GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-011 Acceptable Use of Information Assets

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Rules for the acceptable use of organisational information, systems and other assets are documented, carry a review date within the defined interval and are acknowledged by each person before access is granted, with re-acknowledgement when the rules change. The rules name the prohibited activities, the limits on personal use, the obligations to protect organisational information and the clear desk and clear screen rules for workspaces and information processing facilities. They also govern the use of social media, external sites and applications, covering the posting of organisational information on public sites and the use of organisational email addresses and authentication secrets to open accounts elsewhere. The rules state the conditions under which organisational information may be accessed, processed, stored or transmitted on a system the organisation does not control. Each such use is covered either by a recorded verification that the external system implements the required controls or by an approved connection or processing agreement. An acknowledgement record exists for every person holding access.

Rationale

Nobody can be held to a rule they were never shown, so the acknowledgement before access is what makes the rest enforceable, in a disciplinary process and in a legal one. The clauses added when this control moved to HRS are the ones that follow the work rather than the device: a personal laptop, a home desk, a social media account opened with a work email address. The external systems clause decides whether contractor and bring-your-own-device working is governed or merely tolerated. It needs either a verification of the other system's controls or an agreement with whoever runs it. Issued in S4 when GOV-025 was re-homed to HRS (CQ-072, ADR-007, ADR-033). HRS-003 carries the same obligations into the employment contract, HRS-006 the disciplinary process for a breach and IAM-011 the technical controls on remote access.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.310(b) adds a limb HRS-011 does not carry: the physical attributes of the surroundings of a specific workstation or class of workstation. That is a siting requirement per class, and it is what governs a home desk facing a shared room.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (21)

HRS-02Acceptable Use of Technology Policy and Proceduresfull
HRS-03Clean Desk Policy and Proceduresfull
HRS-13Compliance User Responsibilitypartial
HRS-15AI Acceptable Useinformative
HRS-02Acceptable Use of Technology Policy and Proceduresfull
HRS-03Clean Desk Policy and Proceduresfull
HRS-13Compliance User Responsibilitypartial
HIPAA-164.310.bWorkstation Usepartial
5.10Acceptable use of information and other associated assetsfull
7.7Clear desk and clear screenfull
NIS2-Art.21.2.gBasic Cyber Hygiene Practices and Cybersecurity Traininginformative
NIS2-CIR-12.2Handling of Assetspartial
NIS2-CIR-8.1Awareness Raising and Basic Cyber Hygiene Practicesinformative
AC-20Use of External Systemsfull
AC-20(1)Use of External Systems | Limits on Authorized Usefull
AC-22Publicly Accessible Contentpartial
PL-4Rules of Behaviorfull
PL-4(1)Rules of Behavior | Social Media and External Site/Application Usage Restrictionsfull
SC-43Usage Restrictionspartial
GV-6.1-010Third-Party AI Risk Policies | GV-6.1-010informative
CC1.1COSO Principle 1: Demonstrates Commitment to Integrity and Ethical Valuesinformative

Evidence (2)

policydocumentmanual

Acceptable use rules defining permitted and prohibited use of organisational information assets, covering personal use limits, clear desk and clear screen, use of social media and external sites and the conditions for using a system the organisation does not control.

Example: Acceptable Use Policy v4.1 (policy management system, approved 2026-02-10), covering permitted use of devices, networks, cloud services and data; prohibited activities; personal use limits; social media and public posting rules; clear desk and clear screen rules; and the conditions for processing organisational information on personally owned or contractor-managed systems

Test: Request the acceptable use rules. Verify: (1) prohibited activities are listed explicitly, (2) personal use limits are stated, (3) obligations to protect organisational information are stated, (4) rules for social media, external sites and applications are stated, covering the posting of organisational information publicly and the use of organisational email addresses and authentication secrets to open accounts elsewhere, (5) clear desk and clear screen rules are stated for workspaces and information processing facilities, (6) the conditions for accessing or processing organisational information on a system the organisation does not control are stated, together with the requirement for a recorded verification of that system's controls or an approved connection or processing agreement, (7) the rules carry a management approval and a review date within the defined interval, (8) distribution to personnel is evidenced.

system_exporttechnicalautomated

Signed acknowledgement records confirming all personnel have read and accepted the acceptable use policy before receiving system access.

Example: AUP acknowledgement export from the HRIS or training platform (BambooHR, Workday, KnowBe4, or equivalent), showing name, email, and acknowledgement date for each current employee, with 100% or near-100% completion.

Test: Export the acknowledgement records from the human resources or training system and reconcile them against the list of people holding access. Verify: (1) every person holding access has a recorded acknowledgement, (2) the acknowledgement pre-dates the grant of access for people who joined in the period, (3) a re-acknowledgement is recorded against the current version of the rules for people who acknowledged an earlier version, (4) anyone without an acknowledgement has an open remediation action.

Questions (3)

boolean

Are the acceptable use rules acknowledged by each person before access to organisational systems is granted?

The acknowledgement before access is what makes the rules enforceable later. Rules published on an intranet with no record of who has read them do not meet the control; Q2 captures how the acknowledgement is recorded.

select

How is acknowledgement of the acceptable use policy captured and tracked for all personnel?

Digital acknowledgement recorded in HRIS or training platform with completion reportWet or e-signature on employment contract or onboarding documentationVerbal acknowledgement during onboarding with no formal recordAcknowledgement is not formally captured

A digital acknowledgement export showing 100% (or near-100%) completion for all active staff, with acknowledgement dates, is the standard evidence.

multi

Which of the following does your acceptable use policy address?

Prohibited activitiesLimits on personal useObligations to protect organisational informationUse of social media, external sites and applicationsPosting organisational information on public sitesUse of organisational email addresses or authentication secrets to open accounts elsewhereClear desk and clear screen rulesConditions for processing organisational information on a system the organisation does not controlNone of the above

The last five items are the ones most often missing from a policy written for a single office and a managed laptop. The external systems item is the one that governs contractor and bring-your-own-device working; the control also asks for a recorded verification of that system's controls or an approved connection or processing agreement for each such use.