---
title: "ISO 27001: 2022 A.5.10 Acceptable use of information and other associated asset"
description: This article provides additional information on how you can meet the requirement for the A.5.10 Acceptable use of information and other associated asset
---

[Skip to content](https://knowledge.adoptech.co.uk/iso-27001-5.10-acceptable-use-of-information-and-other-associated-asset#main-content)

[![Adoptech-logo-GreyWithoutStrapline-1.png\]](https://knowledge.adoptech.co.uk/hs-fs/hubfs/Adoptech-logo-GreyWithoutStrapline-1.png?height=39&name=Adoptech-logo-GreyWithoutStrapline-1.png)](https://knowledge.adoptech.co.uk/?hsLang=en)

Open main navigation

Close main navigation

 Adoptech Help Centre

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.adoptech.co.uk/?hsLang=en)
2. [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en)
3. [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)

# ISO 27001: 2022 A.5.10 Acceptable use of information and other associated asset

## This article provides additional information on how you can meet the requirement for the A.5.10 Acceptable use of information and other associated asset

### **ISO 27001: 2022 Control Description**

Rules for the acceptable use and procedures for handling information and other associated assets should be identified, documented, and implemented.

### Purpose

To ensure information and other associated assets are appropriately protected, used, and handled.

### **Guidance on implementation**

Personnel and external party users using or having access to the organisation’s information and other associated assets should be made aware of the information security requirements for protecting and handling the organisation’s information and other associated assets. They should be responsible for their use of any information processing facilities.

The organisation should establish a topic-specific policy on the acceptable use of information and other associated assets and communicate it to anyone who uses or handles information and other associated assets. The topic-specific policy on acceptable use should provide clear direction on how individuals are expected to use information and other associated assets. The topic-specific policy should state:

a) Expected and unacceptable behaviours of individuals from an information security perspective;

b) Permitted and prohibited use of information and other associated assets;

c) Monitoring activities being performed by the organisation.

Acceptable use procedures should be drawn up for the full information life cycle in accordance with its classification (see A.5.12) and determined risks. The following items should be considered:

a) Access restrictions supporting the protection requirements for each level of classification;

b) Maintenance of a record of the authorised users of information and other associated assets;

c) Protection of temporary or permanent copies of information to a level consistent with the protection of the original information;

d) Storage of assets associated with information in accordance with manufacturers’ specifications (see A.7.8);

e) Clear marking of all copies of storage media (electronic or physical) for the attention of the authorised recipient (see A.7.10);

f) Authorisation of disposal of information and other associated assets and supported deletion method(s) (see A.8.10).

It may be the case that the assets concerned do not directly belong to the organisation, such as public cloud services. The use of such third-party assets and any assets of the organisation associated with such external assets (e.g., information, software) should be identified as applicable and controlled.

- [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#main-content)

    - [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#getting-started)
    - [Accounts & Billing](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#accounts-billing)
- [FAQ's on Adoptech](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#main-content)

    - [Frameworks](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#frameworks)
    - [Policies & Documents](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#policies-documents)
    - [Risk Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#risk-management)
    - [Supplier Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#supplier-management)
    - [Audit Preparation](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#audit-preparation)
    - [Trust Centre](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#trust-centre)
    - [User Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#user-management)
- [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#main-content)

    - [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)
    - [ISO 42001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-42001)
    - [Cyber Essentials](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#cyber-essentials)
    - [CAF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#caf)
    - [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)
    - [SOC2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#soc2)
    - [Data Privacy (GDPR)](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#data-privacy-gdpr)
    - [DORA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#dora)
    - [ISO 9001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-9001)
    - [ISO 22301](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-22301)
    - [ISO 14001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-14001)
    - [NIST 800-53](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-800-53)
    - [NIST-CSF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-csf)
    - [NIS2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nis2)
    - [ISO 20000-1](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-20000-1)
    - [HIPAA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#hipaa)
- [Integrations](https://knowledge.adoptech.co.uk/integrations?hsLang=en#main-content)

    - [Cloud Infrastructure](https://knowledge.adoptech.co.uk/integrations?hsLang=en#cloud-infrastructure)
    - [Identity & Access](https://knowledge.adoptech.co.uk/integrations?hsLang=en#identity-access)
    - [DevOps & Code](https://knowledge.adoptech.co.uk/integrations?hsLang=en#devops-code)
    - [Project Management](https://knowledge.adoptech.co.uk/integrations?hsLang=en#project-management)
    - [HR & People Systems](https://knowledge.adoptech.co.uk/integrations?hsLang=en#hr-people-systems)
    - [Security & Devices](https://knowledge.adoptech.co.uk/integrations?hsLang=en#security-devices)
    - [Communication & Collaboration](https://knowledge.adoptech.co.uk/integrations?hsLang=en#communication-collaboration)
- [Legal & Regulations](https://knowledge.adoptech.co.uk/legal-regulations?hsLang=en)
- [Security Guidance](https://knowledge.adoptech.co.uk/security-guidance?hsLang=en)
- [Troubleshooting](https://knowledge.adoptech.co.uk/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.adoptech.co.uk/hs-fs/hubfs/adoptech-logo-1.png?width=209&height=54&name=adoptech-logo-1.png "Chill listening crop-3")](https://adoptech.co.uk/)

<https://uk.linkedin.com/company/adoptech>

Copyright © 2026, Adoptech Ltd.