligns with — By mandating persistent, machine-readable labels on data-at-rest, the control ensures confidentiality and integrity protections are applied according to classification.
- PR.AT-01partialaligns with — Personnel must receive training on correct labelling procedures so they understand how to apply and respect classification markings in daily operations.
- PR.DS-02partialaligns with — Label metadata travels with data-in-transit, enabling downstream systems to enforce the same classification-driven protections during transmission.
- PR.PS-04partialaligns with — System-generated labels embedded in logs and output allow continuous monitoring tools to recognize the sensitivity of the information being processed or transmitted.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.1.1partialaligns with — The ISO control's requirement to label information according to a classification scheme directly supports the ASVS mandate to identify and classify all sensitive data processed by the application.
- V14.1.2partialaligns with — By requiring documented procedures for attaching classification labels and handling data based on those labels, the ISO control aligns with the ASVS need for documented protection requirements tied to each data classification level.
- V14.2.4partialaligns with — The ISO guidance on using metadata labels to drive handling decisions for confidentiality and other security properties aligns with the ASVS requirement that controls for encryption, integrity, logging, and access be defined per data classification.
- V16.2.5partialaligns with — The ISO control's use of classification labels to determine appropriate handling of sensitive output aligns with the ASVS requirement that logging decisions respect the protection level of the data being processed.
Related weaknesses / CWE (10)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1230partialmitigates — Labelling can flag sensitive metadata, yet does not enforce technical controls to prevent its disclosure.
- CWE-200partialprevents — By requiring classification labels and metadata on all information assets, the control makes it harder for sensitive data to be inadvertently exposed because downstream systems and users can recognize and enforce handling rules based on those labels.
- CWE-201partialmitigates — Labelling makes sensitive data visible to developers and prevents accidental inclusion in outbound messages.
- CWE-213partialprevents — Labelling helps communicate classification decisions and reduce policy conflicts.
- CWE-538partialmitigates — Requiring visible or metadata labels on classified information helps ensure that files placed in externally accessible locations still carry an explicit sensitivity marker, lowering the likelihood of unnoticed exposure.
- CWE-284nonemitigates — Classification labels and associated metadata provide the necessary input for access-control decisions, allowing systems to apply the correct protections once the sensitivity of the information is known.
- CWE-532nonenone — Mandatory labelling of sensitive output forces classification metadata into logs and other system-generated files, reducing the chance that confidential information is written without any indication of its sensitivity.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.