Data Masking Control (8.11)
Data Masking is an ISO 27001 control that involves hiding or transforming sensitive information so that it is exposed only when there is a legitimate business need. The goal is to limit who can see sensitive data by presenting it in a non-sensitive form, such as a redacted document, while keeping the data usable for its intended purpose. It is one of the reference controls organisations may choose to apply based on their risk assessment and legal or regulatory requirements.
Annex A control 8.11 (Data Masking) is a reference control introduced in the ISO/IEC 27001:2022 revision that calls for the use of data masking techniques to limit the exposure of sensitive information, guided by business requirements and applicable laws and regulations. Supporting guidance in ISO/IEC 27002:2022 describes techniques such as pseudonymisation and anonymisation, which transform sensitive data into a non-sensitive form while aiming to preserve its usability and integrity. As an Annex A control, its applicability is determined through the organisation's risk assessment and documented in the Statement of Applicability rather than being universally mandatory; the level and method of masking depend on scope, data sensitivity, and regulatory context. This control applies specifically within the ISO 27001 framework and should not be conflated with the SOC 2 Trust Services Criteria.
Why it matters
Sensitive data is frequently exposed not through sophisticated attacks but through routine access: developers testing against production data, support staff viewing full customer records, or reports circulated more widely than intended. Data Masking (Annex A 8.11) addresses this by limiting exposure of sensitive information to those with a legitimate business need, presenting the data in a non-sensitive form while keeping it usable for its intended purpose. This reduces the blast radius when access is broader than necessary and helps organisations align data handling with applicable laws and regulations.
Control 8.11 was newly introduced in the ISO/IEC 27001:2022 revision, reflecting increased attention to techniques such as pseudonymisation and anonymisation as ways to transform sensitive data into a non-sensitive form. Because it is an Annex A reference control rather than a universally mandatory requirement, its relevance depends on the organisation's risk assessment and is documented in the Statement of Applicability. Where sensitive personal or regulated data is processed, masking can be an effective way to demonstrate that exposure has been deliberately constrained.
It is important to recognise the limits of this control. Applying 8.11 within an ISO 27001 ISMS covers only the defined scope of that management system and does not, on its own, guarantee freedom from data exposure or breach. The appropriate masking technique and level of transformation depend on data sensitivity, scope, and regulatory context, and this control should not be conflated with the SOC 2 Trust Services Criteria, which operate under a separate framework.
Who it's relevant to
Inside Data Masking Control (8.11)
Common questions
Answers to the questions practitioners most commonly ask about Data Masking Control (8.11).