ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets

ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets

ISO 27001 Annex A 5.10 focuses on establishing, communicating, and enforcing rules for the acceptable use of information and other associated assets.

The purpose is to make sure employees, contractors, and other authorized users understand:

  • What organizational assets they are allowed to use
  • How those assets may be used
  • What activities are prohibited
  • How organizational information must be handled
  • What security responsibilities users have
  • What actions may create security risks

Simple explanation

A.5.10 means the organization should clearly define how people are allowed to use company information, devices, applications, systems, and other technology assets.

For example, employees may be permitted to use company laptops for business purposes, but may be prohibited from:

  • Sharing passwords
  • Installing unauthorized software
  • Uploading confidential company data to personal cloud storage
  • Using company systems for illegal activities
  • Connecting unauthorized devices
  • Circumventing security controls

Why is A.5.10 important?

Employees and other users interact with organizational information and technology every day.

Even well-designed security controls can be weakened by inappropriate use.

Common examples include:

  • Sending confidential information to a personal email account
  • Sharing credentials
  • Installing unapproved software
  • Using unauthorized cloud services
  • Storing company information on personal devices
  • Connecting unknown USB devices
  • Uploading company information to public AI tools
  • Using weak or reused passwords
  • Bypassing security controls
  • Using company resources for unauthorized activities

A clear acceptable-use policy helps establish consistent expectations.

Simple principle

People should know what they are allowed to do with company information and technology—and what they are not allowed to do.


What does A.5.10 require?

The organization should establish appropriate rules for the acceptable use of:

  • Information
  • Laptops
  • Mobile devices
  • Applications
  • Cloud services
  • Email
  • Internet access
  • Network resources
  • Storage
  • Collaboration platforms
  • Source-code repositories
  • Corporate accounts
  • Other information-processing assets

The rules should be:

  • Documented
  • Communicated
  • Appropriate to the organization’s environment
  • Understood by users
  • Reviewed periodically
  • Updated when significant changes occur

Who should follow the acceptable-use rules?

The rules may apply to:

  • Employees
  • Contractors
  • Consultants
  • Temporary staff
  • Interns
  • Third-party personnel
  • Remote workers
  • Other authorized users

The organization should determine which rules apply to each type of user.


Activities required to implement A.5.10

1. Identify assets that require acceptable-use rules

Start by identifying important assets users interact with.

Examples:

AssetAcceptable Use Consideration
Company LaptopBusiness use, software installation
EmailBusiness communication and data sharing
Cloud StorageApproved storage and sharing
GitHubSource-code handling
Slack/TeamsBusiness communication
InternetAppropriate business use
Mobile DeviceAccess to company information
AI ToolsHandling of confidential information
Production SystemsRestricted administrative use

Not every asset needs a separate policy.

The acceptable-use requirements can be consolidated into one organizational policy.


2. Define permitted use

The organization should explain what users are allowed to do.

For example:

Employees may:

  • Use company devices for authorized business activities
  • Access systems according to their assigned permissions
  • Use approved applications
  • Store business information in approved locations
  • Use approved cloud services
  • Access company systems remotely through approved methods
  • Report security incidents and suspected misuse

3. Define prohibited use

The policy should clearly identify activities that are not permitted.

Examples include:

Unauthorized access

Users must not attempt to access:

  • Another employee’s account
  • Systems without authorization
  • Production systems without approval
  • Restricted information

Credential sharing

Users must not:

  • Share passwords
  • Share MFA codes
  • Allow others to use their accounts

Unauthorized software

Users should not install:

  • Unapproved software
  • Pirated software
  • Malware
  • Security tools without authorization
  • Applications that create unacceptable security risks

Data misuse

Users must not:

  • Copy confidential information to personal storage
  • Send restricted information to unauthorized recipients
  • Upload sensitive information to unauthorized platforms
  • Publish confidential information publicly

4. Address email and communication use

Acceptable-use rules should cover organizational communication platforms.

Users should understand expectations around:

  • Business email
  • Messaging platforms
  • File sharing
  • External recipients
  • Confidential information
  • Phishing
  • Suspicious attachments
  • Sensitive information

Example

Before sending confidential information externally, employees should verify:

Recipient → Authorization → Information Sensitivity → Approved Transfer Method


5. Address internet usage

The organization may define appropriate internet use.

Users should not use organizational systems for activities that:

  • Violate applicable laws
  • Introduce malware
  • Circumvent security controls
  • Create unacceptable business risk
  • Damage the organization’s reputation
  • Consume excessive organizational resources

The organization should clearly distinguish between legitimate limited personal use, if permitted, and prohibited activities.


6. Address cloud and SaaS usage

Employees frequently create security risks by using unauthorized cloud services.

