ISO 27001 Annex A 5.10 focuses on establishing, communicating, and enforcing rules for the acceptable use of information and other associated assets.
The purpose is to make sure employees, contractors, and other authorized users understand:
- What organizational assets they are allowed to use
- How those assets may be used
- What activities are prohibited
- How organizational information must be handled
- What security responsibilities users have
- What actions may create security risks
Simple explanation
A.5.10 means the organization should clearly define how people are allowed to use company information, devices, applications, systems, and other technology assets.
For example, employees may be permitted to use company laptops for business purposes, but may be prohibited from:
- Sharing passwords
- Installing unauthorized software
- Uploading confidential company data to personal cloud storage
- Using company systems for illegal activities
- Connecting unauthorized devices
- Circumventing security controls
Why is A.5.10 important?
Employees and other users interact with organizational information and technology every day.
Even well-designed security controls can be weakened by inappropriate use.
Common examples include:
- Sending confidential information to a personal email account
- Sharing credentials
- Installing unapproved software
- Using unauthorized cloud services
- Storing company information on personal devices
- Connecting unknown USB devices
- Uploading company information to public AI tools
- Using weak or reused passwords
- Bypassing security controls
- Using company resources for unauthorized activities
A clear acceptable-use policy helps establish consistent expectations.
Simple principle
People should know what they are allowed to do with company information and technology—and what they are not allowed to do.
What does A.5.10 require?
The organization should establish appropriate rules for the acceptable use of:
- Information
- Laptops
- Mobile devices
- Applications
- Cloud services
- Internet access
- Network resources
- Storage
- Collaboration platforms
- Source-code repositories
- Corporate accounts
- Other information-processing assets
The rules should be:
- Documented
- Communicated
- Appropriate to the organization’s environment
- Understood by users
- Reviewed periodically
- Updated when significant changes occur
Who should follow the acceptable-use rules?
The rules may apply to:
- Employees
- Contractors
- Consultants
- Temporary staff
- Interns
- Third-party personnel
- Remote workers
- Other authorized users
The organization should determine which rules apply to each type of user.
Activities required to implement A.5.10
1. Identify assets that require acceptable-use rules
Start by identifying important assets users interact with.
Examples:
| Asset | Acceptable Use Consideration |
|---|---|
| Company Laptop | Business use, software installation |
| Business communication and data sharing | |
| Cloud Storage | Approved storage and sharing |
| GitHub | Source-code handling |
| Slack/Teams | Business communication |
| Internet | Appropriate business use |
| Mobile Device | Access to company information |
| AI Tools | Handling of confidential information |
| Production Systems | Restricted administrative use |
Not every asset needs a separate policy.
The acceptable-use requirements can be consolidated into one organizational policy.
2. Define permitted use
The organization should explain what users are allowed to do.
For example:
Employees may:
- Use company devices for authorized business activities
- Access systems according to their assigned permissions
- Use approved applications
- Store business information in approved locations
- Use approved cloud services
- Access company systems remotely through approved methods
- Report security incidents and suspected misuse
3. Define prohibited use
The policy should clearly identify activities that are not permitted.
Examples include:
Unauthorized access
Users must not attempt to access:
- Another employee’s account
- Systems without authorization
- Production systems without approval
- Restricted information
Credential sharing
Users must not:
- Share passwords
- Share MFA codes
- Allow others to use their accounts
Unauthorized software
Users should not install:
- Unapproved software
- Pirated software
- Malware
- Security tools without authorization
- Applications that create unacceptable security risks
Data misuse
Users must not:
- Copy confidential information to personal storage
- Send restricted information to unauthorized recipients
- Upload sensitive information to unauthorized platforms
- Publish confidential information publicly
4. Address email and communication use
Acceptable-use rules should cover organizational communication platforms.
Users should understand expectations around:
- Business email
- Messaging platforms
- File sharing
- External recipients
- Confidential information
- Phishing
- Suspicious attachments
- Sensitive information
Example
Before sending confidential information externally, employees should verify:
Recipient → Authorization → Information Sensitivity → Approved Transfer Method
5. Address internet usage
The organization may define appropriate internet use.
Users should not use organizational systems for activities that:
- Violate applicable laws
- Introduce malware
- Circumvent security controls
- Create unacceptable business risk
- Damage the organization’s reputation
- Consume excessive organizational resources
The organization should clearly distinguish between legitimate limited personal use, if permitted, and prohibited activities.
6. Address cloud and SaaS usage
Employees frequently create security risks by using unauthorized cloud services.
Examples include:
- Personal Google Drive
- Personal Dropbox
- Personal OneDrive
- Unauthorized file-sharing services
- Unapproved project-management platforms
- Unapproved AI applications
The organization should define:
Which cloud services are approved for business information?
