iso-27001-email-security

By July 25th, 2026compliant-growth7 min read

ISO 27001 Email Security: Policies and Technical Controls

Email remains the most exploited attack vector in modern organisations. For companies pursuing or maintaining ISO 27001 certification, securing email systems is not optional. Annex A of ISO 27001:2022 contains specific controls that directly address email security. This article provides a direct answer to what ISO 27001 requires for email security, including policy development, encryption standards, anti-spam and anti-phishing controls, email authentication protocols such as DMARC, SPF, and DKIM, archiving obligations, acceptable use policies, and mobile email considerations.

Annex A.13 Requirements for Email Security

ISO 27001:2022 Annex A.13 (Communications Security) is the primary section governing email security. It covers network security management, information transfer policies, and confidentiality agreements. Control A.13.2.1 requires that information transfer policies, procedures, and controls are in place to protect information transmitted via email. Control A.13.2.2 addresses agreements on information transfer, including electronic messaging. Control A.13.2.3 covers electronic messaging to ensure appropriate protection of information when communicating via email, instant messaging, and other electronic channels.

ISO ControlControl NameEmail Security Requirement
A.13.2.1Information transfer policies and proceduresFormal policy for email use, content classification, and transmission rules
A.13.2.2Agreements on information transferContracts with email service providers and third parties governing data protection
A.13.2.3Electronic messagingTechnical controls for email confidentiality, integrity, and availability
A.8.24Use of cryptographyEncryption of email content and attachments when transmitting sensitive information
A.8.7Protection against malwareAnti-malware scanning of email attachments and links

Email Security Policy

An ISO 27001-compliant email security policy must define acceptable use, content classification, encryption requirements, retention periods, and incident reporting procedures. The policy should be approved by management, communicated to all users, and reviewed at regular intervals. Key policy elements include:

  • Classification of emails based on sensitivity (public, internal, confidential, restricted)
  • Rules for sending sensitive information via email, including mandatory encryption
  • Prohibition on sending company data to personal email accounts
  • Requirements for email disclaimers and confidentiality notices
  • Rules for forwarding work emails to external addresses
  • Procedures for reporting suspicious or phishing emails

Email Encryption: S/MIME and TLS

ISO 27001 requires organisations to protect the confidentiality and integrity of information transmitted via email. Two primary encryption methods are commonly deployed: TLS for transport-level encryption and S/MIME for end-to-end encryption.

Encryption MethodProtection ScopeStrengthsLimitations
TLS (Transport Layer Security)Email in transit between mail serversAutomatic, transparent to users, widely supportedDoes not encrypt email content at rest; only protects while in transit
S/MIME (Secure/Multipurpose Internet Mail Extensions)End-to-end encryption of email content and attachmentsEncrypts at rest and in transit; provides sender authenticationRequires certificate management; both parties must support S/MIME
PGP / GPGEnd-to-end encryptionOpen standard; no central certificate authority requiredComplex key management; limited support in enterprise environments

Anti-Spam and Anti-Phishing Controls

ISO 27001 control A.8.7 requires protection against malware, which includes email-borne threats such as phishing links and malicious attachments. An effective anti-spam and anti-phishing framework should include:

  • Gateway filtering – block spam and known malicious emails at the perimeter using content filtering, reputation analysis, and attachment sandboxing
  • Link protection – rewrite or scan URLs in inbound emails to detect phishing links at the time of click
  • Attachment scanning – inspect all email attachments using multiple anti-malware engines
  • User reporting – provide a one-click mechanism for users to report suspicious emails to the security team
  • Automated response – integrate phishing reporting with security orchestration, automation, and response (SOAR) platforms to enable rapid mailbox remediation

DMARC, SPF, and DKIM Implementation

Email authentication protocols are essential for preventing domain spoofing and phishing. ISO 27001 auditors will expect organisations to implement Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC). These three protocols work together to verify that emails claiming to come from your domain are legitimate.

ProtocolFunctionDeployment Priority
SPFPublishes authorised sending IP addresses for your domain in DNS1 – foundational, must be deployed first
DKIMDigitally signs outgoing emails using a private key; receivers verify using a public DNS record2 – provides signing and verification
DMARCPolicy framework that tells receiving servers how to handle emails that fail SPF or DKIM checks3 – policy enforcement and reporting

Email Archiving and Retention

ISO 27001 control A.8.10 (Information deletion) and A.8.11 (Data masking) both have implications for email archiving. Organisations must define retention periods for email based on legal, regulatory, and business requirements. Archived emails must be stored in a tamper-proof format, indexed for search, and accessible only to authorised personnel. Common archiving requirements include:

  • Retention of financial and contractual emails for 6 – 10 years depending on jurisdiction
  • Immutable storage to prevent deletion or alteration of archived messages
  • eDiscovery capabilities for legal and regulatory requests
  • Secure deletion after the retention period expires
  • Backup of email archives to a separate geographical location

Acceptable Use of Email

An acceptable use policy (AUP) for email is required under ISO 27001 control A.8.6 (Acceptable use of assets) and must be signed by every employee. The AUP should address personal use of corporate email, forwarding rules, size limits, use of distribution lists, and prohibition of unauthorised mass mailings. Regular training should reinforce the AUP, and violations should be addressed through the organisation’s disciplinary process.

Mobile Email Security

With the prevalence of bring your own device (BYOD) and mobile device management (MDM) policies, securing email on mobile devices is a critical ISO 27001 requirement. Control A.8.1 (User endpoint devices) and control A.8.17 (Mobile device policy) both apply. Key controls for mobile email include:

  • Mandatory device encryption and screen lock
  • Remote wipe capability for lost or stolen devices
  • Containerisation of corporate email data separate from personal apps
  • Conditional access policies that require compliant devices to connect
  • Prohibition of email attachment downloads to personal cloud storage

Frequently Asked Questions

Does ISO 27001 require email encryption?

Yes. ISO 27001 requires appropriate protection of information transmitted via email, which includes encryption where necessary based on risk assessment. Control A.13.2.3 and A.8.24 together mandate encryption for sensitive email content and attachments.

What is the difference between SPF, DKIM, and DMARC?

SPF specifies which IP addresses are authorised to send email for your domain. DKIM provides a digital signature that verifies the email has not been tampered with. DMARC tells receiving mail servers what to do with emails that fail SPF or DKIM checks (quarantine, reject, or allow), and provides reporting on email authentication results.

How often should the email security policy be reviewed?

ISO 27001 requires periodic review of all policies and controls. Most organisations review their email security policy annually or when significant changes occur, such as new email platform deployments, regulatory updates, or after a security incident.

Does ISO 27001 cover personal email accounts used for work?

The standard requires that company information is protected regardless of where it is processed. Using personal email accounts for work purposes is strongly discouraged and should be explicitly prohibited in the acceptable use policy.

What email archiving period does ISO 27001 require?

ISO 27001 does not prescribe a specific retention period. Organisations must determine retention based on legal, regulatory, and business requirements, and document these in the information retention policy.

Conclusion

Email security under ISO 27001 requires a combination of policy, technical controls, and user awareness. By implementing encryption, authentication protocols, anti-phishing measures, and robust archiving, organisations can satisfy audit requirements while significantly reducing the risk of email-borne attacks. The investment in structured email security pays dividends in reduced incident response costs and strengthened customer trust.

Ready to strengthen your email security for ISO 27001? Our ISO consultants can help you design policies, deploy technical controls, and prepare for certification audits. Get in touch with our team to discuss your requirements.