ISO 27001A.5 — Acceptable use of information and other assets
A.5.10
Acceptable use of information and other assets
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Define and enforce acceptable use rules for information, assets, and processing facilities.
Points of focus
- Acceptable use policy published
- Coverage of devices, cloud apps, and data handling
- Acknowledgement on join and major revisions
- Enforcement linked to disciplinary process
Implementation notes
Keep acceptable use short and concrete: approved collaboration tools, prohibited data locations, AI/paste rules for customer data, and personal device expectations. Collect acknowledgements at hire and on material updates. Route new SaaS via a lightweight approval so A.5.10 and supplier controls stay aligned. Pair with A.5.9 inventory so 'approved tools' matches reality.
Audit tip: Show acknowledgement rates and how a recent shadow-IT request was handled.
Evidence auditors typically request:
- Acceptable use policy with version
- HRIS acknowledgement records
- Exception requests for non-standard tools
- Related disciplinary or coaching examples (redacted)
Common gaps
- Policy silent on AI tools / shadow SaaS
- Acknowledgements never collected
- BYOD use without stated rules
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.10 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.10)
Frequently Asked Questions
If it covers information security use rules with version control and acknowledgements, yes — avoid a second unread policy.
Include contractors with system access in acknowledgements or equivalent contract schedules.
On hire plus when the policy materially changes; annual re-ack is common but not magic.