ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.10: Acceptable use of information and other associated assets

Rules on how information and other associated assets may acceptably be used, together with procedures for handling them, are to be identified, written down and put into practice. Purpose: see that information and associated assets are used, handled and protected properly. Guidance: staff and external users with access should be told what security the organization expects when they use or handle its information and assets and are answerable for their own use of processing facilities. A topic-specific acceptable use policy, communicated to everyone who uses or handles the assets, should set out the behaviour expected and not tolerated, what uses are allowed and forbidden, and what monitoring the organization carries out. Handling procedures cover the whole information life cycle according to classification (5.12) and assessed risk, considering: access restrictions for each classification level; a record of authorized users; protection of temporary and permanent copies equal to the original; storing assets as their manufacturers specify (7.8); marking each copy of electronic or paper media clearly for whoever is authorized to receive it (7.10); and authorization of disposal together with the approved deletion methods (8.10). Other information: where assets belong to someone else, such as public cloud services, their use and the organization's related assets should be identified and controlled, for instance through agreements with the provider, and collaborative working environments need care.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 75 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 8 controls

  • AC-22 Publicly Accessible Content
  • AC-8 System Use Notification
  • CM-10 Software Usage Restrictions
  • CM-7(2) Prevent Program Execution
  • MP-7 Media Use
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • SC-18 Mobile Code

FedRAMP Moderate · 8 controls

  • AC-22 Publicly Accessible Content
  • AC-8 System Use Notification
  • CM-10 Software Usage Restrictions
  • CM-7(2) Prevent Program Execution
  • MP-7 Media Use
  • PL-4 Rules of Behavior
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))
  • SC-18 Mobile Code

NIST SP 800-53 Rev 5 · 8 controls

ISO/IEC 42001:2023 · 4 controls

  • 7.5.1 General
  • A.9 Use of AI systems
  • A.9.2 Processes for responsible use of AI systems
  • A.9.4 Intended use of the AI system
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 12.6.3.2 12.6.3.2 Awareness training covers acceptable use of end-user technologies
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • ISM-1359 Removable media usage policy
  • ISM-1864 System usage policy
  • ISM-1865 Agreement to system usage policies before access

CMMC 2.0 · 3 controls

ISO 27701:2019 · 3 controls

  • 6.2.1 Management direction for information security
  • 6.4.2 During employment
  • 6.6.3 User responsibilities
  • 0062 0062 Apply the minimum protections and handling requirements
  • 0063 0063 Apply the Security Caveat Standard and controlling authority requirements
  • 0066 0066 Handle accountable material per originator and caveat owner requirements

SOC 2 · 3 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC2.2 CC2.2 Internal communication of objectives and control responsibilities (COSO principle 14)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • AM-2 Use only approved services
  • ASBv3-AM-5 Use only approved applications in virtual machine

C5 (Germany) · 2 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets

CIS Controls v8 · 2 controls

  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-3.1 Establish and Maintain a Data Management Process

MTCS (Singapore) · 2 controls

  • 10.4 Prevention of misuse of cloud facilities
  • 6.9 Acceptable usage

NIST SP 800-171 Rev 3 · 2 controls

  • 16 s 16 Data surveillance: policy on computer resource use, logging, access and auditing, notified in advance
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice
  • AUCDR-IS-6 Information security training and awareness program
  • CCM-HRS-02 Acceptable Use of Technology Policy and Procedures

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor
  • s87-1-1 s 87(1) no. 1 Co-determine rules on order in the establishment and employee conduct

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.10 Acceptable use of information and other associated assets
  • s12 s 12 Computer surveillance: written policy notified in advance

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.