A.5.10Acceptable use of information and other associated assets
Set clear rules for how staff may use company information, devices and systems, and make sure everyone knows them. This prevents careless or risky handling of company assets.
Mapping at a glance
A.5.10Acceptable use of information and other associated assetsISO/IEC 27001:2022
For most companies this is a short document handed out at onboarding: no personal cloud storage for client files, no company laptop used for openly risky purposes, and a clear line on what happens to a departing employee's data. Auditors rarely test acceptable use by reading the document alone; they ask staff at random what they would do with a suspicious USB stick found in the parking lot, or check whether anyone is running unauthorised chat apps or file-sharing tools. The typical gap is a policy that reads well but was never checked against what shadow IT discovery tooling, when it exists, finds running on the network.
Common gaps
The acceptable use policy exists but was never distributed beyond a link buried in the employee handbook, and most staff cannot recall having read it.
Personal cloud storage and messaging apps are technically prohibited on paper but are visibly in daily use for sharing client files.
The rules cover company laptops but say nothing about personal phones used to check work email or access company systems.
Questions your auditor will ask
How do staff learn what they may and may not do with company devices and data?
Point to the signed acceptable use policy delivered during onboarding, plus any refresher communication sent after a material update.
How do you catch unauthorised apps or services staff start using on their own?
Describe the shadow IT discovery routine that periodically checks for technology in use that was never approved, and the process for adopting or retiring what it finds.
What is prohibited under the acceptable use policy?
Walk through the specific restrictions, such as unauthorised cloud storage, personal use of company credentials, and removable media rules, named in the policy.
Does the policy address personal devices used for work?
Confirm whether personal phones or laptops accessing company email or files are covered, and what conditions apply if they are permitted.
Where regulation demands it
NIS2 art. 12.2 (Handling of assets) requires the same day-to-day handling rules A.5.10 asks organizations to set for staff use of company assets.
ENS mp.si.1 (Marcado de soportes) covers marking media with the classification of the information it holds, one specific rule inside the broader acceptable-use set A.5.10 requires.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.