In this guide you will learn how to implement ISO 27001 Annex A 5.10 Acceptable Use and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.10 is an ISO 27001 control that requires an organisation to implement rules and procedures for the acceptable use of information and other assets.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.10 Training Video
- ISO 27001 Annex A 5.10 Requirements and Guidance
- How to implement ISO 27001 Annex A 5.10
- 1. Formalise the Acceptable Use Policy (AUP)
- 2. Define Asset Classifications and Handling Rules
- 3. Map Rules to the Centralised Asset Register
- 4. Provision Identity and Access Management (IAM) Roles
- 5. Enforce Multi-Factor Authentication (MFA) for Asset Access
- 6. Implement Technical Controls and Monitoring
- 7. Execute Formal Policy Acknowledgment
- 8. Deliver Role-Based Security Awareness Training
- 9. Establish Procedures for the Return of Assets (ROE)
- 10. Audit Asset Usage and Policy Compliance
- How to comply
- How to pass the ISO 27001 Annex A 5.10 audit
- What will an audit check?
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.10 FAQ
- ISO 27001 Controls and Attribute Values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.10 is a preventive control that ensures information and other associated assets are appropriately protected, used and handled.
The ISO 27001 standard defines ISO 27001 Annex A 5.10 as:
Rules for the acceptable use and procedures for handling information and other associated assets should be identified, documented and implemented.
ISO 27001:2022 Annex A 5.10 Acceptable use of information and other associated assets
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.10 Training Video
In this free training video you will learn How to implement ISO 27001 Acceptable Use (Annex A 5.10) and Pass Your Audit.
ISO 27001 Annex A 5.10 Requirements and Guidance
To implement ISO 27001 Annex A 5.10 Acceptable Use Of Information And Other Associated Assets you are going to have to ensure that
- Personnel, contractors and third party users are made aware of the information security requirements for protecting and handling assets and information
- People are responsible for their use of company assets
- There is a topic specific policy on acceptable use
- Acceptable use procedures are documented, communicated and in place
What should an acceptable use policy cover?
The Acceptable Use Policy should cover the following topics
- Expected behaviour for information security
- Unacceptable behaviour for information security
- What monitoring the organisation is doing
What acceptable use processes do I need?
You are going to have acceptable use processes for the full information security lifecycle based on its classification and identified risks. What this means is you will consider
- Access restrictions that are based on classification
- Having a record of authorised users of information and systems
- Protecting information that has been copied to the same level as the original
- Following manufacturers specifications when storing information
- Marking storage media for the attention of the recipient
- Processes for disposing information and other assets including deletion methods and authorisation
Acceptable Use and Cloud Services
So what about assets that do not belong to the organisation? Cloud based assets for example. Well you need to identify those as well and record them as applicable and controlled. You are going to ensure there are agreements are in place and those agreements provide the required controls.
ISO 27001 Acceptable Use Template
The ISO 27001 acceptable use policy template is pre written and ready to go.

How to implement ISO 27001 Annex A 5.10
Implementing ISO 27001 Annex A 5.10 is about more than just a policy document; it is about ensuring every user understands their responsibilities when handling organisational assets. By following this 10-step implementation framework, you will create a culture of accountability and significantly reduce the risk of accidental data breaches or malicious insiders. As a Lead Auditor, I look for clear evidence that these rules are communicated, enforced, and technically supported across the entire information estate.
1. Formalise the Acceptable Use Policy (AUP)
- Draft a comprehensive Acceptable Use Policy that defines permitted and prohibited activities for all information assets.
- Ensure the policy covers hardware, software, network resources, and cloud-based services.
- Result: A legally sound and clear set of expectations that forms the foundation of your asset security governance.
2. Define Asset Classifications and Handling Rules
- Link the AUP to your Information Classification Policy to specify how “Confidential” or “Restricted” assets must be used.
- Identify specific restrictions for mobile devices, removable media, and personal equipment (BYOD).
- Result: Context-specific rules that protect assets based on their sensitivity and value to the organisation.
3. Map Rules to the Centralised Asset Register
- Cross-reference acceptable use requirements with individual entries in your Asset Register.
- Ensure that every asset category identified in Annex A 5.9 has a corresponding set of usage rules.
- Result: A structured approach ensuring no technical or information asset is left without oversight.
4. Provision Identity and Access Management (IAM) Roles
- Configure IAM roles to enforce acceptable use by restricting access to only those assets required for a specific job function.
- Utilise the principle of least privilege to ensure users cannot access prohibited resources.
- Result: Technical enforcement of policy by preventing unauthorised asset interactions at the infrastructure level.
5. Enforce Multi-Factor Authentication (MFA) for Asset Access
- Mandate MFA for all users accessing critical business systems or sensitive data repositories.
- Integrate MFA prompts into the login workflow for remote access and administrative accounts.
- Result: Verification of user identity before allowing asset use, mitigating the risk of credential theft.
6. Implement Technical Controls and Monitoring
- Deploy Endpoint Detection and Response (EDR) or Data Loss Prevention (DLP) tools to monitor for policy violations.
- Configure web filters and application whitelisting to prevent the use of unauthorised software or sites.
- Result: Real-time visibility into asset usage and automated prevention of high-risk activities.
7. Execute Formal Policy Acknowledgment
- Require all employees, contractors, and third-party users to sign the AUP during onboarding.
- Maintain a digital audit trail of acknowledgments within your HR system or GRC tool.
- Result: Defensible evidence of user commitment to follow security rules, essential for HR disciplinary processes.
8. Deliver Role-Based Security Awareness Training
- Conduct regular training sessions that explain the practical application of acceptable use in daily tasks.
- Use real-world examples of security risks, such as phishing or shadow IT, to illustrate the importance of compliance.
- Result: A well-informed workforce that understands why rules exist and how to protect assets effectively.
9. Establish Procedures for the Return of Assets (ROE)
- Update the Record of Equipment (ROE) documents to include specific return protocols during offboarding.
- Verify that all hardware, software licenses, and access tokens are recovered when a user’s contract ends.
- Result: Prevention of “asset sprawl” and ensuring that former users no longer have physical or logical access.
10. Audit Asset Usage and Policy Compliance
- Schedule periodic audits of system logs and access reports to verify that assets are being used as intended.
- Review policy effectiveness annually or following significant changes to the technical environment.
- Result: Continuous improvement of security posture and readiness for formal ISO 27001 certification audits.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
How to comply
To comply with ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to:
- Implement a topic specific Acceptable Use Policy
- Implement Acceptable Use Procedures
- Communicate and gain acceptance of the Acceptable Use Policy
How to pass the ISO 27001 Annex A 5.10 audit
To pass an audit of ISO 27001 Annex A 5.10 Acceptable use of information and other associated assets you are going to make sure that you have followed the steps above in how to comply.
What will an audit check?
The audit is going to check a number of areas. Lets go through the main ones
1. That you have an Acceptable Use Policy
What this means is that you need to show that you have an acceptable use policy in place, that it has been approved and signed off.
2. That your Acceptable Use Policy has been communicated and accepted
You need to communicate the Acceptable Use Policy to all staff and get them to accept it. There are many ways to record acceptance of policy from getting email confirmation, an actual signature or using a training tool to distribute and seek understanding and acceptance.
3. That you have covered the entire information lifecycle
Acceptable use covers the entire information lifecycle. It is unlikely that the acceptable use policy will cover everything that is required and it would not make sense for it to do so. Rather you will have a suite of topic specific policies that are complimentary covering things such as logging and monitoring, access control.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.10 are
1. Your haven’t got acceptance from people of the policy
As well as having the policy you need to communicate it and get people to accept it. Often people think is enough just to ‘have’ a policy. It is not.
2. You forgot the bits that were not obvious
Acceptable use is part of many of the policies that you will have as you are communicating to people what is expected of them. Having a complete set of policies that cover the entire information lifecycle is important. Considering access control, information destruction, handling, information transfer and more.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.10 FAQ
Yes, a documented Acceptable Use Policy is considered a mandatory piece of evidence to satisfy the requirements of Annex A 5.10 during a certification audit.
Provides verifiable proof that users have been informed of their responsibilities.
Supports compliance with Clause 7.3 (Awareness) and Annex A 5.4 (Disciplinary process).
Sets the legal groundwork for monitoring and enforcement activities.
Acts as a primary reference for auditors to gauge the maturity of your ISMS.
A comprehensive AUP must define permitted and prohibited behaviours regarding the use of organisational networks, devices, and data.
Rules for internet and email usage (e.g., prohibiting illegal content).
Guidelines for social media and external communications.
Restrictions on unauthorised software installation or hardware modification.
Requirements for password hygiene and screen locking.
Clear definitions of what constitutes “incidental” personal use.
Yes, the control applies to any asset used to access organisational information, regardless of whether it is company-owned or a personal device.
Must define security requirements for accessing the corporate network via VPN.
Requires clear rules on data segregation between personal and business use.
Should mandate the use of anti-malware and encryption on personal devices (BYOD).
States the organisation’s right to wipe corporate data from personal hardware upon termination.
Organisations should review their AUP at least annually or whenever significant technical or organisational changes occur.
Triggers for review include the adoption of new technologies like Generative AI.
Must be updated following a major security incident involving asset misuse.
Ensures alignment with changing legal, regulatory, or contractual requirements.
Helps maintain relevance as working patterns (like hybrid work) evolve.
Violations of the AUP should trigger formalised disciplinary procedures as defined in your organisational HR policies and Annex A 5.4.
May result in the immediate revocation of access to corporate systems.
Can lead to formal warnings, suspension, or termination of employment.
Might involve legal action if the misuse involves data breaches or criminal activity.
Acts as a deterrent to other employees by demonstrating enforcement of security rules.
ISO 27001 Controls and Attribute Values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Protect | Asset management | Protection |
| Integrity | ||||
| Availability |
Stuart Barker
I am the ISO 27001 Ninja.
I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.
If you want to pass your audit the first time, book a call.

