A.5.10A.5 Organizational controls

Acceptable use of information and other associated assets

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.10 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Ensure information and associated assets are properly protected, used and handled.

How to meet this control

In short: Document and implement rules for acceptable use and handling of assets.

  1. Step 01Publish an Acceptable Use Policy covering email, internet, devices, cloud apps, AI tools and removable media, and capture acknowledgement at onboarding and annually
  2. Step 02State clearly that the organisation monitors use of its assets so monitoring is lawful and expected
  3. Step 03Define handling rules for each classification level across the full lifecycle (create, store, transmit, dispose)
  4. Step 04Apply the same protection to copies, drafts and backups as to the original information
  5. Step 05Set and communicate approved secure disposal and deletion methods and control use of third-party and cloud assets

Tip: Have staff acknowledge an Acceptable Use Policy at onboarding and annually.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Make users aware of the security requirements for protecting the assets they use
  • ›Hold users responsible for any assets and processing facilities they use
  • ›Establish and communicate a topic-specific policy on acceptable use
  • ›State expected and unacceptable behaviours and permitted and prohibited uses
  • ›Tell users that the organisation monitors use of its assets
  • ›Set handling procedures across the full information life cycle based on classification
  • ›Protect temporary and permanent copies to the same level as the original information
  • ›Define authorised disposal and secure deletion methods, and control use of third-party or cloud assets

Audit evidence to keep

  • - Acceptable Use Policy with staff acknowledgement records
  • - Documented handling rules mapped to each classification level
  • - Notice to staff that asset usage is monitored
  • - Evidence acknowledgements are refreshed periodically (for example annually)

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.10. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.