Not everyone who needs data should be able to identify people or sensitive details.
Annex A 8.11 exists to ensure organisations apply data masking techniques to protect sensitive information, particularly personal and confidential data, while still allowing it to be used for legitimate business purposes.
This control is about reducing exposure without breaking functionality.

Annex A 8.11 of ISO 27001:2022 focuses on data masking.
At a practical level, this means:
This is a new control in ISO 27001:2022, reflecting increased focus on privacy, data protection, and minimisation.
Many users, systems, and third parties need access to data — but not to its most sensitive elements.
Common scenarios include:
Without masking:
Annex A 8.11 ensures organisations separate data usefulness from data sensitivity.
A pragmatic approach to Annex A 8.11 typically includes the following elements.
Organisations should identify information where:
This commonly includes:
Masking should be driven by data use, not just data type.
ISO 27001:2022 highlights two primary approaches:
The choice depends on:
The stronger the masking, the lower the exposure.
Annex A 8.11 also supports other masking methods, including:
Different techniques may be combined to achieve the required protection level.
Masking is ineffective if identity can be reconstructed.
Organisations should ensure:
Re-identification risk should be assessed deliberately.
Access to original, unmasked data should be:
Masking reduces exposure only if access is genuinely restricted.
Organisations should consider:
Binding agreements or usage restrictions should be enforced technically where possible, not just contractually.
Annex A 8.11 supports maintaining records of:
Records support assurance, accountability, and regulatory response.
Data masking is closely linked to:
Masking strategies should be designed to support:
Legal alignment is a core driver of this control.
Annex A 8.11 does not require:
It does require organisations to:
Data masking is a risk-reduction control, not a cosmetic one.
Most data exposure is unnecessary exposure.
Annex A 8.11 is about using data safely without seeing more than you need.
When data masking is applied effectively:
Security is not always about blocking access.
Sometimes it is about changing what people are allowed to see.
Annex A 8.11 ensures organisations do exactly that — deliberately and defensibly.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today