HRS-011 Acceptable Use of Information Assets
Description
Rules for the acceptable use of organisational information, systems and other assets are documented, carry a review date within the defined interval and are acknowledged by each person before access is granted, with re-acknowledgement when the rules change. The rules name the prohibited activities, the limits on personal use, the obligations to protect organisational information and the clear desk and clear screen rules for workspaces and information processing facilities. They also govern the use of social media, external sites and applications, covering the posting of organisational information on public sites and the use of organisational email addresses and authentication secrets to open accounts elsewhere. The rules state the conditions under which organisational information may be accessed, processed, stored or transmitted on a system the organisation does not control. Each such use is covered either by a recorded verification that the external system implements the required controls or by an approved connection or processing agreement. An acknowledgement record exists for every person holding access.
Rationale
Nobody can be held to a rule they were never shown, so the acknowledgement before access is what makes the rest enforceable, in a disciplinary process and in a legal one. The clauses added when this control moved to HRS are the ones that follow the work rather than the device: a personal laptop, a home desk, a social media account opened with a work email address. The external systems clause decides whether contractor and bring-your-own-device working is governed or merely tolerated. It needs either a verification of the other system's controls or an agreement with whoever runs it. Issued in S4 when GOV-025 was re-homed to HRS (CQ-072, ADR-007, ADR-033). HRS-003 carries the same obligations into the employment contract, HRS-006 the disciplinary process for a breach and IAM-011 the technical controls on remote access.
Applicability (9 profiles)
164.310(b) adds a limb HRS-011 does not carry: the physical attributes of the surroundings of a specific workstation or class of workstation. That is a siting requirement per class, and it is what governs a home desk facing a shared room.
Framework Mappings (21)
| HRS-02 | Acceptable Use of Technology Policy and Procedures | full |
| HRS-03 | Clean Desk Policy and Procedures | full |
| HRS-13 | Compliance User Responsibility | partial |
| HRS-15 | AI Acceptable Use | informative |
| HRS-02 | Acceptable Use of Technology Policy and Procedures | full |
| HRS-03 | Clean Desk Policy and Procedures | full |
| HRS-13 | Compliance User Responsibility | partial |
| HIPAA-164.310.b | Workstation Use | partial |
| 5.10 | Acceptable use of information and other associated assets | full |
| 7.7 | Clear desk and clear screen | full |
| NIS2-Art.21.2.g | Basic Cyber Hygiene Practices and Cybersecurity Training | informative |
| NIS2-CIR-12.2 | Handling of Assets | partial |
| NIS2-CIR-8.1 | Awareness Raising and Basic Cyber Hygiene Practices | informative |
| AC-20 | Use of External Systems | full |
| AC-20(1) | Use of External Systems | Limits on Authorized Use | full |
| AC-22 | Publicly Accessible Content | partial |
| PL-4 | Rules of Behavior | full |
| PL-4(1) | Rules of Behavior | Social Media and External Site/Application Usage Restrictions | full |
| SC-43 | Usage Restrictions | partial |
| GV-6.1-010 | Third-Party AI Risk Policies | GV-6.1-010 | informative |
| CC1.1 | COSO Principle 1: Demonstrates Commitment to Integrity and Ethical Values | informative |
Evidence (2)
Acceptable use rules defining permitted and prohibited use of organisational information assets, covering personal use limits, clear desk and clear screen, use of social media and external sites and the conditions for using a system the organisation does not control.
Example: Acceptable Use Policy v4.1 (policy management system, approved 2026-02-10), covering permitted use of devices, networks, cloud services and data; prohibited activities; personal use limits; social media and public posting rules; clear desk and clear screen rules; and the conditions for processing organisational information on personally owned or contractor-managed systems
Test: Request the acceptable use rules. Verify: (1) prohibited activities are listed explicitly, (2) personal use limits are stated, (3) obligations to protect organisational information are stated, (4) rules for social media, external sites and applications are stated, covering the posting of organisational information publicly and the use of organisational email addresses and authentication secrets to open accounts elsewhere, (5) clear desk and clear screen rules are stated for workspaces and information processing facilities, (6) the conditions for accessing or processing organisational information on a system the organisation does not control are stated, together with the requirement for a recorded verification of that system's controls or an approved connection or processing agreement, (7) the rules carry a management approval and a review date within the defined interval, (8) distribution to personnel is evidenced.
Signed acknowledgement records confirming all personnel have read and accepted the acceptable use policy before receiving system access.
Example: AUP acknowledgement export from the HRIS or training platform (BambooHR, Workday, KnowBe4, or equivalent), showing name, email, and acknowledgement date for each current employee, with 100% or near-100% completion.
Test: Export the acknowledgement records from the human resources or training system and reconcile them against the list of people holding access. Verify: (1) every person holding access has a recorded acknowledgement, (2) the acknowledgement pre-dates the grant of access for people who joined in the period, (3) a re-acknowledgement is recorded against the current version of the rules for people who acknowledged an earlier version, (4) anyone without an acknowledgement has an open remediation action.
Questions (3)
Are the acceptable use rules acknowledged by each person before access to organisational systems is granted?
The acknowledgement before access is what makes the rules enforceable later. Rules published on an intranet with no record of who has read them do not meet the control; Q2 captures how the acknowledgement is recorded.
How is acknowledgement of the acceptable use policy captured and tracked for all personnel?
A digital acknowledgement export showing 100% (or near-100%) completion for all active staff, with acknowledgement dates, is the standard evidence.
Which of the following does your acceptable use policy address?
The last five items are the ones most often missing from a policy written for a single office and a managed laptop. The external systems item is the one that governs contractor and bring-your-own-device working; the control also asks for a recorded verification of that system's controls or an approved connection or processing agreement for each such use.