Control Mapping Readerplace a control, see the map

A.8.11 Data masking

A.8.11 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.

The control as we hold it

Data masking. Data masking is to be applied as directed by the access control policy, related topic policies and what the business needs, with applicable law taken into account. Purpose (stated in ISO/IEC 27002:2022): reduces exposure of sensitive data such as PII and supports legal and contractual compliance. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.11.

Reviewed and closest counterparts in the other frameworks

We hold no cross-framework row for A.8.11 yet. The reviewed pairs page lists the released pairs and their coverage.

What an auditor commonly asks for

General guidance for this control area (domain: Technological controls), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control