What you need to know
Information remains exposed before, during, and after an exchange—regardless of whether it moves through an API, portal, file transfer, email, shared database, or manual process. Put protection duties and exit conditions in an owned agreement.
Potentially affected
Data exchanges with suppliers, customers, affiliates and internal units; application interfaces; shared platforms; file transfer; email; reports; contracts; privacy; incident response; retention; and relationship termination.
DSE recommendation
Inventory recurring sensitive exchanges, classify the information and participants, document protection and response duties, approve the agreement, monitor operation and changes, and rehearse orderly and emergency termination.
Source facts: protection follows the information, not one connection type
NIST Special Publication 800-47 Revision 1 addresses the security of information exchanges. Organizations exchange or provide access to information through many channels, including connections, services, files, messages, removable media, applications, and manual processes. NIST focuses on protecting information before, during, and after the exchange rather than prescribing one technology.
The publication describes identifying exchanges, assessing risk, selecting protections, establishing agreements, maintaining the exchange, and ending it. The form of agreement can vary with risk and organizational need. Examples include interconnection security agreements, memoranda of understanding or agreement, service-level agreements, nondisclosure agreements, contracts, and user agreements. More than one instrument may be needed to cover technical, operational, legal, privacy, and business responsibilities.
An agreement does not itself create protection. The parties must implement, operate, monitor, and periodically review the agreed safeguards. Changes in information, purpose, participants, architecture, ownership, threat, or law can alter risk. Termination also needs planning so access, credentials, routes, stored copies, and continuing obligations do not persist unnoticed.
DSE recommendation: create an exchange register before reviewing contracts
Inventory recurring exchanges of sensitive or operationally important information across external parties and internal units with separate authority. Record the business purpose, source, recipient, data elements, volume, frequency, direction, channel, locations, owners, users, decisions supported, and systems involved. Include exports, support access, shared dashboards, telemetry, backups, identity federation, reports, and informal transfers that bypass the expected interface.
Classify the information and identify confidentiality, integrity, availability, privacy, safety, retention, and provenance requirements on both sides. Determine whether the recipient may combine the data, use it for another purpose, create derived information, disclose it to a subcontractor, or make automated decisions from it.
DSE recommendation: make responsibilities executable
- Name accountable parties. Identify information owners, system owners, security and privacy contacts, operational contacts, incident contacts, change approvers, and termination authority for each participant.
- Define protections end to end. Cover identity, least privilege, transfer, storage, integrity, validation, logging, time, monitoring, backup, disposal, personnel access, physical protection, and subcontractors.
- Specify evidence and notification. State which logs and records exist, who can obtain them, preservation and response time, incident thresholds, communication channels, investigation cooperation, and notification responsibilities.
- Control change. Require review for new fields, purposes, users, endpoints, regions, service providers, interfaces, cryptographic changes, retention, and material control changes. Define emergency changes and retrospective approval.
- Plan disconnection. Address normal expiration, breach, unsafe conditions, loss of authorization, emergency suspension, credential revocation, route removal, data return or deletion, residual copies, and continuity impact.
DSE recommendation: verify operation and exit
Before launch, test authorized and unauthorized transactions, data validation, error handling, duplicate or delayed messages, rate and volume limits, monitoring, incident contacts, recovery, and evidence retrieval. Confirm that both parties interpret responsibilities the same way. Approve residual risk and unresolved assumptions through the named authority.
Monitor activity against the agreed purpose, population, destination, frequency, protections, and service expectations. Reconcile actual participants and flows to the register. Review agreements on a risk-based schedule and after incidents or material changes; a renewal date alone may be too late.
Exercise orderly and emergency termination. Verify that exchanges stop without unsafe business consequences, access and secrets are revoked, automated jobs and cached routes are removed, retained information is handled as agreed, required evidence remains available, and downstream parties are addressed. Confirm termination from both sides; one party’s disabled job does not prove the other party deleted access or copies. Keep the register, assessment, signed instruments, test evidence, change history, reviews, incidents, approvals, and closure proof. That lifecycle record turns a data connection into an accountable information relationship.
Official references
- National Institute of Standards and Technology, SP 800-47 Revision 1: Managing the Security of Information Exchanges, July 20, 2021; reviewed August 11, 2026.
Review the official source
NIST SP 800-47 Rev. 1: Managing the Security of Information Exchanges · Published July 20, 2021
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE