ISO27001:2022 – A5.10 Acceptable use of information and other associated assets

Introduction to ISO 27001 – A5.10

We all have our own views on what is and isn’t acceptable in our personal lives.

For example, you may not allow pets on the sofa, while someone else does. You might find it acceptable to use your mobile during a conversation, while others may not. These are unwritten personal rules we apply to our lives.; We define what is and is not acceptable.

But what does this look like in business?

Watch our video below for an overview of the Annex A control, and read the pages below to see what needs to be done.

In business, there are norms — like emailing late on a Friday — that some consider acceptable and others do not. But when it comes to information security and data protection, this kind of ambiguity leaves your organisation at risk.

That’s why ISO 27001 – A5.10 is such a critical control. It requires you to clearly define what you deem to be acceptable regarding the use of information and associated assets — for both internal staff and third parties like vendors or contractors.

What does ISO 27001 – A5.10 require?

The standard states that:

“Rules for the acceptable use and procedures for handling information and other associated assets should be identified, documented and implemented.” (A5.10 Acceptable Use of Information and Other Associated Assets)

Why is this required?

If you don’t define what’s acceptable, people will apply their own standards. In life, we may get away with it — in business, that’s a risk. For example:

  • Is it okay to email personal data externally?
  • What about sending bank details?
  • What if it’s customer financial data?

Without clear rules, these questions have no consistent answer. But if you specify, for instance, that financial data must always be encrypted before emailing, you’ve established a standard. If someone violates it, you can take appropriate action — assuming they were aware of the rule in the first place.

This also applies to how systems are used. Is it acceptable to browse gambling sites at work? What about streaming services or using AI tools like ChatGPT?

Perhaps you’re fine with AI in marketing but not in software development. These rules depend on your organisation’s values and risks. The important part: have the conversation.

What the auditor is looking for

The auditor will be looking for evidence of clear rules and defined procedures for handling data. Specifically, they will expect to see:

  • An Acceptable Use Policy
  • Employee contracts
  • Contractor/consultant contracts
  • Data Processing Agreements (in supplier contracts)
  • Standard Operating Procedures (SOP)

Your Acceptable Use Policy should cover topics like:

    • Email and internet use
    • Mobile phone and laptop usage
    • Accessing or storing sensitive data
    • Acceptable use of AI

Third-party contracts should clearly define expectations — for example, requiring the deletion of data post-contract or restricting system access. Your Standard Operating Procedures (SOP) should define what is acceptable when sharing or disposing of data, such as encryption methods or device wiping protocols.

Once in place, make sure these rules are communicated — and that you audit compliance against them.

Q & A

Should these rules include use of personal devices?

Yes. Consider whether personal phones are allowed at desks. Can staff access company email from their phones? What’s acceptable will vary, but you need to define it clearly.

Is it possible to get this wrong?

Absolutely. If your rules are overly strict, they may alienate your team. The key is to strike a balance. Be respectful, but clear. A well-written policy educates, informs, and encourages responsible behaviour.

Difficulty rating

We rate this a 1 out of 5. It requires minimal technical knowledge, but does require thoughtful input from your management team. Use the items above as a starting point to define your own standards.

More questions?

Remember, no ISO27001 control stands alone. Review our FAQ for related controls and implementation tips. Still need help with Acceptable Use Policies or setting clear expectations? Get in touch — we’re happy to help.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book.. The Real Easy Guide to ISO27001”, available on Amazon.

ISO 27001 – A5.10