Skip to main content
Category: Technical Security Controls

Information Labeling

Also known as: Data Labeling, Document Labeling, Sensitivity Labeling
Simply put

Information labeling is the practice of attaching tags or markings to data, documents, or communications to indicate how sensitive they are and how they should be handled. For example, a document might be labeled as Public, Confidential, or Personal so that people know the level of protection it requires. This helps organizations consistently identify and safeguard sensitive information.

Formal definition

Information labeling is the process of attaching metadata, tags, or markings to information assets, such as documents, email, or data, to signify their classification, sensitivity level, or handling requirements, typically in alignment with an organization's data classification taxonomy. Labels (for example, Public, General, Confidential, Personal) are applied to drive consistent handling, protection, and access decisions across the information lifecycle. Implementation approaches vary by organization and may be manual or supported by tooling; the specific labeling scheme, taxonomy, and enforcement depend on organizational scope and policy.

Why it matters

Information labeling underpins an organization's ability to protect data consistently. Without clear markings indicating how sensitive a document, email, or dataset is, employees are left to guess at the appropriate handling, which increases the risk of over-sharing confidential material or under-protecting personal information. Labels translate an abstract data classification policy into practical, visible guidance that travels with the information itself across its lifecycle.

In a compliance context, labeling supports both SOC 2 and ISO 27001 objectives, though it maps to each framework differently and in a partial way. Under the SOC 2 Common Criteria, consistent classification and handling of information can serve as evidence supporting confidentiality-related controls, particularly where an engagement includes the optional Confidentiality or Privacy categories. Under ISO 27001, labeling is commonly addressed as one of the Annex A reference controls that an organization may select through its Statement of Applicability, informed by its risk assessment; the specific control reference and count depend on the version of the standard cited. Satisfying labeling expectations in one framework does not automatically satisfy the other.

It is important to recognize the limits of labeling as a control. A label communicates handling requirements but does not by itself enforce them; enforcement typically depends on complementary controls such as access management, encryption, and monitoring. Labeling schemes and their effectiveness vary by organization, and the presence of labels alone does not guarantee that sensitive information is protected against loss or breach.

Who it's relevant to

Compliance and GRC Managers
Those overseeing SOC 2 examinations or ISO 27001 certification use labeling as a practical expression of the organization's data classification policy. They should be prepared to show how the labeling scheme aligns with the taxonomy, and, for ISO 27001, how the relevant Annex A control was addressed through the Statement of Applicability, noting that specifics depend on the version and scope.
Security Engineers and IT Teams
These teams design and operate the mechanisms that apply labels, whether manual conventions or tooling-based approaches. They also configure the complementary controls, such as access restrictions and encryption, that give labels practical effect, since a label communicates handling requirements but does not enforce them on its own.
Auditors and Assessors
Auditors evaluating confidentiality-related controls examine whether labels are applied consistently and whether handling matches the assigned sensitivity. Under SOC 2 they assess this as evidence supporting the design and, in a Type II engagement, operating effectiveness of controls over the review period; findings depend on the auditor and the scope of the engagement.
Document Owners and General Staff
The people who create and handle information rely on labels to know what level of protection a given document or message requires. Clear, consistently applied labels reduce ambiguity in day-to-day handling decisions and support the broader classification program.

Inside Information Labeling

Classification-Driven Labeling
Information labeling typically applies markings to information and associated assets according to the organization's information classification scheme, so that the sensitivity level (for example, public, internal, confidential, or restricted) is visible and can drive appropriate handling.
Annex A Reference Control
In ISO/IEC 27001, labeling of information is addressed as a reference control within Annex A rather than as an ISMS clause requirement. As with all Annex A controls, its inclusion is selected via the Statement of Applicability and informed by the risk assessment, and control groupings differ between the 2013 and 2022 revisions.
Scope of Media and Formats
Labeling procedures typically span multiple formats, including physical documents and media as well as electronic information, so that markings remain associated with the information across the forms it takes. The exact coverage depends on scope and the organization's handling procedures.
Link to Handling Procedures
Labels are generally most useful when tied to defined handling rules, so that a given classification and its label indicate how information should be stored, transmitted, shared, and disposed of.
Relationship to SOC 2 Criteria
In a SOC 2 examination, labeling practices may be evaluated as part of the controls a service organization has in place, particularly where Confidentiality or Privacy categories are within scope. These are Trust Services Criteria and should not be conflated with ISO 27001 Annex A controls.

