ISO 27001 Email Security: Policies and Technical Controls
Email remains the most exploited attack vector in modern organisations. For companies pursuing or maintaining ISO 27001 certification, securing email systems is not optional. Annex A of ISO 27001:2022 contains specific controls that directly address email security. This article provides a direct answer to what ISO 27001 requires for email security, including policy development, encryption standards, anti-spam and anti-phishing controls, email authentication protocols such as DMARC, SPF, and DKIM, archiving obligations, acceptable use policies, and mobile email considerations.
Annex A.13 Requirements for Email Security
ISO 27001:2022 Annex A.13 (Communications Security) is the primary section governing email security. It covers network security management, information transfer policies, and confidentiality agreements. Control A.13.2.1 requires that information transfer policies, procedures, and controls are in place to protect information transmitted via email. Control A.13.2.2 addresses agreements on information transfer, including electronic messaging. Control A.13.2.3 covers electronic messaging to ensure appropriate protection of information when communicating via email, instant messaging, and other electronic channels.
| ISO Control | Control Name | Email Security Requirement |
|---|---|---|
| A.13.2.1 | Information transfer policies and procedures | Formal policy for email use, content classification, and transmission rules |
| A.13.2.2 | Agreements on information transfer | Contracts with email service providers and third parties governing data protection |
| A.13.2.3 | Electronic messaging | Technical controls for email confidentiality, integrity, and availability |
| A.8.24 | Use of cryptography | Encryption of email content and attachments when transmitting sensitive information |
| A.8.7 | Protection against malware | Anti-malware scanning of email attachments and links |
Email Security Policy
An ISO 27001-compliant email security policy must define acceptable use, content classification, encryption requirements, retention periods, and incident reporting procedures. The policy should be approved by management, communicated to all users, and reviewed at regular intervals. Key policy elements include:
- Classification of emails based on sensitivity (public, internal, confidential, restricted)
- Rules for sending sensitive information via email, including mandatory encryption
- Prohibition on sending company data to personal email accounts
- Requirements for email disclaimers and confidentiality notices
- Rules for forwarding work emails to external addresses
- Procedures for reporting suspicious or phishing emails
Email Encryption: S/MIME and TLS
ISO 27001 requires organisations to protect the confidentiality and integrity of information transmitted via email. Two primary encryption methods are commonly deployed: TLS for transport-level encryption and S/MIME for end-to-end encryption.
| Encryption Method | Protection Scope | Strengths | Limitations |
|---|---|---|---|
| TLS (Transport Layer Security) | Email in transit between mail servers | Automatic, transparent to users, widely supported | Does not encrypt email content at rest; only protects while in transit |
| S/MIME (Secure/Multipurpose Internet Mail Extensions) | End-to-end encryption of email content and attachments | Encrypts at rest and in transit; provides sender authentication | Requires certificate management; both parties must support S/MIME |
| PGP / GPG | End-to-end encryption | Open standard; no central certificate authority required | Complex key management; limited support in enterprise environments |
Anti-Spam and Anti-Phishing Controls
ISO 27001 control A.8.7 requires protection against malware, which includes email-borne threats such as phishing links and malicious attachments. An effective anti-spam and anti-phishing framework should include:
- Gateway filtering – block spam and known malicious emails at the perimeter using content filtering, reputation analysis, and attachment sandboxing
- Link protection – rewrite or scan URLs in inbound emails to detect phishing links at the time of click
- Attachment scanning – inspect all email attachments using multiple anti-malware engines
- User reporting – provide a one-click mechanism for users to report suspicious emails to the security team
- Automated response – integrate phishing reporting with security orchestration, automation, and response (SOAR) platforms to enable rapid mailbox remediation
DMARC, SPF, and DKIM Implementation
Email authentication protocols are essential for preventing domain spoofing and phishing. ISO 27001 auditors will expect organisations to implement Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC). These three protocols work together to verify that emails claiming to come from your domain are legitimate.
| Protocol | Function | Deployment Priority |
|---|---|---|
| SPF | Publishes authorised sending IP addresses for your domain in DNS | 1 – foundational, must be deployed first |
| DKIM | Digitally signs outgoing emails using a private key; receivers verify using a public DNS record | 2 – provides signing and verification |
| DMARC | Policy framework that tells receiving servers how to handle emails that fail SPF or DKIM checks | 3 – policy enforcement and reporting |
Email Archiving and Retention
ISO 27001 control A.8.10 (Information deletion) and A.8.11 (Data masking) both have implications for email archiving. Organisations must define retention periods for email based on legal, regulatory, and business requirements. Archived emails must be stored in a tamper-proof format, indexed for search, and accessible only to authorised personnel. Common archiving requirements include:
- Retention of financial and contractual emails for 6 – 10 years depending on jurisdiction
- Immutable storage to prevent deletion or alteration of archived messages
- eDiscovery capabilities for legal and regulatory requests
- Secure deletion after the retention period expires
- Backup of email archives to a separate geographical location
Acceptable Use of Email
An acceptable use policy (AUP) for email is required under ISO 27001 control A.8.6 (Acceptable use of assets) and must be signed by every employee. The AUP should address personal use of corporate email, forwarding rules, size limits, use of distribution lists, and prohibition of unauthorised mass mailings. Regular training should reinforce the AUP, and violations should be addressed through the organisation’s disciplinary process.
Mobile Email Security
With the prevalence of bring your own device (BYOD) and mobile device management (MDM) policies, securing email on mobile devices is a critical ISO 27001 requirement. Control A.8.1 (User endpoint devices) and control A.8.17 (Mobile device policy) both apply. Key controls for mobile email include:
- Mandatory device encryption and screen lock
- Remote wipe capability for lost or stolen devices
- Containerisation of corporate email data separate from personal apps
- Conditional access policies that require compliant devices to connect
- Prohibition of email attachment downloads to personal cloud storage
Frequently Asked Questions
Does ISO 27001 require email encryption?
Yes. ISO 27001 requires appropriate protection of information transmitted via email, which includes encryption where necessary based on risk assessment. Control A.13.2.3 and A.8.24 together mandate encryption for sensitive email content and attachments.
What is the difference between SPF, DKIM, and DMARC?
SPF specifies which IP addresses are authorised to send email for your domain. DKIM provides a digital signature that verifies the email has not been tampered with. DMARC tells receiving mail servers what to do with emails that fail SPF or DKIM checks (quarantine, reject, or allow), and provides reporting on email authentication results.
How often should the email security policy be reviewed?
ISO 27001 requires periodic review of all policies and controls. Most organisations review their email security policy annually or when significant changes occur, such as new email platform deployments, regulatory updates, or after a security incident.
Does ISO 27001 cover personal email accounts used for work?
The standard requires that company information is protected regardless of where it is processed. Using personal email accounts for work purposes is strongly discouraged and should be explicitly prohibited in the acceptable use policy.
What email archiving period does ISO 27001 require?
ISO 27001 does not prescribe a specific retention period. Organisations must determine retention based on legal, regulatory, and business requirements, and document these in the information retention policy.
Conclusion
Email security under ISO 27001 requires a combination of policy, technical controls, and user awareness. By implementing encryption, authentication protocols, anti-phishing measures, and robust archiving, organisations can satisfy audit requirements while significantly reducing the risk of email-borne attacks. The investment in structured email security pays dividends in reduced incident response costs and strengthened customer trust.
Ready to strengthen your email security for ISO 27001? Our ISO consultants can help you design policies, deploy technical controls, and prepare for certification audits. Get in touch with our team to discuss your requirements.