ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10

ISO 27001 Acceptable Use of Information and Other Associated Assets Explained – Control 5.10

Most information security incidents involve misuse, not technical failure. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations invest heavily in next-gen firewalls, endpoint detection, and complex cloud security tools, only to suffer a disastrous breach because an employee installed unvetted shadow IT software, forwarded sensitive commercial files to their personal webmail to work over the weekend, or plugged an unknown USB drive into a corporate workstation. Without explicit, readable rules, staff will make up their own standards of what is “acceptable”—and those standards vary wildly. Annex A 5.10 removes ambiguity, replacing guesswork with clear, practical boundaries that protect assets without paralyzing daily business operations.

ISO 27001:2022 includes Annex A 5.10 to ensure your organisation defines, documents, communicates, and enforces acceptable use rules for information assets, systems, and devices. This control updates former 2013 requirements (8.1.3) and acts as the essential human behavioral bridge connecting asset management (Annex A 8.9), information classification (Annex A 5.12), access control (Annex A 5.15), and security awareness training (Annex A 6.3).

Quick Summary: What ISO 27001 Annex A 5.10 Requires

At a practical level, Annex A 5.10 is about setting clear, realistic, and enforceable rules for how employees, contractors, and third parties interact with your systems, data, and devices. It does not mean banning all personal use or creating a draconian 80-page policy that nobody reads; it expects a pragmatic Acceptable Use Policy (AUP) tailored to your operational reality. Here is what you need to do in plain English:

  • Publish a Clear Acceptable Use Policy (AUP): Document explicit rules covering business vs. personal device use, email hygiene, internet browsing, SaaS tool usage, and social media behavior.
  • Define Prohibited High-Risk Activities: Explicitly ban shadow IT installations, disabling security agents, sharing credentials, auto-forwarding corporate email, and storing sensitive data on unapproved personal cloud accounts.
  • Map Use Rules to Information Classification: Tie acceptable handling rules directly to your classification tiers (Public, Internal, Confidential, Restricted) (Annex A 5.12).
  • Enforce Explicit AUP Acknowledgement: Require all new joiners, contractors, and existing staff to review and sign/acknowledge the AUP during onboarding (Annex A 6.1) and annual refreshers.
  • Address the Full Asset Lifecycle: Define acceptable behaviors across data creation, daily processing, mobile/remote handling (Annex A 6.7), clean desk habits (Annex A 7.7), and asset return (Annex A 5.11).
  • Support Rules with Technical Guardrails: Back up policy rules with automated technical controls (e.g., blocking unapproved software installs, USB device restrictions, and web content filtering).

Why Ambiguous Acceptable Use Rules Are a Critical Hazard

When an organisation manages asset use through unwritten assumptions or verbal “common sense,” employees default to the path of least resistance. When security rules create friction, staff routinely bypass controls to get their daily work done.

Ignoring acceptable use controls exposes your business to severe hazards:

  • Rogue Shadow IT & Unvetted SaaS Sprawl: Employees subscribing to unvetted AI tools or file-sharing platforms using personal credit cards, uploading sensitive customer PII or commercial code into unencrypted public cloud tenants (Annex A 5.23).
  • Malware Infiltration via Unapproved Software: Staff downloading pirated software, browser extensions, or administrative utility tools that carry hidden ransomware or keyloggers onto corporate networks.
  • Data Exfiltration via Personal Channels: Staff emailing sensitive commercial files to personal webmail or copying confidential archives onto unencrypted USB drives (Annex A 5.14).
  • Inability to Enforce Disciplinary Action: HR and Legal teams being completely unable to hold employees accountable for malicious or reckless data handling because the organisation never explicitly prohibited the behavior in writing (Annex A 6.4).

My 8 Step Plan to Implement Annex A 5.10 Fast

You do not need a complex, bureaucratic legal manifesto to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready acceptable use framework.

1. Publish a Concise, Read-Friendly Acceptable Use Policy (AUP)

Document a clear, 3-to-4 page Acceptable Use Policy written in plain English, avoiding dense legalese (Annex A 5.1):

  • Define acceptable business use of company laptops, mobile devices, internet access, corporate email, and collaboration channels (Slack, Microsoft Teams).
  • Define clear boundaries for incidental personal use (e.g., “Reasonable personal use of internet during breaks is permitted provided it does not disrupt work or violate security rules”).
  • Highlight employee accountability and the requirement to report security incidents or lost devices immediately (Annex A 6.8).

2. Explicitly Define Prohibited & High-Risk Behaviors

Eliminate ambiguity by publishing a clear “Never Do” list across your AUP documentation:

  • Prohibit installing unauthorized third-party software, browser add-ons, or pirated media on company endpoints.
  • Prohibit auto-forwarding corporate emails to personal webmail accounts or uploading company files to personal cloud drives (e.g., personal Dropbox, Google Drive).
  • Prohibit sharing user credentials, writing down passwords, disabling endpoint antivirus agents, or bypassing MFA prompts (Annex A 5.17).
  • Prohibit using corporate email or assets for illegal activities, offensive content, or unauthorized commercial side-businesses.

