Skip to content
compliancebase
ISO 27001A.5 — Acceptable use of information and other assets

A.5.10

Acceptable use of information and other assets

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Define and enforce acceptable use rules for information, assets, and processing facilities.

Points of focus

  • Acceptable use policy published
  • Coverage of devices, cloud apps, and data handling
  • Acknowledgement on join and major revisions
  • Enforcement linked to disciplinary process

Implementation notes

Keep acceptable use short and concrete: approved collaboration tools, prohibited data locations, AI/paste rules for customer data, and personal device expectations. Collect acknowledgements at hire and on material updates. Route new SaaS via a lightweight approval so A.5.10 and supplier controls stay aligned. Pair with A.5.9 inventory so 'approved tools' matches reality.

Audit tip: Show acknowledgement rates and how a recent shadow-IT request was handled.

Evidence auditors typically request:

  • Acceptable use policy with version
  • HRIS acknowledgement records
  • Exception requests for non-standard tools
  • Related disciplinary or coaching examples (redacted)

Common gaps

  • Policy silent on AI tools / shadow SaaS
  • Acknowledgements never collected
  • BYOD use without stated rules

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.10This control

Primary sources

Frequently Asked Questions

If it covers information security use rules with version control and acknowledgements, yes — avoid a second unread policy.

Include contractors with system access in acknowledgements or equivalent contract schedules.

On hire plus when the policy materially changes; annual re-ack is common but not magic.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above