Examples include:

  • Personal Google Drive
  • Personal Dropbox
  • Personal OneDrive
  • Unauthorized file-sharing services
  • Unapproved project-management platforms
  • Unapproved AI applications

The organization should define:

Which cloud services are approved for business information?


7. Address AI and Generative AI usage

Modern acceptable-use policies should consider AI tools.

Employees may use AI tools for legitimate business purposes, but organizations should establish rules for handling company information.

For example, users may be prohibited from entering:

  • Customer confidential information
  • Passwords
  • API keys
  • Encryption keys
  • Personal information
  • Source code
  • Security vulnerabilities
  • Internal confidential documents

into unapproved AI services.

Example

Public information

→ AI tools may be permitted.

Internal information

→ Use only approved tools where permitted.

Confidential information

→ Require appropriate authorization and approved tools.

Restricted information

→ Prohibit external AI processing unless specifically authorized.

The exact rules should depend on the organization’s AI risk assessment.


8. Address removable media

If USB devices or removable media are permitted, the organization should establish rules.

For example:

  • Only approved devices may be used.
  • Sensitive information should not be copied without authorization.
  • Unknown USB devices should not be connected.
  • Lost removable media must be reported.
  • Encryption should be used where appropriate.

9. Address personal devices

If employees are allowed to use personal devices for business activities, the organization should establish appropriate rules.

This may include:

  • Device security
  • Screen lock
  • Encryption
  • Approved applications
  • Remote access
  • Data storage
  • Separation of personal and business information
  • Remote wipe where applicable

If personal devices are not permitted, the policy should clearly state this.


10. Address remote working

Remote employees may access company information from:

  • Home
  • Hotels
  • Airports
  • Coworking spaces
  • Customer locations

Acceptable-use requirements may include:

  • Use of approved devices
  • Secure Wi-Fi
  • VPN where required
  • Screen privacy
  • Secure storage
  • No unauthorized sharing
  • Immediate reporting of lost devices

11. Define user responsibilities

Users should understand their individual responsibilities.

For example:

Users are responsible for protecting the information and assets entrusted to them.

Responsibilities may include:

  • Protecting credentials
  • Locking devices
  • Reporting incidents
  • Protecting confidential information
  • Using approved applications
  • Following access restrictions
  • Reporting lost devices
  • Following data-classification requirements

12. Communicate the policy

A policy is only useful if users know about it.

The organization can communicate acceptable-use requirements through:

  • Employee onboarding
  • Security awareness training
  • Annual training
  • Employee handbook
  • Policy acknowledgment
  • Intranet
  • Email communications
  • Security awareness campaigns

Users may be required to acknowledge that they have read and understood the policy.


13. Review and update the rules

Acceptable-use requirements should evolve with technology.

For example, an organization may need to update its policy when it begins using:

  • Generative AI
  • New cloud platforms
  • BYOD
  • Remote working
  • New collaboration tools
  • New mobile applications

The policy should also be reviewed periodically.


Startup Example

Consider a SaaS startup with 50 employees.

Employees use:

  • Company laptops
  • Google Workspace
  • Slack
  • GitHub
  • AWS
  • Jira
  • Generative AI tools

The company establishes the following rules.

Employees may:

  • Use approved systems for business activities.
  • Use approved AI tools according to company rules.
  • Store company documents in approved cloud storage.
  • Access GitHub according to their role.
  • Work remotely using approved security controls.

Employees must not:

  • Share passwords or MFA codes.
  • Upload confidential customer information to unapproved AI tools.
  • Store company documents in personal cloud accounts.
  • Install unauthorized software.
  • Copy production data to personal devices.
  • Access systems without authorization.
  • Disable security controls.
  • Share confidential information with unauthorized people.

Employees must:

  • Lock their devices.
  • Protect credentials.
  • Report suspected security incidents.
  • Report lost or stolen devices.
  • Follow information-classification requirements.

This creates clear expectations without requiring a large number of separate policies.


Example Acceptable-Use Matrix

ActivityPermitted?Conditions
Business emailYesAuthorized business use
Approved cloud storageYesFollow classification rules
Personal cloud storageNo/RestrictedUnless explicitly approved
Company laptopYesFollow security requirements
Unauthorized softwareNoIT approval required
Password sharingNoNever permitted
Approved AI toolYesFollow AI/data rules
Uploading confidential data to public AINoUnless specifically authorized
Remote workYesFollow remote-access controls
USB storageRestrictedApproved devices only
Production accessRestrictedRole-based authorization
Personal use of company systemsOrganization-definedSubject to policy

Example Acceptable Use Register

For more mature organizations, specific assets can be tracked.

