Compliance Can’t Live in One Person’s Head
Most organisations have rules about how staff should use systems and information…somewhere…they think (hope?!).
Maybe in an acceptable use policy. Maybe in an employee handbook. Maybe in a PDF saved in the onboarding folder that nobody has opened since the logo was updated three years ago.
The problem is not usually that rules do not exist. The problem is that people don’t understand them, which means they cannot possibly remember them, and so continue working as if they don’t exist. Because, practically speaking, they don’t actually exist.
This is where ISO 27001 Control 5.10: Acceptable Use of Information and Other Associated Assets applies.
This control is about making sure people understand how they are expected to use information, systems, devices, applications and other associated assets. Contrary to popular opinion, Control 5.10 does not exist to make everyone’s working day harder. It is there to make sure information is handled consistently, safely and in line with the organisation’s risk appetite.
Control 5.10 ensures that people know what they can and cannot do with company information and systems.
And no, “use common sense” is not a control.
What Control 5.10 is Really Asking
Control 5.10 is about defining, documenting and applying rules for the acceptable use of information and associated assets.
That sounds fairly simple until you think about how people actually work.
Staff use laptops, mobile phones, cloud storage, shared drives, messaging tools, AI assistants, customer platforms, finance systems, personal devices, removable media, collaboration apps and supplier portals. Information moves between teams, systems, customers and third parties all day.
A good acceptable use approach should explain how these things can be used safely. It should cover what is allowed, what is restricted, what needs approval and what is completely off limits.
This may include rules for:
- using company devices
- storing and sharing business information
- accessing systems remotely
- using personal devices for work
- handling confidential or sensitive data
- using cloud services and SaaS applications
- using AI tools
- copying, downloading or transferring files
- connecting removable media
- using email, messaging and collaboration platforms
- reporting misuse or accidental exposure
The aim is not to write a 40-page policy that terrifies everyone into doing nothing. The aim is to create clear, usable guardrails.
People should not need a law degree to understand whether they can upload a customer document to a tool, save files to a personal drive, use an AI note-taker in a meeting, or send work data to a private email address.
Why It Matters
Acceptable use is one of those controls that looks basic until something goes wrong.
A staff member uploads confidential customer data to an unapproved AI tool. A contractor saves project files to a personal cloud account. A team starts using a free SaaS platform because it is quicker than waiting for approval. Someone forwards documents to a private email address so they can work from home. A USB stick appears because, apparently, it’s still 2008.
None of this necessarily starts with bad intent. Most of the time, people are trying to get their work done.
If the rules are unclear, outdated or buried in policy sludge, staff will make their own decisions. Some of those decisions will be sensible. Others will create confidentiality, integrity or availability risks the organisation did not intend to accept.
Control 5.10 helps reduce the gap between what the organisation thinks is happening and what is actually happening.
It also supports other parts of the ISMS. Access control, data leakage prevention, supplier management, asset management, incident response, remote working and information classification all depend on people using information and assets properly.
Acceptable use is not a standalone HR policy. It is part of how the organisation protects information every day.
Where Organisations Usually Get This Wrong
The most common mistake is treating acceptable use as an onboarding document. A new employee joins. They sign the policy. The policy disappears into the HR system. Five years later, they are using tools, data and workflows that did not exist when they signed it. This means there is no meaningful acceptance.
Other common issues include:
- policies that are too generic to guide real decisions
- rules that do not mention modern tools, including AI and SaaS platforms
- no link between acceptable use and data classification
- staff signing policies without understanding them
- rules that are not reinforced through training or reminders
- no process for approving exceptions
- unclear consequences for misuse
- no evidence that acceptable use requirements are reviewed or maintained
AI has made this more visible. It’s no longer enough to tell staff not to share “sensitive information” if nobody has explained what that means in the context of prompts, meeting transcripts, customer tickets, contracts, code, board papers or internal reports.
Acceptable use needs to be practical enough to help people make good decisions in the moment.
What Good Looks Like
A strong acceptable use process is clear, current and connected to the way people actually work.
Good organisations usually have rules that are easy to find and easy to understand. The policy explains what staff can do, what they cannot do and when they need approval. It uses examples that match the business, rather than vague statements copied from a template.
They also connect acceptable use to information classification. If information is confidential, restricted or customer-sensitive, staff should know what that means for storage, sharing, transfer and use in external tools.
Ownership is clear. Someone is responsible for keeping the rules current as technology, suppliers and working practices change. That matters because acceptable use requirements can go stale quickly.
Training is practical. Staff are not just told that information security is important. They are shown what risky behaviour looks like in their own work environment. The difference is enormous.
Exceptions are managed. There will always be cases where someone needs to use a tool, device or workflow that falls outside the usual rules. Mature organisations do not pretend this never happens. They assess the risk, approve it where appropriate and document the decision.
And lastly, there is evidence. The organisation can show the policy, acceptance records, training activity, review history, approved exceptions, incidents, corrective actions and links to related controls. Because we’ve never seen an auditor take, “we told people once 13 years ago” as an acceptable answer.
The AI Angle
AI has made acceptable use far more important than it used to be. People can now process, summarise, rewrite, analyse and transform information through tools that feel harmless because they sit behind a simple text box. That makes data sharing less obvious.
A prompt can contain customer information. A meeting recording can include confidential discussions. A document summary can expose commercial details. A code assistant can touch intellectual property.
Acceptable use rules need to explain what staff can do with AI tools, what data is prohibited, which tools are approved, what outputs need review and who to ask when the situation is unclear. We don’t suggest implementing a ban on everything; blanket bans usually just drive behaviour underground. Instead, we suggest giving your team clear boundaries that reflect the real risks they’re encountering every day.
How de.iterate Helps
At de.iterate, we help organisations turn acceptable use from a signed policy into an operating control. Our platform supports you to:
- maintain acceptable use policies and related procedures
- link acceptable use requirements to assets, data, suppliers, risks and controls
- assign ownership for policy review and control activities
- schedule recurring reviews through assurance tasks
- capture evidence of staff acknowledgement and training
- track exceptions, incidents and corrective actions
- demonstrate to auditors that acceptable use is current and embedded
Instead of acceptable use living in an old policy folder, it becomes part of your management system. As a result, doing the right thing becomes clear, easy and repeatable.
Book a demo to see how de.iterate can help.
Tags: