1. Purpose
The purpose of this Employee IT Usage Policy is to define how employees and authorized personnel should use the organization’s IT resources securely and responsibly.
The policy is intended to:
- Protect organizational information and technology resources.
- Establish clear employee responsibilities for IT usage.
- Reduce risks arising from misuse, negligence, unauthorized access, or unsafe practices.
- Protect company and customer information.
- Support secure remote and office-based working.
- Ensure appropriate use of company devices, applications, networks, cloud services, and accounts.
Core principle:
Employees must use organizational IT resources only for authorized business purposes, protect the information they access, and follow established security requirements.
2. Scope
This policy applies to:
- Full-time employees
- Part-time employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Other authorized users
It covers organizational:
- Laptops and desktops
- Mobile devices
- Corporate email
- Internet and network access
- Wi-Fi
- Cloud services
- SaaS applications
- Business applications
- Source-code repositories
- Collaboration platforms
- File-storage systems
- VPN and remote-access systems
- User accounts
- Authentication credentials
- Removable media
- Printers and other IT equipment
3. Employee IT Responsibilities
Every employee is responsible for using IT resources securely.
Employees must:
- Use only authorized accounts.
- Protect passwords and authentication methods.
- Use MFA where required.
- Protect assigned devices.
- Lock devices when unattended.
- Use approved applications and services.
- Protect confidential and restricted information.
- Follow security policies and procedures.
- Report security incidents promptly.
- Return organizational equipment when required.
- Complete required security awareness training.
Employees must not assume that access to a system means that they are authorized to use all information available within that system.
4. Company IT Equipment
Company-provided equipment may include:
- Laptops
- Desktops
- Mobile phones
- Tablets
- Security tokens
- USB devices
- Monitors and peripherals
- Network equipment
Employees should use company equipment primarily for authorized business purposes.
Employees must:
- Keep equipment physically secure.
- Avoid unauthorized modifications.
- Keep security software enabled.
- Apply updates when required.
- Report loss or theft immediately.
- Follow IT support instructions.
- Return equipment when requested.
5. Laptop and Desktop Security
Employees using company computers should:
- Use strong authentication.
- Enable MFA where supported.
- Lock the screen when leaving the device.
- Keep the operating system updated.
- Use approved endpoint protection.
- Avoid disabling security controls.
- Avoid installing unauthorized software.
- Store company information only in approved locations.
- Report suspicious behavior.
Example
Before leaving a laptop unattended:
Save work → Close sensitive information → Lock screen → Secure device
6. Mobile Device Usage
Where mobile devices are used for company activities, employees should:
- Enable screen lock.
- Use device encryption where supported.
- Use MFA.
- Install approved applications only.
- Keep the device updated.
- Avoid sharing the device with unauthorized persons.
- Report loss or theft immediately.
Company information should not be stored on personal mobile devices unless specifically authorized.
7. User Accounts
Employees must use their own assigned accounts.
Employees must not:
- Share accounts.
- Use another employee’s credentials.
- Allow another person to use their authenticated session.
- Attempt to bypass access controls.
- Create unauthorized accounts.
Shared accounts should only be used where technically necessary and formally controlled.
8. Password and MFA Requirements
Employees must:
- Keep passwords confidential.
- Use organization-approved password requirements.
- Use a password manager where provided.
- Use MFA where required.
- Report suspected credential compromise.
- Avoid approving unexpected MFA requests.
Employees must never:
- Send passwords through unsecured channels.
- Write passwords on visible notes.
- Share MFA codes.
- Approve an unexpected authentication request.
- Reuse company credentials for unauthorized external services where prohibited.
9. Email Usage
Corporate email should be used responsibly.
Employees should:
- Verify unexpected requests.
- Check recipients before sending information.
- Avoid suspicious links and attachments.
- Use approved methods for sensitive information.
- Report phishing attempts.
- Avoid forwarding confidential business information to personal email accounts.
Before sending sensitive information:
Verify Recipient → Verify Information → Verify Authorization → Use Approved Channel
10. Internet Usage
Company internet access is primarily provided for business purposes.
Employees must not use organizational networks to:
- Conduct illegal activities.
- Attack external systems.
- Circumvent security controls.
- Download malicious content.
- Conduct unauthorized security testing.
- Distribute malware.
- Access systems without authorization.
Reasonable personal use may be permitted if it does not:
- Interfere with work.
- Create security risks.
- Consume excessive resources.
- Violate organizational policies.
11. Software Installation
Employees may install software only where authorized.
Software should be obtained from legitimate and approved sources.
Employees must not install:
- Pirated software
- Cracked applications
- Unauthorized remote-access tools
- Unapproved security tools
- Unauthorized browser extensions
- Software that creates unacceptable security risks
Business software requests should follow the organization’s IT/software approval process.
12. Cloud and SaaS Applications
Employees must use approved cloud and SaaS applications for company information.
Examples include:
- Collaboration
- File sharing
- CRM
- HR systems
- Project management
- Source-code repositories
- Customer support
- Security tools
Employees must not create unauthorized accounts for business activities where the service is not approved.
Example
An employee should not upload a confidential customer document to a personal cloud-storage account to work from home.
13. Generative AI and AI Tools
Employees may use approved AI tools only in accordance with organizational requirements.
Unless specifically authorized, employees must not enter:
- Customer confidential information
- Personal data
- Passwords
- API keys
- Encryption keys
- Source code
- Security incident information
- Confidential contracts
- Restricted business information
into public or unapproved AI services.
Employees should verify AI-generated content before relying on it for business purposes.
14. Data Storage
Company information should be stored only in approved locations.
Employees should not use:
- Personal email
- Personal cloud storage
- Personal file-sharing accounts
- Unauthorized messaging applications
- Personal USB devices
- Unapproved AI services
for storing or transferring confidential company information.
Employees should follow the organization’s information classification and retention requirements.
15. Data Sharing
Before sharing company information, employees should verify:
- Who is receiving it.
- Whether the recipient is authorized.
- What classification applies.
- Whether external sharing is permitted.
- Whether encryption is required.
- Whether a contractual or legal restriction applies.
Employees should use approved secure-sharing mechanisms.
16. Remote Working
Employees working remotely must maintain the same level of security expected in the office.
Employees should:
- Use company-managed devices where required.
- Secure their workspace.
- Protect confidential information from family members or visitors.
- Use approved remote-access methods.
- Avoid discussing sensitive information in public locations.
- Lock devices when unattended.
- Report security incidents.
Public Wi-Fi
Employees should follow organizational requirements when using public Wi-Fi.
Where required, employees should use approved VPN or other secure connection mechanisms.
17. Home Working
When working from home, employees should:
- Keep company devices secure.
- Prevent unauthorized family/member access.
- Protect printed documents.
- Secure home Wi-Fi.
- Avoid leaving devices unattended.
- Use approved applications and storage.
- Follow company security controls.
Company devices should not be used by unauthorized family members.
18. Removable Media
The use of USB drives and other removable media should be controlled.
Employees must:
- Use approved media where required.
- Avoid unknown USB devices.
- Protect sensitive information.
- Encrypt sensitive data where required.
- Scan media where appropriate.
- Securely dispose of media.
An employee should never connect an unknown USB device to a company computer simply to identify its contents.
19. Printing and Physical Documents
Employees should handle printed information according to its classification.
Employees should:
- Collect documents promptly from printers.
- Avoid leaving confidential documents unattended.
- Store sensitive documents securely.
- Dispose of sensitive documents using approved methods.
- Avoid unnecessary printing of confidential information.
20. Corporate Messaging and Collaboration Tools
Approved messaging and collaboration tools should be used for business communication.
Employees must not:
- Share passwords or credentials.
- Share restricted information through unauthorized channels.
- Add unauthorized external participants to confidential discussions.
- Create unauthorized groups containing sensitive information.
- Use personal messaging accounts for confidential business information where prohibited.
21. Source Code and Development Systems
Employees involved in software development must:
- Use approved source-code repositories.
- Protect repository credentials.
- Follow access-control requirements.
- Avoid storing secrets in source code.
- Follow code-review processes.
- Use approved development environments.
- Protect customer and production data.
- Follow secure development requirements.
Production credentials must not be stored in source-code repositories.
22. Cloud Infrastructure Access
Employees with cloud access must:
- Use individual accounts where feasible.
- Use MFA.
- Follow least privilege.
- Use approved administrative methods.
- Avoid sharing cloud credentials.
- Follow change-management requirements.
- Avoid unauthorized production changes.
AWS Example
A developer who discovers that a production security group needs modification should follow:
Request → Review → Approval → Change → Verification → Record
rather than making an unapproved direct production change.
23. Personal Devices / BYOD
Where Bring Your Own Device (BYOD) is permitted, employees may be required to comply with security controls such as:
- Device encryption
- Screen lock
- MFA
- Approved applications
- Mobile/device management
- Security updates
- Remote wipe where applicable
- Restrictions on local company data storage
The organization may restrict access from personal devices when required by security or compliance considerations.
24. Security Monitoring
The organization may monitor the use of its IT resources where permitted by applicable requirements.
Monitoring may include:
- Login activity
- Endpoint activity
- Network activity
- Cloud activity
- Administrative actions
- Security events
- Application activity
- Data access
- Security alerts
Monitoring should be performed for legitimate purposes such as security, troubleshooting, incident investigation, compliance, and protection of organizational resources.
Applicable privacy and legal requirements should be considered.
25. Security Incident Reporting
Employees must report suspected security incidents promptly.
Examples include:
- Lost laptop
- Lost mobile phone
- Phishing email
- Malware
- Accidental disclosure
- Wrong-recipient email
- Suspicious login
- Stolen credentials
- Unauthorized access
- Suspicious software
- Unusual cloud activity
- Lost access card
- Suspected data breach
Reporting Process
Detect → Stop/Contain if Safe → Report → Record → Investigate → Respond → Recover → Learn
Employees should not attempt to hide mistakes or security incidents.
Early reporting can reduce the impact of an incident.
26. IT Support and Service Requests
Employees should use approved IT support channels for technical issues.
Examples:
- Password reset
- Device problems
- Software installation
- Access requests
- VPN issues
- Hardware replacement
- Security concerns
- SaaS access problems
Employees should not bypass IT/security controls to solve technical problems independently.
27. Unauthorized Security Activities
Employees must not perform security testing or technical activities against systems without authorization.
This includes:
- Port scanning
- Vulnerability scanning
- Penetration testing
- Exploitation
- Password attacks
- Network interception
- Denial-of-service testing
- Social engineering
- Security testing of customer systems
Authorization must be obtained before such activities are performed.
28. Personal Use
Limited personal use of company IT resources may be allowed where approved.
Personal use must not:
- Interfere with work.
- Create security risks.
- Violate law or company policy.
- Consume excessive resources.
- Introduce unauthorized software.
- Involve prohibited activities.
The organization may prohibit personal use for specific systems.
29. IT Asset Transfer
When an employee changes roles or departments, IT assets and access should be reviewed.
The process may include:
Role Change → Review Access → Transfer/Recover Assets → Modify Permissions → Update Inventory → Verify
Examples:
- Laptop
- Mobile phone
- Security token
- SaaS accounts
- Cloud access
- Administrative privileges
- Physical access cards
30. Employee Offboarding
When employment ends, the organization should coordinate:
- Account disablement
- Access revocation
- Device recovery
- Asset recovery
- Token recovery
- SaaS access removal
- Cloud access removal
- Repository access removal
- Company information return
- Data transfer where required
- Credential revocation
Lifecycle
Offboarding Trigger → Identify Access/Assets → Disable Access → Recover Assets → Transfer Business Information → Update Records → Verify Closure
31. Loss or Theft of IT Equipment
Employees must immediately report lost or stolen:
- Laptops
- Mobile devices
- Tablets
- Security tokens
- USB drives
- Access cards
- Other company equipment
The organization may then:
- Disable accounts.
- Revoke credentials.
- Remotely lock/wipe devices where available.
- Investigate potential data exposure.
- Assess incident severity.
- Notify relevant parties where required.
32. Exceptions
Exceptions must be:
- Business justified.
- Risk assessed.
- Approved by an authorized person.
- Documented.
- Time-bound where appropriate.
- Reviewed periodically.
Example:
An employee may temporarily require access to a system outside the standard process for an emergency business requirement.
The exception should document:
- Reason
- Scope
- Risk
- Compensating controls
- Approver
- Expiry/review date
33. Non-Compliance
Failure to comply with this policy may result in:
- Security investigation
- Additional training
- Access restriction
- Corrective action
- Disciplinary action
- Contractual action
- Legal action where applicable
Actions should be proportionate to the circumstances and consistent with organizational procedures.
34. Roles and Responsibilities
Employees
- Follow this policy.
- Protect company IT resources.
- Protect organizational information.
- Report incidents.
- Complete security training.
Managers
- Ensure employees understand applicable requirements.
- Approve access where authorized.
- Notify IT/HR of role changes and departures.
IT
- Provision and maintain IT resources.
- Apply technical security controls.
- Manage devices and accounts.
- Support users.
- Maintain asset records.
Information Security / ISMS
- Maintain security requirements.
- Monitor compliance.
- Provide security guidance.
- Support incident management and awareness.
HR
- Coordinate onboarding and offboarding.
- Ensure employees receive relevant policies.
- Support appropriate disciplinary processes.
Management
- Approve the policy.
- Provide resources.
- Support enforcement.
35. Employee Awareness
Employees should receive IT-security awareness training covering:
- Password and MFA security
- Phishing
- Data handling
- Device security
- Remote working
- Cloud and SaaS usage
- AI tool usage
- Incident reporting
- Social engineering
- Secure information sharing
Training should be provided during onboarding and periodically thereafter according to organizational requirements.
36. Acceptable vs Unacceptable IT Usage
| Acceptable | Unacceptable |
|---|---|
| Use company laptop for authorized work | Allowing unauthorized persons to use it |
| Use approved SaaS applications | Creating unauthorized SaaS accounts |
| Use MFA | Sharing MFA approvals |
| Store company data in approved systems | Using personal cloud storage |
| Report phishing | Ignoring suspicious emails |
| Use approved software | Installing pirated software |
| Follow change management | Making unauthorized production changes |
| Use approved AI tools | Uploading confidential data to public AI |
| Report lost equipment | Waiting to report a lost laptop |
| Use authorized cloud access | Sharing AWS credentials |
37. AWS SaaS Startup Example
Consider a 25-person SaaS startup using AWS, GitHub, Microsoft 365, Slack, Jira, and a customer-support platform.
Employee expectations
Laptop
→ Company-managed
→ Encryption enabled
→ Screen lock
→ Endpoint protection
Identity
→ Individual account
→ MFA
→ Least privilege
AWS
→ Role-based access
→ No credential sharing
→ Production changes controlled
GitHub
→ Approved repository
→ MFA
→ No secrets in source code
Customer Data
→ Approved systems only
→ No personal storage
→ No unauthorized AI tools
Remote Work
→ Secure device
→ Approved access mechanism
→ Confidential information protected
Incident
→ Report immediately
→ Security team investigates
This gives employees practical rules instead of requiring them to interpret a general security policy.
38. Audit Evidence
Possible evidence includes:
- Employee IT Usage Policy
- Employee acknowledgement
- Security awareness records
- Asset inventory
- Device management records
- Access-control records
- MFA configuration
- Software inventory
- SaaS application register
- Security monitoring
- IT support tickets
- Incident reports
- Offboarding records
- Asset return records
- Exception approvals
An auditor may select employees and verify:
Employee → Assigned Device → Account → Access → Training → Policy Acknowledgement → Offboarding/Asset Return
39. Common Mistakes
Mistake 1 — Treating IT usage as only laptop usage
Modern employees use cloud platforms, SaaS applications, AI tools, collaboration systems, and mobile devices.
Mistake 2 — No BYOD rules
If personal devices are permitted, their security requirements should be clear.
Mistake 3 — No AI guidance
Employees may unintentionally expose confidential information through public AI services.
Mistake 4 — No lost-device process
Employees should know exactly what to do if a laptop or phone is lost.
Mistake 5 — No offboarding linkage
IT usage policy should connect with the employee lifecycle.
Mistake 6 — Excessive restrictions
Rules should be practical enough that employees can actually follow them.
Mistake 7 — Policy without technical controls
Where appropriate, technical controls should support the policy rather than relying entirely on employee behavior.
40. Relationship with Other ISMS Documents
The Employee IT Usage Policy should connect with:
Acceptable Use Policy
→ General rules for responsible technology use
Information Security Policy
→ Overall security direction
Asset Inventory
→ IT resources assigned to employees
Asset Lifecycle Management
→ Acquisition, transfer, maintenance, and disposal
Access Control Policy
→ Employee access to systems and information
Security Awareness Policy
→ Employee training
Joiner-Mover-Leaver Procedure
→ Employee access lifecycle
Incident Management Procedure
→ Security incident reporting
Data Classification Procedure
→ Appropriate handling of information
Remote Working Policy
→ Secure work outside the office
SaaS Application Register
→ Approved cloud applications
Change Management
→ Controlled IT and production changes
The relationship is:
Employee → Device/Account → Access → Information → Authorized Use → Security Controls → Monitoring → Incident Reporting → Offboarding
41. Quick Audit Checklist
| Check | Yes/No | Evidence |
|---|---|---|
| Is the Employee IT Usage Policy approved? | ||
| Does it cover employees and relevant contractors? | ||
| Are company devices covered? | ||
| Are mobile devices covered? | ||
| Are passwords and MFA addressed? | ||
| Are email and internet usage addressed? | ||
| Are cloud and SaaS applications addressed? | ||
| Is AI usage addressed where relevant? | ||
| Are data storage and sharing requirements defined? | ||
| Is remote working addressed? | ||
| Is BYOD addressed where applicable? | ||
| Are software installation rules defined? | ||
| Are removable media requirements defined? | ||
| Is security incident reporting defined? | ||
| Is unauthorized security testing prohibited? | ||
| Is lost/stolen equipment reporting defined? | ||
| Are employee offboarding requirements defined? | ||
| Are exceptions controlled? | ||
| Are employees trained? | ||
| Are policy acknowledgements maintained? | ||
| Is the policy periodically reviewed? |
42. Policy Review
This policy should be reviewed periodically and when significant changes occur, including:
- New IT systems
- New cloud services
- New SaaS applications
- Introduction of AI tools
- Changes to remote working
- Major security incidents
- Changes in applicable requirements
- Significant changes to the organization’s technology environment
- Changes in the organization’s risk profile
All significant revisions should be approved by the designated authority.
43. Final Principle
The Employee IT Usage Policy should make security expectations simple for employees:
Use authorized IT resources. Protect company information. Protect your account and device. Do not bypass security controls. Report problems quickly.
The practical lifecycle is:
Provision → Authorize → Use → Protect → Monitor → Report → Support → Review → Transfer/Offboard → Securely Retire
The goal is to make secure IT usage part of everyday employee behavior rather than treating information security as a separate technical responsibility.
