Skip to main content
Category: Technical Security Controls

Data Masking Control (8.11)

Also known as: Annex A 8.11, Control 8.11, A.8.11 Data Masking
Simply put

Data Masking is an ISO 27001 control that involves hiding or transforming sensitive information so that it is exposed only when there is a legitimate business need. The goal is to limit who can see sensitive data by presenting it in a non-sensitive form, such as a redacted document, while keeping the data usable for its intended purpose. It is one of the reference controls organisations may choose to apply based on their risk assessment and legal or regulatory requirements.

Formal definition

Annex A control 8.11 (Data Masking) is a reference control introduced in the ISO/IEC 27001:2022 revision that calls for the use of data masking techniques to limit the exposure of sensitive information, guided by business requirements and applicable laws and regulations. Supporting guidance in ISO/IEC 27002:2022 describes techniques such as pseudonymisation and anonymisation, which transform sensitive data into a non-sensitive form while aiming to preserve its usability and integrity. As an Annex A control, its applicability is determined through the organisation's risk assessment and documented in the Statement of Applicability rather than being universally mandatory; the level and method of masking depend on scope, data sensitivity, and regulatory context. This control applies specifically within the ISO 27001 framework and should not be conflated with the SOC 2 Trust Services Criteria.

Why it matters

Sensitive data is frequently exposed not through sophisticated attacks but through routine access: developers testing against production data, support staff viewing full customer records, or reports circulated more widely than intended. Data Masking (Annex A 8.11) addresses this by limiting exposure of sensitive information to those with a legitimate business need, presenting the data in a non-sensitive form while keeping it usable for its intended purpose. This reduces the blast radius when access is broader than necessary and helps organisations align data handling with applicable laws and regulations.

Control 8.11 was newly introduced in the ISO/IEC 27001:2022 revision, reflecting increased attention to techniques such as pseudonymisation and anonymisation as ways to transform sensitive data into a non-sensitive form. Because it is an Annex A reference control rather than a universally mandatory requirement, its relevance depends on the organisation's risk assessment and is documented in the Statement of Applicability. Where sensitive personal or regulated data is processed, masking can be an effective way to demonstrate that exposure has been deliberately constrained.

It is important to recognise the limits of this control. Applying 8.11 within an ISO 27001 ISMS covers only the defined scope of that management system and does not, on its own, guarantee freedom from data exposure or breach. The appropriate masking technique and level of transformation depend on data sensitivity, scope, and regulatory context, and this control should not be conflated with the SOC 2 Trust Services Criteria, which operate under a separate framework.

Who it's relevant to

Compliance and GRC Managers
Those maintaining an ISO 27001 ISMS need to decide whether Control 8.11 applies based on their risk assessment and to document that decision, along with the selected masking approach, in the Statement of Applicability. Because 8.11 is new to the 2022 revision, organisations transitioning from earlier editions should assess whether it warrants inclusion in their scope.
Security Engineers and Data Architects
Engineers responsible for implementing controls may apply masking techniques such as pseudonymisation, anonymisation, or redaction to limit exposure of sensitive information. The appropriate technique depends on data sensitivity and the need to preserve usability and integrity for the data's intended purpose, so implementation choices should align with the documented risk assessment.
Auditors and Certification Bodies
When Control 8.11 is marked applicable in the Statement of Applicability, auditors typically assess whether the organisation's masking measures are consistent with its stated business requirements and applicable laws and regulations. Certification against ISO 27001 covers only the defined scope of the ISMS, so the assessment of 8.11 is bounded accordingly.
Privacy and Legal Teams
Teams responsible for regulatory compliance may find data masking relevant where laws and regulations constrain the exposure of personal or otherwise sensitive data. The level and method of masking often depend on the regulatory context, and these teams can help inform whether and how the control should be applied.

Inside Data Masking Control (8.11)

Annex A Reference Control 8.11 (ISO/IEC 27001:2022)
Data Masking is a reference control listed in Annex A of the ISO/IEC 27001:2022 revision, which restructured the Annex into 93 controls across four themes. Control 8.11 addresses the use of data masking techniques. As an Annex A control, it is selected via the Statement of Applicability and informed by the organization's risk assessment rather than being mandatory in every ISMS.
Data Masking Techniques
The control concerns applying techniques that limit exposure of sensitive data, which may include obscuring, pseudonymizing, or anonymizing data. The specific techniques and their applicability depend on the organization's scope, data types, and identified risks.
Relationship to Access Control and Data Protection Objectives
Data masking typically supports broader objectives around protecting sensitive or personal data by reducing the amount of identifiable information exposed to users, processes, or environments that do not require it. It commonly complements, rather than replaces, other controls such as access restrictions.
Selection via Statement of Applicability
Because 8.11 is an Annex A reference control, its inclusion or exclusion is documented in the Statement of Applicability with justification, and is driven by the results of the risk assessment applicable to the defined ISMS scope.
Distinction from SOC 2 Trust Services Criteria
This control belongs to ISO/IEC 27001:2022 Annex A and should not be conflated with the SOC 2 Trust Services Criteria. In a SOC 2 examination, masking-related activities would be assessed as controls mapped to relevant criteria (such as the Common Criteria or Confidentiality, depending on scope) rather than to an Annex A control number.

