Skip to main contentChat with us

ISO 27001:2022 Annex A  ·  Organizational Control

A.5.10
Acceptable use of information and other associated assets

To ensure that employees and third parties understand their responsibilities regarding the acceptable use of information, systems, and assets, preventing misuse and protecting organizational interests.

Last reviewed: June 12, 2026  ·  Authored by TÜV SÜD & BSI Certified Lead Auditors

Control Definition

The organization must work out and write down the rules for how information and other associated assets may acceptably be used, along with procedures for handling them, and then put both into practice.

Control Objective

To ensure that employees and third parties understand their responsibilities regarding the acceptable use of information, systems, and assets, preventing misuse and protecting organizational interests.

What This Really Means

Acceptable Use Policy (AUP) is your organization's rulebook for how employees can and cannot use company information, computers, networks, email, internet, mobile devices, and cloud services. It defines what's allowed, what's forbidden, and what happens if rules are broken.

Think of it like terms of service for your workplace: you're provided tools to do your job, but you can't use them for anything—personal projects, illegal activity, harassment, downloading pirated software, or sharing confidential data on social media. The AUP sets boundaries.

This control requires you to document these rules clearly, communicate them to everyone (employees, contractors, vendors), obtain acknowledgment that they've read and understood the policy, and enforce consequences for violations. It covers everything from "no personal use of company email" to "don't click suspicious links" to "all work created using company resources belongs to the company." The goal is preventing both malicious and accidental misuse of organizational assets.

Why It Matters

Without clear acceptable use rules, employees make their own decisions—often putting the organization at risk. Insider threats, data leaks, legal liability, and productivity loss all stem from undefined or unenforced acceptable use boundaries.

Without documented and enforced acceptable use policies, organizations face:

  • Data Breaches and IP Theft – Employees emailing customer lists to personal Gmail, uploading source code to public GitHub, or storing sensitive files in personal Dropbox without realizing it violates policy
  • Legal Liability and HR Issues – Employees using company email for harassment, viewing inappropriate content on company devices, or making defamatory statements on social media using company accounts
  • Malware and Security Incidents – Users installing unapproved software, clicking phishing links, or connecting infected USB drives because "nobody said I couldn't"
  • Productivity Loss and Bandwidth Abuse – Employees streaming Netflix, gaming, torrenting files, or running personal side businesses using company resources

Indian organizations face additional risks: DPDPA holds organizations accountable for employee mishandling of personal data, making clear acceptable use rules legally critical.

Implementation Guidance

1

Draft Comprehensive Acceptable Use Policy Covering All Asset Types

Document rules for: email usage (personal use limits, no spam/harassment), internet browsing (blocked categories, monitoring disclosure), software installation (approved lists only), mobile devices (BYOD rules, separation of personal/work data), cloud services (approved SaaS only), USB drives (encryption required), and information handling (no personal email forwarding). Keep language clear and specific, not vague.

2

Define What's Explicitly Prohibited with Examples

List forbidden activities: accessing/storing illegal content, installing pirated software, cryptocurrency mining, running personal businesses, harassment or discrimination, sharing credentials, bypassing security controls, connecting unauthorized devices, using company resources for political campaigns. Provide real examples so there's no ambiguity.

3

Specify Monitoring and Privacy Expectations

Clearly state: "Company reserves the right to monitor all use of company systems, networks, email, and internet. Employees should have no expectation of privacy when using company assets." Specify what's monitored (email content, web browsing, file transfers), how (DLP tools, firewall logs, endpoint monitoring), and under what circumstances (routine audits, investigations).

4

Establish Consequences for Policy Violations

Define disciplinary actions for violations: first offense (written warning), second offense (suspension), severe violations (immediate termination). Specify who investigates (HR + IT Security), how violations are reported, and under what conditions law enforcement may be involved. Make consequences clear and consistent with employment law.

5

Require Signed Acknowledgment from All Users

During onboarding, require new employees to read the AUP and sign an acknowledgment form: "I have read, understood, and agree to comply with the Acceptable Use Policy." Obtain signatures digitally (DocuSign, HR portal) or on paper. Require annual re-acknowledgment. Extend to contractors, vendors, and temporary staff. Maintain acknowledgment records for audit.

6

Communicate Policy Through Multiple Channels

Don't just email a PDF and hope people read it. Conduct in-person or video training sessions highlighting key rules, include policy in employee handbook, post reminders on intranet, send quarterly security awareness emails with policy highlights, and display login banners: "Authorized use only. Usage is monitored and logged."

7

Implement Technical Controls to Enforce Policy

Back policy with technology: web filtering to block inappropriate sites, DLP to prevent data exfiltration, application whitelisting to restrict software installations, USB blocking on sensitive workstations, email monitoring for policy keywords, and endpoint detection to identify unauthorized software. Policy + enforcement = compliance.

