A.5.10 Organizational
Acceptable use of information and other associated assets
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-2partialaligns with — Both controls require maintaining an authoritative record of who is authorized to access specific information and associated assets.
- AC-8partialaligns with — Both controls ensure users receive a clear statement of expected conduct and monitoring before or during system interaction.
- MP-7partialaligns with — Both controls restrict how storage media and associated assets may be used throughout their lifecycle based on classification and risk.
- PS-6partialaligns with — Both controls establish binding agreements that define user responsibilities for protecting and properly handling organizational information assets.
- PL-4noneimplements — Both controls require an organization-defined set of rules that explicitly state permitted and prohibited behaviors for users handling organizational assets.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — By requiring the policy to define permitted and prohibited uses of assets and to enforce access restrictions aligned with classification, the ISO control supports the CSF outcome of defining, managing, and enforcing access permissions and authorizations.
- PR.AT-01mostlyaligns with — The ISO control mandates that personnel and external users be made aware of information-security requirements and their responsibilities for protecting assets, fulfilling the CSF outcome of providing awareness and training so personnel can perform tasks securely.
- GV.PO-02partialaligns with — The ISO control requires the acceptable-use policy to be communicated and enforced, which aligns with the CSF outcome of reviewing, updating, communicating, and enforcing policy to reflect changing requirements.
- ID.AM-05partialaligns with — The ISO control ties acceptable-use procedures to asset classification and risk, thereby supporting the CSF outcome of prioritizing assets based on classification, criticality, and mission impact.
- GV.PO-01noneimplements — The ISO control requires creation and communication of a topic-specific acceptable-use policy that defines expected behaviors and permitted uses, directly satisfying the CSF outcome of establishing policy for managing cybersecurity risks based on organizational context and priorities.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — Clear rules on handling copies, storage, and disposal of classified information lower the likelihood that sensitive data will be left accessible to unauthorized actors.
- CWE-522partialprevents — Acceptable-use expectations that cover protection of credentials and information assets throughout their lifecycle discourage practices that expose or mishandle authentication material.
- CWE-284nonemitigates — By defining and communicating explicit permitted versus prohibited uses of information assets, the control reduces the chance that users will exercise access rights outside intended boundaries.
- CWE-732nonenone — Requiring classification-based access restrictions and authorized-user records helps ensure that default or overly broad permissions are not left in place for sensitive resources.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Acceptable-use restrictions on copying or exfiltrating data from local systems make it harder for an adversary to collect and remove sensitive information without violating policy.
- T1078partialmitigates — Clear rules on permitted versus prohibited account usage and monitoring reduce the likelihood that an adversary can operate undetected with stolen or misused valid credentials.
- T1025nonemitigates — Policy statements that restrict removable-media handling reduce the chance an attacker can use USB or other external devices to gather data covertly.
- T1059nonemitigates — Explicit prohibitions on unauthorized scripting or command execution limit an attacker’s ability to leverage interpreters on organization assets without detection.
- T1565nonemitigates — Defined responsibilities and monitoring expectations deter unauthorized modification of stored or transmitted data by making such actions a clear policy violation.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — By defining and communicating explicit rules for permitted versus prohibited use of information assets, the control reduces the chance that users will configure or operate systems in ways that deviate from secure defaults.
- A01nonemitigates — Clear statements of expected versus unacceptable behaviours and access restrictions tied to information classification help limit the likelihood that users will exceed their authorized privileges.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.