3. Map Acceptable Use to Data Classification Handling Rules

Ensure acceptable use rules align directly with your Data Classification & Handling Matrix (Annex A 5.12):

  • Public Data: Unrestricted sharing; acceptable for public social media and external marketing.
  • Internal Data: Acceptable on approved corporate channels; prohibited on public web forums or open repositories.
  • Confidential / Restricted Data (PII, Financials, Source Code): Must be processed strictly inside encrypted, approved enterprise SaaS platforms; direct email attachments, USB transfers, or pasting into unvetted public AI tools (e.g., ChatGPT free tier) strictly prohibited.

4. Address Remote, Mobile, and BYOD Use Rules

Extend acceptable use rules to remote, work-from-home, and mobile environments (Annex A 6.7):

  • Prohibit family members or non-employees from accessing or using company-issued laptops or mobile devices under any circumstances.
  • Mandate privacy screens and prohibit discussing confidential client matters in public spaces (trains, coffee shops, open spaces) (Annex A 5.14).
  • Enforce strict BYOD (Bring Your Own Device) rules: require Mobile Application Management (MAM) containerization for personal phones accessing corporate email or Slack.

5. Back Up Policy with Technical Enforcement Guardrails

Policy alone is insufficient; support human rules with automated technical guardrails:

  • Enforce standard user privileges (remove local administrative rights) on endpoints to prevent unauthorized software installations.
  • Deploy Web Content Filtering and Cloud Access Security Brokers (CASB) to block access to known malicious sites, personal webmail, and unapproved file-sharing domains (Annex A 8.23).
  • Disable unencrypted USB mass storage devices globally using Endpoint Detection and Response (EDR) or MDM policies (Annex A 7.10).

6. Embed AUP Acknowledgement into HR Onboarding and Exit

Ensure acceptable use rules are legally binding across the employee lifecycle (Annex A 6.1 & Annex A 6.5):

  • Require all new joiners to review and digitally sign/acknowledge the Acceptable Use Policy prior to receiving system access credentials (Annex A 5.18).
  • Incorporate annual AUP re-acknowledgement prompts into your central HR or learning management portal.
  • Remind departing staff of their ongoing confidentiality obligations and acceptable asset return duties during HR exit interviews (Annex A 5.11).

7. Communicate AUP Expectations via Engaging Awareness Training

Transform your policy from a passive document into active operational culture (Annex A 6.3):

  • Deliver engaging, scenario-based security awareness micro-learning showing real-world examples of acceptable vs. unacceptable asset handling.
  • Run quarterly simulated phishing exercises to reinforce acceptable email handling behaviors without punishing staff.
  • Reinforce clear desk and clear screen rules (Annex A 7.7) through routine office walkthroughs and remote working tips.

8. Audit AUP Compliance and Feed Findings into Management Reviews

Verify that acceptable use rules are followed in daily operations (Annex A 5.36):

  • Review SIEM logs, shadow IT discovery reports, and DLP alerts monthly (Annex A 8.15) to identify unapproved software or unauthorized data transfer attempts.
  • Involve HR and Legal leads promptly whenever serious, intentional AUP policy violations occur (Annex A 6.4).
  • Present AUP policy compliance metrics and policy violation trends to executive leadership during formal ISMS Management Reviews.

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same acceptable use mistakes. Here are the main traps and how to solve them:

  • Problem: Writing an Overly Restrictive 50-Page Policy That Bans All Personal Use, Forcing Staff onto Shadow IT
    Ninja Solution: Keep the AUP concise and practical; permit reasonable, incidental personal use while setting strict guardrails around company data.
  • Problem: Publishing an AUP on the Intranet but Never Requiring Staff to Read or Sign It
    Ninja Solution: Mandate digital AUP signature/acknowledgement during HR onboarding and require annual re-certification.
  • Problem: Relying Entirely on Written Policy Without Applying Technical Local Admin Restrictions
    Ninja Solution: Remove local admin rights on user workstations so staff physically cannot install unauthorized software.
  • Problem: Failing to Update the AUP to Cover Modern Workplace Risks (Generative AI, SaaS, Remote Work)
    Ninja Solution: Review and update your AUP annually to include explicit rules governing Generative AI tools, SaaS adoption, and remote working.

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 5.10 is about replacing human guesswork and informal assumptions with clear, fair, and enforceable operational boundaries. Technical controls provide defensive walls, but human behavior determines whether those walls hold; setting clear acceptable use rules protects your information assets without destroying business agility.

By publishing a concise AUP, defining prohibited high-risk activities, mapping rules to data classifications, establishing remote/BYOD guidelines, enforcing local admin technical blocks, requiring onboarding AUP sign-offs, delivering engaging awareness training, and auditing compliance logs, you build a strong security culture, eliminate shadow IT risks, and satisfy your ISO 27001 auditor with complete confidence.