Common questions

Answers to the questions practitioners most commonly ask about Data Masking Control (8.11).

Is data masking a mandatory control I must implement to achieve ISO 27001 certification?
Not automatically. Annex A control 8.11 (Data masking) in the ISO/IEC 27001:2022 version is a reference control, not a blanket requirement. Whether it applies to your ISMS is determined through your risk assessment and documented in the Statement of Applicability. If the control is not relevant to your defined scope, you may justify its exclusion. The certifiable requirements themselves are in clauses 4 through 10; Annex A controls are selected based on the risks you identify.
Does implementing data masking under ISO 27001 Annex A also satisfy the SOC 2 Trust Services Criteria?
Not directly. The two frameworks are distinct, and satisfying one does not automatically satisfy the other. Data masking is an ISO 27001 Annex A reference control, whereas SOC 2 assesses controls against the Trust Services Criteria (with Security, the Common Criteria, being the only required category and Confidentiality or Privacy being optional depending on scope). A masking practice can often be mapped to relevant SOC 2 criteria, but such mapping is typically partial, and a SOC 2 examination would evaluate the control on its own terms as designed and, in a Type II engagement, as operating over the review period.
How do I decide whether data masking belongs in my Statement of Applicability?
The decision typically flows from your risk assessment. Where you identify risks related to the exposure of sensitive data, for example in non-production environments, reporting, or shared datasets, control 8.11 may be selected to address them. If applicable, you document its inclusion in the Statement of Applicability along with the justification; if it is not relevant to your defined scope, you record the justification for its exclusion. The specific outcome depends on your scope, data, and the risks you have identified.
What is the difference between masking data and other techniques for protecting sensitive information?
Data masking generally refers to obscuring or substituting sensitive values so they are not exposed while remaining usable for a given purpose. It is often distinguished from techniques such as encryption or access restriction, which address confidentiality in other ways. In most implementations, organizations select an approach appropriate to the use case and the risk, rather than treating any single technique as universally required. The exact method and its suitability depend on your scope, the data involved, and your risk assessment.
How would an ISO 27001 certification body assess our data masking control during an audit?
Where the control is included in your Statement of Applicability, the certification body will typically examine whether it is implemented consistently with your documented approach and whether it addresses the risks it was selected to mitigate. The specifics of what an auditor evaluates depend on the certification body, your defined scope, and how the control is documented. Bear in mind that an ISO 27001 certificate covers only the defined scope of the ISMS.
If we implement data masking, what does that assurance cover and what remains out of scope?
Assurance is bounded. Under ISO 27001, a certificate covers only the defined scope of the ISMS, and inclusion of control 8.11 attests that the masking control was selected and assessed within that scope, not that all sensitive data everywhere is protected. If the same practice is evaluated in a SOC 2 examination, the resulting report attests only to the controls and, for a Type II, the period covered, and does not guarantee freedom from breaches. In both cases the control's effect is limited to the scope, criteria, and boundaries defined for the engagement.

Common misconceptions

Data Masking (8.11) is a mandatory control that every ISO 27001-certified organization must implement.
The certifiable ISO/IEC 27001 requirements are in clauses 4 through 10. Annex A controls, including 8.11, are reference controls selected through the Statement of Applicability and informed by risk assessment. An organization may justify excluding 8.11 if it is not applicable to its scope, so it is not universally mandatory.
Control 8.11 has always existed with the same numbering in ISO 27001.
Data Masking as a distinctly numbered control (8.11) is associated with the 2022 revision, which restructured Annex A into 93 controls across four themes. Control counts and numbering depend on the edition, so the version should be specified whenever citing control numbers.
Implementing data masking satisfies the equivalent SOC 2 requirement automatically.
Mapping between ISO 27001 and SOC 2 is possible but only partial. Satisfying an ISO 27001 Annex A control does not automatically satisfy SOC 2 criteria; SOC 2 is an attestation examination performed by a licensed CPA firm evaluating controls against the Trust Services Criteria, and the two outcomes are assessed independently.

Best practices

Document the inclusion or exclusion of Annex A 8.11 in your Statement of Applicability, and ensure the decision is justified by and traceable to your risk assessment results.
Always specify that you are referencing the ISO/IEC 27001:2022 edition when citing control 8.11, since numbering and control counts differ from the 2013 version.
Select masking techniques (such as obscuring, pseudonymization, or anonymization) based on the specific data types and risks within your defined ISMS scope rather than applying a single approach universally.
Treat data masking as complementary to other controls such as access restrictions, rather than assuming it alone eliminates exposure of sensitive data.
If pursuing both frameworks, map masking-related controls to the relevant SOC 2 Trust Services Criteria separately, recognizing that the mapping is partial and each outcome is evaluated independently.
Review the effectiveness and continued applicability of masking controls as part of ongoing ISMS operation, since applicability can change with scope, data, and risk over time.