SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.10Acceptable use of information and other associated assets

Set clear rules for how staff may use company information, devices and systems, and make sure everyone knows them. This prevents careless or risky handling of company assets.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

In practice

For most companies this is a short document handed out at onboarding: no personal cloud storage for client files, no company laptop used for openly risky purposes, and a clear line on what happens to a departing employee's data. Auditors rarely test acceptable use by reading the document alone; they ask staff at random what they would do with a suspicious USB stick found in the parking lot, or check whether anyone is running unauthorised chat apps or file-sharing tools. The typical gap is a policy that reads well but was never checked against what shadow IT discovery tooling, when it exists, finds running on the network.

Common gaps

The acceptable use policy exists but was never distributed beyond a link buried in the employee handbook, and most staff cannot recall having read it.
Personal cloud storage and messaging apps are technically prohibited on paper but are visibly in daily use for sharing client files.
The rules cover company laptops but say nothing about personal phones used to check work email or access company systems.

Questions your auditor will ask

How do staff learn what they may and may not do with company devices and data?
Point to the signed acceptable use policy delivered during onboarding, plus any refresher communication sent after a material update.
How do you catch unauthorised apps or services staff start using on their own?
Describe the shadow IT discovery routine that periodically checks for technology in use that was never approved, and the process for adopting or retiring what it finds.
What is prohibited under the acceptable use policy?
Walk through the specific restrictions, such as unauthorised cloud storage, personal use of company credentials, and removable media rules, named in the policy.
Does the policy address personal devices used for work?
Confirm whether personal phones or laptops accessing company email or files are covered, and what conditions apply if they are permitted.

Where regulation demands it

NIS2 art. 12.2 (Handling of assets) requires the same day-to-day handling rules A.5.10 asks organizations to set for staff use of company assets.
ENS mp.si.1 (Marcado de soportes) covers marking media with the classification of the information it holds, one specific rule inside the broader acceptable-use set A.5.10 requires.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.10?”
Also via MCP, free with account