ISO/IEC 27001:2022 Annex A · Control 5.10
Acceptable Use of Information and Other Associated Assets: A Practical Implementation Guide
Give users clear, realistic rules for handling information, devices, systems and services.
Acceptable-use rules define permitted and prohibited behavior for information and associated assets throughout their lifecycle.
What should the control achieve?
- Users understand permitted and prohibited behavior.
- Rules cover relevant assets, technologies and contexts.
- Exceptions are authorized and time limited.
- Violations are consistently handled.
Step-by-step implementation
Identify use scenarios
Cover corporate devices, personal devices, email, internet, removable media, cloud services, AI tools, remote work and confidential information.
Write practical rules
Use examples and distinguish mandatory rules from guidance.
Align with law and culture
Review privacy, monitoring, employment and works-council requirements.
Communicate and acknowledge
Include onboarding, periodic refreshers and targeted updates.
Enforce and monitor
Configure technical restrictions where appropriate and define proportionate investigation.
Manage exceptions
Document business need, risk, safeguards, owner and expiry.
What this could look like in practice
A consultancy permits limited personal use of laptops but prohibits unapproved file-sharing and entering client data into public AI tools. Web filtering blocks high-risk categories, staff acknowledge the policy at onboarding and exceptions require Security approval.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Onboarding | Employee reviews rules before receiving equipment. | Acknowledgement record |
| New technology | Policy owner assesses AI and collaboration use cases. | Updated guidance |
| Violation | Manager, HR and Security follow a documented response. | Case record |
Implementation evidence
- Acceptable-use policy
- Acknowledgements
- Awareness materials
- Technical restrictions
- Exception register
- Investigation procedure
- Disciplinary linkage
- Review history
Useful metrics
- Acknowledgement completion
- Policy-related incidents
- Expired exceptions
- Repeated violations
Common mistakes
- Using generic rules employees cannot interpret.
- Banning common practices without approved alternatives.
- Monitoring without legal review or transparency.
- Ignoring contractors and personal devices.
- Failing to update rules for new technology.
Questions an auditor may ask
- How are users informed of acceptable use?
- Which behaviors are technically restricted?
- How are exceptions approved?
- Show how a recent violation was handled.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.