Audit Evidence

During your ISO 27001 certification audit, auditors will expect to see the following evidence to demonstrate compliance with A.5.10:

Documentation

  • Acceptable Use Policy document approved by management and version-controlled
  • Employee acknowledgment forms (signed or digitally accepted) for all personnel
  • Training records showing AUP communication and awareness sessions
  • Incident reports documenting policy violations and disciplinary actions taken
  • Technical controls configuration (web filters, DLP rules, application whitelisting)

Interviews

  • HR representatives about policy distribution and acknowledgment tracking
  • IT Security team about technical enforcement mechanisms and monitoring
  • Random employees to verify they're aware of AUP rules and where to find the policy

Observations

  • Review of HR onboarding checklist showing AUP acknowledgment requirement
  • Demonstration of technical controls (web filtering dashboard, DLP alerts)
  • Testing policy enforcement by attempting prohibited actions (install software, access blocked site)
  • Review of incident management system showing policy violation investigations

Practitioner Insights

Surendra Pal Singh

I've seen companies with beautiful 50-page Acceptable Use Policies that nobody reads or signs. During audits, when I ask employees "Can you use company email for personal business?" they just shrug. Your AUP must be concise (5-10 pages max), written in plain language, and actively enforced. A one-page summary with key do's and don'ts is more effective than a legal treatise.

Surendra Pal Singh · CISO, DPO, CISA, ISO 27001, 27701, 42001 Lead Auditor
Saundhi Chauhan

The biggest gap: policies say "no unauthorized software installation" but don't specify what's authorized. Employees then install Chrome extensions, developer tools, or collaboration apps assuming they're fine. Maintain an approved software list, use application whitelisting, and provide a self-service portal for requesting new tools. Make it easy to comply, hard to violate.

Saundhi Chauhan · ISO 27001, 27701 Lead Auditor

Common Challenges & Solutions

Challenge

Employees claim they never saw the AUP or didn't know certain activities were prohibited.

Solution

Implement mandatory acknowledgment during onboarding before granting system access—no signature, no account. Display policy summary on login screen. Send annual reminders with "click here to re-certify you've read the policy." Include AUP questions in security awareness training. Maintain audit logs of who acknowledged when.

Challenge

Policy prohibits personal use of company resources, but executives and senior management routinely ignore it.

Solution

Get executive buy-in before rolling out policy—ensure leadership understands and commits to compliance. Make exceptions explicit: "Limited personal use of email for brief messages is acceptable; extended personal projects are not." Apply policies consistently regardless of rank. No special treatment; if CEO violates policy, same consequences as anyone else (or document approved exception).

Challenge

Remote and hybrid workers claim rules designed for office don't apply to them at home.

Solution

Update policy to explicitly cover remote work: "These rules apply regardless of location—office, home, coffee shop, or airport." Address WFH-specific issues: connecting to public Wi-Fi (use VPN), family members using work laptops (forbidden), mixing personal and work devices (BYOD policy). Remote work doesn't mean relaxed security.

Challenge

Technical controls block legitimate work activities causing frustration and workarounds.

Solution

Balance security with productivity. Allow exception requests: create a form for "I need access to [blocked site/software] for [business reason]" with manager approval. Review blocked categories quarterly and adjust overly restrictive rules. Provide alternatives: block personal cloud storage but offer approved corporate file sharing (OneDrive, Google Drive).

Challenge

Shadow IT proliferates because AUP is too restrictive and approval processes are too slow.

Solution

Streamline software approval processes—target 48-hour turnaround for standard requests. Pre-approve common tools (Slack, Zoom, etc.) and publish approved list. Use cloud access security brokers (CASB) to discover shadow IT without blocking everything. Engage with departments to understand their needs rather than just saying "no."

Frequently Asked Questions

Can we allow limited personal use of company email and internet, or must we prohibit it entirely?
Limited personal use is acceptable and realistic for most organizations—total prohibition is unenforceable. Define "limited" clearly: "Brief personal emails during breaks are acceptable; forwarding chain letters, political campaigns, or conducting personal business is not." Specify monitoring so employees know personal use isn't private. Balance employee morale with security.
Do BYOD (Bring Your Own Device) policies need to be part of the Acceptable Use Policy?
Yes, or as a separate linked policy. BYOD needs specific rules: mandatory MDM enrollment, separation of work/personal data through containerization, no jailbreaking/rooting, remote wipe consent, acceptable apps, and what happens if the device is lost. Don't allow BYOD without clear documented rules—the risks are too high.
How do we handle social media use? Can employees mention the company on their personal accounts?
Create a social media policy (can be part of AUP or separate) addressing: (1) Personal accounts must not claim to represent the company officially. (2) Confidential information cannot be shared. (3) Employees are personally liable for their posts. (4) Company logos/trademarks require approval to use. Distinguish between personal expression and brand representation.
What if an employee violates AUP but claims it was an accident or they didn't understand the rule?
First offense for minor violations (clicking a phishing link, briefly browsing a blocked site) should be educational—provide retraining, not punishment. Intentional or severe violations (stealing data, installing malware, harassment) warrant immediate disciplinary action regardless of claimed ignorance. Document the incident, investigation, and outcome. Consistency is key.
Should contractors and vendors who access our systems be bound by our Acceptable Use Policy?
Absolutely. All third parties with system access must acknowledge your AUP or have equivalent provisions in their contracts. Create a "Third Party Access Agreement" incorporating AUP requirements. Provision separate contractor accounts with appropriate restrictions. Revoke access immediately when contracts end. Treat contractors with same rigor as employees for policy enforcement.
How often should we review and update the Acceptable Use Policy?
Review annually at minimum, or when: (1) Significant technology changes occur (new tools, cloud migration). (2) Policy violations reveal gaps. (3) Business model changes (remote work, BYOD adoption). (4) Regulatory changes (DPDPA, industry-specific rules). Document review dates and changes. Require re-acknowledgment after major updates. Keep policy current with how people actually work.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations