N.1.07 Acceptable use of information and related assets
Control Overview
This control mandates that the organization defines, distributes, and enforces clear guidelines regarding the safe and permissible use of corporate information and infrastructure—including laptops, mobile devices, storage media, and business applications. The objective is to mitigate insider risk, protecting the organization from security incidents stemming from user ignorance, carelessness, or a lack of clarity regarding secure operational boundaries. Compliance requires effective distribution of these rules, monitoring for violations, and continuous refinement to keep up with modern working standards.
Applicability Note: This control is fully applicable to the anDREa platform and governs the everyday operations of all internal staff and contractors.
Compliance & Strategic Approach
Our approach satisfies these requirements by tying acceptable use behavior directly to our ISO/IEC 27001-based ISMS, specifically targeting the realities of modern, distributed, and remote work environments.
Rather than implementing a standalone, rigid "Acceptable Use Policy" that employees sign and forget, anDREa embeds acceptable use requirements directly into contextual, operational workflows. Guidelines for interacting with systems are distributed across our Remote Working framework, Device Security standards, and explicit Data Handling rules. By making these guidelines a fundamental part of mandatory onboarding tracks and recurring security awareness sessions, we ensure behavioral compliance is continuously reinforced and audited.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | Equipment & Acceptable Use Agreement | Requires rules for the acceptable use of information and assets to be identified, documented, and implemented. |
| ISO/IEC 27001 | A.06.07 - Remote working | Establishes enforceable technical controls and rules for working off-site (e.g., VPN usage, local encryption, device locks). |
| ISO/IEC 27001 | A.05.12 - Classification of information A.05.13 - Labelling of information | Connects asset classification to real-world data handling rules, defining what data can be opened or stored on specific assets. |
| Internal Policy Document | A.06.07 - Remote working | Specifies explicit operational expectations for hardware handling, mandatory screen-locks, clean-desk standards, and secure connectivity. |
| Onboarding & Training | Training | Audit trail showing that all team members have completed training and formally acknowledged acceptable use boundaries. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None material. Forward-Looking Governance: Currently, infrastructure access is strictly managed. Should the organization introduce or expand Bring Your Own Device (BYOD) allowances in the future, those provisions must be formally codified within this specific control framework to avoid introducing operational gaps.