Common questions

Answers to the questions practitioners most commonly ask about Information Labeling.

Does ISO 27001 mandate a specific information labeling scheme that every organization must adopt?
No. ISO 27001 itself sets the ISMS requirements in clauses 4 through 10, and information labeling appears as a reference control in Annex A rather than as a rigid, prescribed scheme. Whether and how labeling is applied is typically determined through your risk assessment and documented in the Statement of Applicability. Depending on scope, an organization may justify excluding or tailoring the control. The standard does not dictate a universal set of labels; those decisions are yours to make and defend.
Is information labeling a Trust Services Criteria requirement I have to meet for a SOC 2 report?
Information labeling is an Annex A reference control under ISO 27001 and should not be conflated with the SOC 2 Trust Services Criteria. In a SOC 2 examination, labeling practices may be relevant as part of the controls you present, particularly where they support the Security (Common Criteria) category or optional categories such as Confidentiality, but there is no standalone 'labeling criterion.' What is assessed depends on the controls you define and the scope of the engagement, as evaluated by the CPA firm.
How do we decide which labeling categories to use?
In most engagements, labeling categories flow from a data classification scheme informed by your risk assessment. Organizations typically define a small number of tiers reflecting sensitivity, and then map labels to those tiers. The exact categories vary by organization, sector, and applicable criteria, so there is no single correct set. Documenting the rationale, and, for ISO 27001, reflecting relevant decisions in the Statement of Applicability, helps demonstrate that the approach is deliberate rather than arbitrary.
Should labeling be applied to physical documents as well as digital information?
Depending on scope, labeling can apply to information in multiple forms, including electronic files, storage media, and physical documents. Where physical assets fall within the defined boundary of your ISMS or the controls covered by a SOC 2 report, extending labeling to them is common. The scope you define determines what is in and out; assets outside that boundary are not covered by the resulting certificate or report.
How can we show an auditor or certification body that labeling is operating, not just documented?
For a point-in-time review, such as a SOC 2 Type I, demonstrating the suitability of design, policies, procedures, and labeling standards, may be sufficient. Where operating effectiveness over a period is assessed, such as a SOC 2 Type II or an ISO 27001 certification audit, evidence that labels are consistently applied across the review period is typically expected. This can include labeled samples, system configurations, and records showing the practice was followed, though the specific evidence sought varies by auditor, certification body, and scope.
What are the limitations of relying on labeling as a control?
Labeling helps signal how information should be handled, but it does not by itself enforce protection or guarantee freedom from breaches. Its effectiveness depends on complementary handling, access, and monitoring practices, and on users applying labels correctly. A SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined ISMS scope, so labeling should be understood as one element within a broader control environment rather than a complete safeguard.

Common misconceptions

Information labeling is a mandatory control that every organization must implement identically.
In ISO/IEC 27001, labeling appears as an Annex A reference control whose applicability is determined through the Statement of Applicability and risk assessment, so its scope and implementation depend on the organization. For SOC 2, relevant handling and labeling practices depend on the auditor, scope, and which Trust Services Criteria are selected.
A specific number of classification levels or a fixed set of labels is required by the standards.
Neither framework prescribes a universal set of labels or number of tiers. The classification scheme and corresponding labels are defined by the organization based on scope and risk, and vary accordingly.
Having a labeling control satisfies both SOC 2 and ISO 27001 equivalently.
Mapping between SOC 2 Trust Services Criteria and ISO 27001 Annex A controls is possible but partial. Demonstrating labeling for one framework does not automatically satisfy the other, since the standards use different structures, criteria, and forms of assurance.

Best practices

Align labels directly to your defined information classification scheme so each label maps to a specific sensitivity level and set of handling rules.
Extend labeling procedures across the formats relevant to your scope, including physical media and electronic information, so markings persist as information changes form.
Document labeling in a way that supports evidence needs, recognizing that ISO 27001 treats it as an Annex A reference control selected via the Statement of Applicability, while SOC 2 may assess it under Confidentiality or Privacy where those categories are in scope.
Specify the ISO/IEC 27001 revision when referencing where labeling sits within Annex A, since control groupings differ between the 2013 and 2022 versions.
Tie labels to concrete handling procedures for storage, transmission, sharing, and disposal rather than treating the label as an end in itself.
Review labeling practices periodically against your risk assessment and audit scope, and avoid assuming that satisfying one framework's expectations automatically satisfies the other's.