Skip to content

Acceptable Use

What is Acceptable Use?

The agreed-upon rules governing how users may utilize an organization's IT resources, including internet, email, and software.

Governance

Each of these is named in at least one of the same controls as acceptable use. The number is how many controls name both.

What the standards actually require on acceptable use

Requirements naming acceptable use across 6 standards, quoted from the control text.

PCI DSS 4.03 controls

Security awareness training includes acceptable use of end-user technologies in accordance with the entity's policies.

12.6.3.2 · Training on acceptable use of end-user technologies
C5 (Germany)2 controls

Document, communicate and issue acceptable use and safe handling instructions spanning approval for acquisition through disposal, classification and labelling, secure configuration, software versions and patching, unsupported software, installation restriction...

C5-AM-02 · Acceptable Use and Safe Handling of Assets Policy

Set up acceptable use policies that outline the boundaries for interacting with AI systems.

AIGE-SI-4 · Acceptable use policies

Define in policy what use of organisation-owned or managed assets is acceptable and under what conditions, and review that policy at least annually.

CCM-HRS-02 · Acceptable Use of Technology Policy and Procedures

Requires rules for acceptable use, and procedures for handling information and its associated assets, to be identified, documented and put into effect.

iso-27002-2022::5.10 · Acceptable use of information and other associated assets
ISO 270431 control

Acceptable use of assets. Control from ISO 27043 framework, domain: ISO 27043: Asset Management.

ISO27043-07 · Acceptable use of assets

Questions people ask about acceptable use

What is Acceptable Use?
The agreed-upon rules governing how users may utilize an organization's IT resources, including internet, email, and software.
Why is Acceptable Use important for compliance?
Acceptable Use is a key concept in Governance. Understanding acceptable use helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Acceptable Use?
Acceptable Use appears in the requirement text of PCI DSS 4.0, C5 (Germany), ASEAN Guide on AI Governance and Ethics, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, ISO 27002:2022. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Acceptable Use?
Explore our compliance framework pages to see how acceptable use applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Acceptable Use applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.