ISO 27002:2022 5.10: Acceptable use of information and other associated assets
Rules on how information and other associated assets may acceptably be used, together with procedures for handling them, are to be identified, written down and put into practice. Purpose: see that information and associated assets are used, handled and protected properly. Guidance: staff and external users with access should be told what security the organization expects when they use or handle its information and assets and are answerable for their own use of processing facilities. A topic-specific acceptable use policy, communicated to everyone who uses or handles the assets, should set out the behaviour expected and not tolerated, what uses are allowed and forbidden, and what monitoring the organization carries out. Handling procedures cover the whole information life cycle according to classification (5.12) and assessed risk, considering: access restrictions for each classification level; a record of authorized users; protection of temporary and permanent copies equal to the original; storing assets as their manufacturers specify (7.8); marking each copy of electronic or paper media clearly for whoever is authorized to receive it (7.10); and authorization of disposal together with the approved deletion methods (8.10). Other information: where assets belong to someone else, such as public cloud services, their use and the organization's related assets should be identified and controlled, for instance through agreements with the provider, and collaborative working environments need care.
This control maps to 75 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.