A.5.10
    Organizational Controls

    Acceptable use of information and other associated assets

    Rules for the acceptable use of information and of assets associated with information and information processing facilities should be identified, documented and implemented.

    Purpose

    To ensure that information and assets are used in accordance with organizational policies and legal requirements.

    Implementation Guidance

    Define acceptable use policies for all organizational assets

    Cover email, internet, social media, mobile devices, and remote access

    Specify prohibited activities and consequences of policy violations

    Require users to acknowledge acceptable use policies

    Monitor compliance with acceptable use policies

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.10 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.10 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.10 Acceptable use of information and other associated assets. Built for compliance professionals.

    Try ISMS Copilot free