7. Address AI and Generative AI usage
Modern acceptable-use policies should consider AI tools.
Employees may use AI tools for legitimate business purposes, but organizations should establish rules for handling company information.
For example, users may be prohibited from entering:
- Customer confidential information
- Passwords
- API keys
- Encryption keys
- Personal information
- Source code
- Security vulnerabilities
- Internal confidential documents
into unapproved AI services.
Example
Public information
→ AI tools may be permitted.
Internal information
→ Use only approved tools where permitted.
Confidential information
→ Require appropriate authorization and approved tools.
Restricted information
→ Prohibit external AI processing unless specifically authorized.
The exact rules should depend on the organization’s AI risk assessment.
8. Address removable media
If USB devices or removable media are permitted, the organization should establish rules.
For example:
- Only approved devices may be used.
- Sensitive information should not be copied without authorization.
- Unknown USB devices should not be connected.
- Lost removable media must be reported.
- Encryption should be used where appropriate.
9. Address personal devices
If employees are allowed to use personal devices for business activities, the organization should establish appropriate rules.
This may include:
- Device security
- Screen lock
- Encryption
- Approved applications
- Remote access
- Data storage
- Separation of personal and business information
- Remote wipe where applicable
If personal devices are not permitted, the policy should clearly state this.
10. Address remote working
Remote employees may access company information from:
- Home
- Hotels
- Airports
- Coworking spaces
- Customer locations
Acceptable-use requirements may include:
- Use of approved devices
- Secure Wi-Fi
- VPN where required
- Screen privacy
- Secure storage
- No unauthorized sharing
- Immediate reporting of lost devices
11. Define user responsibilities
Users should understand their individual responsibilities.
For example:
Users are responsible for protecting the information and assets entrusted to them.
Responsibilities may include:
- Protecting credentials
- Locking devices
- Reporting incidents
- Protecting confidential information
- Using approved applications
- Following access restrictions
- Reporting lost devices
- Following data-classification requirements
12. Communicate the policy
A policy is only useful if users know about it.
The organization can communicate acceptable-use requirements through:
- Employee onboarding
- Security awareness training
- Annual training
- Employee handbook
- Policy acknowledgment
- Intranet
- Email communications
- Security awareness campaigns
Users may be required to acknowledge that they have read and understood the policy.
13. Review and update the rules
Acceptable-use requirements should evolve with technology.
For example, an organization may need to update its policy when it begins using:
- Generative AI
- New cloud platforms
- BYOD
- Remote working
- New collaboration tools
- New mobile applications
The policy should also be reviewed periodically.
Startup Example
Consider a SaaS startup with 50 employees.
Employees use:
- Company laptops
- Google Workspace
- Slack
- GitHub
- AWS
- Jira
- Generative AI tools
The company establishes the following rules.
Employees may:
- Use approved systems for business activities.
- Use approved AI tools according to company rules.
- Store company documents in approved cloud storage.
- Access GitHub according to their role.
- Work remotely using approved security controls.
Employees must not:
- Share passwords or MFA codes.
- Upload confidential customer information to unapproved AI tools.
- Store company documents in personal cloud accounts.
- Install unauthorized software.
- Copy production data to personal devices.
- Access systems without authorization.
- Disable security controls.
- Share confidential information with unauthorized people.
Employees must:
- Lock their devices.
- Protect credentials.
- Report suspected security incidents.
- Report lost or stolen devices.
- Follow information-classification requirements.
This creates clear expectations without requiring a large number of separate policies.
Example Acceptable-Use Matrix
| Activity | Permitted? | Conditions |
|---|---|---|
| Business email | Yes | Authorized business use |
| Approved cloud storage | Yes | Follow classification rules |
| Personal cloud storage | No/Restricted | Unless explicitly approved |
| Company laptop | Yes | Follow security requirements |
| Unauthorized software | No | IT approval required |
| Password sharing | No | Never permitted |
| Approved AI tool | Yes | Follow AI/data rules |
| Uploading confidential data to public AI | No | Unless specifically authorized |
| Remote work | Yes | Follow remote-access controls |
| USB storage | Restricted | Approved devices only |
| Production access | Restricted | Role-based authorization |
| Personal use of company systems | Organization-defined | Subject to policy |
Example Acceptable Use Register
For more mature organizations, specific assets can be tracked.
| Asset | Authorized Users | Permitted Use | Restrictions | Owner |
|---|---|---|---|---|
| Company Laptop | Employees | Business activities | No unauthorized software | IT |
| GitHub | Developers | Source-code management | No unauthorized repositories | Engineering |
| AWS Production | Authorized Admins | Production operations | Privileged access only | CTO |
| Google Workspace | Employees | Business communication | No confidential sharing externally | IT |
| AI Platform | Approved Users | Approved business tasks | No restricted information | Security |
A.5.10 Audit Evidence
An auditor may look for evidence such as:
Policy
- Acceptable Use Policy
- IT Usage Policy
- Information Security Policy
- AI Usage Policy
- Remote Working Policy
Communication
- Employee onboarding records
- Security awareness training
- Policy acknowledgment
- Annual policy review
Technical enforcement
Where applicable:
- Endpoint management
- Application restrictions
- DLP controls
- Web filtering
- Access controls
- USB restrictions
- Cloud access controls
User compliance
- Policy acknowledgments
- Security training records
- Incident records
- Policy violation records
A.5.10 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has the organization defined acceptable use of information assets? | Acceptable Use Policy |
| Are permitted activities clearly defined? | Policy |
| Are prohibited activities clearly defined? | Policy |
| Does the policy cover company devices? | Policy |
| Does it address cloud and SaaS services? | Policy |
| Does it address remote working where applicable? | Policy |
| Does it address removable media where applicable? | Policy |
| Does it address AI tools where relevant? | AI/Acceptable Use Policy |
| Are users informed of the requirements? | Training Records |
| Do users acknowledge the policy where required? | Acknowledgment Records |
| Is the policy reviewed periodically? | Review Records |
| Are violations handled appropriately? | Incident / HR Records |
Common Mistakes
1. Creating a policy full of vague statements
For example:
“Employees must use technology responsibly.”
This is difficult to enforce.
Better:
“Employees must not share passwords, upload confidential information to unauthorized services, or install software without authorization.”
Specific rules are easier to understand.
2. Ignoring cloud applications
Employees may use numerous SaaS applications without realizing that company information is being transferred outside approved systems.
3. Ignoring AI tools
Modern organizations should consider how employees use ChatGPT and other generative AI services when handling company information.
4. Treating every user identically
A developer, HR employee and system administrator may have very different access and responsibilities.
Acceptable-use requirements should reflect their roles.
5. Having a policy but never communicating it
An unpublished policy is unlikely to be effective.
Users should be made aware of applicable requirements.
6. Creating rules that cannot be enforced
Policies should be realistic and aligned with the organization’s actual technology environment.
Practical Startup Implementation Model
A startup can implement A.5.10 with a simple process:
Identify Assets
↓
Identify Users
↓
Define Permitted Use
↓
Define Prohibited Use
↓
Define Data-Handling Rules
↓
Communicate Policy
↓
Obtain Acknowledgment
↓
Monitor Where Appropriate
↓
Handle Violations
↓
Review & Update
Policy vs. Process vs. Evidence
| Element | Example |
|---|---|
| Policy | Users shall use organizational information and associated assets only for authorized purposes and in accordance with defined security requirements. |
| Process | Acceptable-use requirements are defined, communicated to users, acknowledged where appropriate, monitored and reviewed periodically. |
| Evidence | Acceptable Use Policy, training records, acknowledgment records, technical controls and incident records. |
The objective is not to prevent employees from using technology productively.
The objective is to establish clear boundaries around how organizational information and assets may be used.
Useful Resources
Recommended documents
- Acceptable Use Policy – [Insert Draft Document Link]
- Employee IT Usage Policy – [Insert Draft Document Link]
- AI Acceptable Use Policy – [Insert Draft Document Link]
- Remote Working Policy – [Insert Draft Document Link]
- BYOD Policy – [Insert Draft Document Link]
- Information Classification Policy – [Insert Draft Document Link]
- Security Awareness Training Material – [Insert Draft Document Link]
Related ISO 27001 controls
A.5.10 can work closely with:
- A.5.9 – Inventory of information and other associated assets
- A.5.10 – Acceptable use of information and other associated assets
- A.5.12 – Classification of information
- A.5.13 – Labelling of information
- A.5.14 – Information transfer
- A.5.15 – Access control
- A.6.3 – Information security awareness, education and training
- A.8.1 – User endpoint devices
- A.8.12 – Data leakage prevention
- A.8.19 – Installation of software on operational systems
Final Takeaway
ISO 27001 Annex A 5.10 is about establishing clear rules for how employees and other authorized users may use organizational information and technology assets.
A practical organization should be able to answer:
What can users do with company assets?
What are they prohibited from doing?
How should sensitive information be handled?
Are cloud and AI tools covered?
Have users been informed of the requirements?
What happens when the rules are violated?
For startups, the approach can remain simple:
Define → Communicate → Acknowledge → Enforce → Review
The objective is not to restrict technology unnecessarily.
It is to make sure that employees understand how to use organizational information and technology safely, responsibly and within authorized boundaries.
