ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets defines rules for using company systems, networks, and data safely. Documented guidelines prevent security breaches, stop unauthorized activities, and ensure staff protect organizational property.
Table of contents
Key Takeaways
- Define acceptable asset usage: Create clear rules governing how staff, contractors, and third parties use company systems, devices, and data.
- Store rules centrally: Keep acceptable use policies, code of conduct agreements, and user sign-off logs in a central document repository.
- Cover all asset types: Establish explicit usage boundaries for company hardware, email systems, internet access, software tools, and facilities.
- Clarify personal usage limits: State clearly whether incidental personal use of work equipment is permitted and under what conditions.
- Prohibit high-risk activities: Ban illegal downloads, unapproved tool installations, visiting malicious websites, and sending unencrypted sensitive data.
- Require mandatory user sign-off: Ensure all workers read and accept acceptable use policies before receiving system access or devices.
- Enforce monitoring transparency: Inform workers about workplace monitoring, log collection, and privacy boundaries according to local employment laws.
- Review usage rules annually: Update acceptable use guidelines regularly to address new workplace trends, remote working, and emerging technologies.

How to Implement ISO 27001 Annex A 5.10
- Draft an acceptable use policy: Write a comprehensive acceptable use policy and publish it in your central document repository.
- Define clear usage rules: Detail allowed and prohibited activities for internet browsing, email communication, software downloads, and file sharing.
- Integrate sign-off with onboarding: Require new employees and contractors to sign the acceptable use policy before granting user accounts.
- Define clean desk and screen rules: Establish requirements for locking unattended workstations and securing physical documents when leaving desks.
- Set remote working standards: Include guidelines for securing home offices, public networks, and mobile devices when working off site.
- Establish asset care duties: Instruct workers on protecting assigned laptops, mobile devices, and storage media from loss or physical damage.
- Deploy technical guardrails: Configure content filters, web filtering rules, and permission limits to block unapproved tools automatically.
- Train staff on acceptable use: Deliver regular security awareness sessions highlighting real-world examples of safe and unsafe behaviour.
- Enforce disciplinary procedures: Outline clear consequences for intentional policy violations and link them to company disciplinary codes.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.10
- Review acceptable use policies: Inspect written procedures to verify comprehensive rules cover all corporate assets, systems, and communications.
- Sample user sign-off records: Check employee and contractor personnel files to verify signed policy acceptance records exist for sampled staff.
- Verify pre-access timing: Compare policy acceptance timestamps against account creation dates to ensure sign-offs came first.
- Inspect technical guardrail settings: Check web filtering, system lockdown rules, and permission settings to ensure policy restrictions are enforced.
- Audit policy violation logs: Review incident reports to confirm management investigated and addressed reported acceptable use breaches.
- Perform physical walkthroughs: Conduct unannounced office spot checks to verify compliance with clean desk and clear screen rules.
- Interview operational staff: Speak with team members to test their understanding of acceptable daily asset usage and prohibited actions.
- Check policy review cycles: Confirm that leadership reviewed and re-approved the acceptable use policy within the last twelve months.
Audit Evidence Checklist
- Acceptable use policy: Maintain a documented acceptable use policy with complete revision history in your central repository.
- Signed employee acceptance logs: Supply digital or physical sign-off records proving workers accepted acceptable use terms.
- Contractor policy acknowledgments: Provide signed agreements showing third-party workers agreed to company asset usage rules.
- Clean desk audit reports: Produce inspection logs from routine physical walkthroughs checking screen locks and paper security.
- Technical filtering configuration logs: Supply configuration screenshots proving web filtering and application restrictions are active.
- Policy violation investigation records: Provide closed incident tickets documenting actions taken following acceptable use violations.
- Staff training attendance records: Show sign-off sheets proving workers finished training on acceptable asset use and security rules.
What to Teach Employees
- Use assets for business purposes: Teach staff that company laptops, email accounts, and networks are provided primarily for work tasks.
- Never install unvetted software: Instruct workers not to download unapproved programmes, games, or browser extensions on work devices.
- Lock screens when stepping away: Remind staff to lock their computer screens every time they leave their desk or workspace.
- Avoid unsafe websites: Warn employees against browsing dangerous, unverified, or illegal web pages using company equipment.
- Protect work devices in public: Instruct staff never to leave laptops unattended in cars, coffee shops, or public transport.
- Report asset misuse immediately: Ensure workers know how to report lost equipment, strange computer behaviour, or policy breaches fast.
Common Implementation Challenges
- Unclear personal use boundaries: Vague policies cause confusion over personal browsing limits. Define explicit, reasonable boundaries for personal use.
- Missing user sign-offs: Staff start work without signing policies. Integrate policy acknowledgment into automated onboarding portals.
- Uncontrolled shadow tool use: Workers use unvetted web tools to finish tasks faster. Provide approved corporate solutions and block unapproved apps.
- Neglecting remote workers: Home-based staff use work laptops on insecure networks. Enforce mandatory VPNs and disk encryption for all remote laptops.
- Overly strict, unworkable rules: Impractical restrictions cause staff to find risky workarounds. Balance security needs with daily operational workflows.
- Inconsistent policy enforcement: Failing to address minor violations leads to casual rule breaking. Apply policy standards fairly across all staff levels.
How to Measure Effectiveness (KPIs)
- Policy acknowledgment rate: Track the percentage of active employees and contractors with signed acceptable use agreements on file.
- Acceptable use incident count: Monitor the total number of security events or disciplinary actions linked to acceptable use violations.
- Clean desk compliance rate: Measure the proportion of workstations passing unannounced physical clean desk and clear screen inspections.
- Blocked website attempt rate: Track the volume of blocked attempts to access restricted or malicious websites each month.
- Awareness training completion rate: Track the percentage of workers who finish annual training on acceptable asset use.
- Acceptable use audit finding count: Monitor the number of non-conformities raised against acceptable use rules during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.10 connects to several other ISO 27001 requirements:
Annex A 5.10 does not operate in isolation. It relies on Clause 5.9 (Inventory of Information) to identify what needs protection. It connects to Clause 5.12 (Classification of Information) to determine handling rules. Finally, it supports Clause 6.3 (Information Security Awareness) by providing the content for staff training programmes.