AssetAuthorized UsersPermitted UseRestrictionsOwner
Company LaptopEmployeesBusiness activitiesNo unauthorized softwareIT
GitHubDevelopersSource-code managementNo unauthorized repositoriesEngineering
AWS ProductionAuthorized AdminsProduction operationsPrivileged access onlyCTO
Google WorkspaceEmployeesBusiness communicationNo confidential sharing externallyIT
AI PlatformApproved UsersApproved business tasksNo restricted informationSecurity

A.5.10 Audit Evidence

An auditor may look for evidence such as:

Policy

  • Acceptable Use Policy
  • IT Usage Policy
  • Information Security Policy
  • AI Usage Policy
  • Remote Working Policy

Communication

  • Employee onboarding records
  • Security awareness training
  • Policy acknowledgment
  • Annual policy review

Technical enforcement

Where applicable:

  • Endpoint management
  • Application restrictions
  • DLP controls
  • Web filtering
  • Access controls
  • USB restrictions
  • Cloud access controls

User compliance

  • Policy acknowledgments
  • Security training records
  • Incident records
  • Policy violation records

A.5.10 Audit Checklist

Audit QuestionEvidence
Has the organization defined acceptable use of information assets?Acceptable Use Policy
Are permitted activities clearly defined?Policy
Are prohibited activities clearly defined?Policy
Does the policy cover company devices?Policy
Does it address cloud and SaaS services?Policy
Does it address remote working where applicable?Policy
Does it address removable media where applicable?Policy
Does it address AI tools where relevant?AI/Acceptable Use Policy
Are users informed of the requirements?Training Records
Do users acknowledge the policy where required?Acknowledgment Records
Is the policy reviewed periodically?Review Records
Are violations handled appropriately?Incident / HR Records

Common Mistakes

1. Creating a policy full of vague statements

For example:

“Employees must use technology responsibly.”

This is difficult to enforce.

Better:

“Employees must not share passwords, upload confidential information to unauthorized services, or install software without authorization.”

Specific rules are easier to understand.


2. Ignoring cloud applications

Employees may use numerous SaaS applications without realizing that company information is being transferred outside approved systems.


3. Ignoring AI tools

Modern organizations should consider how employees use ChatGPT and other generative AI services when handling company information.


4. Treating every user identically

A developer, HR employee and system administrator may have very different access and responsibilities.

Acceptable-use requirements should reflect their roles.


5. Having a policy but never communicating it

An unpublished policy is unlikely to be effective.

Users should be made aware of applicable requirements.


6. Creating rules that cannot be enforced

Policies should be realistic and aligned with the organization’s actual technology environment.


Practical Startup Implementation Model

A startup can implement A.5.10 with a simple process:

Identify Assets

↓

Identify Users

↓

Define Permitted Use

↓

Define Prohibited Use

↓

Define Data-Handling Rules

↓

Communicate Policy

↓

Obtain Acknowledgment

↓

Monitor Where Appropriate

↓

Handle Violations

↓

Review & Update


Policy vs. Process vs. Evidence

ElementExample
PolicyUsers shall use organizational information and associated assets only for authorized purposes and in accordance with defined security requirements.
ProcessAcceptable-use requirements are defined, communicated to users, acknowledged where appropriate, monitored and reviewed periodically.
EvidenceAcceptable Use Policy, training records, acknowledgment records, technical controls and incident records.

The objective is not to prevent employees from using technology productively.

The objective is to establish clear boundaries around how organizational information and assets may be used.


Useful Resources

Recommended documents

  • Acceptable Use Policy – [Insert Draft Document Link]
  • Employee IT Usage Policy – [Insert Draft Document Link]
  • AI Acceptable Use Policy – [Insert Draft Document Link]
  • Remote Working Policy – [Insert Draft Document Link]
  • BYOD Policy – [Insert Draft Document Link]
  • Information Classification Policy – [Insert Draft Document Link]
  • Security Awareness Training Material – [Insert Draft Document Link]

Related ISO 27001 controls

A.5.10 can work closely with:

  • A.5.9 – Inventory of information and other associated assets
  • A.5.10 – Acceptable use of information and other associated assets
  • A.5.12 – Classification of information
  • A.5.13 – Labelling of information
  • A.5.14 – Information transfer
  • A.5.15 – Access control
  • A.6.3 – Information security awareness, education and training
  • A.8.1 – User endpoint devices
  • A.8.12 – Data leakage prevention
  • A.8.19 – Installation of software on operational systems

Final Takeaway

ISO 27001 Annex A 5.10 is about establishing clear rules for how employees and other authorized users may use organizational information and technology assets.

A practical organization should be able to answer:

What can users do with company assets?
What are they prohibited from doing?
How should sensitive information be handled?
Are cloud and AI tools covered?
Have users been informed of the requirements?
What happens when the rules are violated?

For startups, the approach can remain simple:

Define → Communicate → Acknowledge → Enforce → Review

The objective is not to restrict technology unnecessarily.

It is to make sure that employees understand how to use organizational information and technology safely, responsibly and within authorized boundaries.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *