ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Acceptable Use Policy

Acceptable Use Policy

1. Purpose

The purpose of this Acceptable Use Policy is to define how organizational information, information systems, devices, applications, cloud services, networks, and other technology resources may be used.

The policy is intended to:

  • Protect organizational information and systems.
  • Prevent unauthorized or inappropriate use.
  • Reduce security risks caused by misuse, negligence, or unsafe behavior.
  • Establish clear expectations for employees, contractors, and third parties.
  • Support confidentiality, integrity, and availability of information.
  • Provide a basis for security awareness, monitoring, and incident management.

Core principle:

Organizational technology and information should be used for authorized business purposes, securely, responsibly, and in accordance with applicable requirements.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Temporary workers
  • Interns
  • Third-party users
  • Service providers with authorized access

It applies to organizational:

  • Laptops and desktops
  • Mobile devices
  • Servers
  • Cloud environments
  • SaaS applications
  • Corporate email
  • Collaboration platforms
  • Internet access
  • Networks
  • Source-code repositories
  • Business applications
  • Customer systems
  • Removable media
  • Information and data
  • Credentials and authentication mechanisms

The policy applies whether resources are accessed from company premises, home, customer locations, or other authorized locations.


3. Acceptable Use Principles

Users are expected to:

  1. Use organizational resources only for authorized purposes.
  2. Protect organizational information from unauthorized access.
  3. Use only accounts and access rights assigned to them.
  4. Follow information classification and handling requirements.
  5. Protect passwords, MFA devices, tokens, keys, and other credentials.
  6. Report suspected security incidents promptly.
  7. Follow applicable security, privacy, legal, and contractual requirements.
  8. Respect intellectual property and licensing requirements.
  9. Use company systems in a professional and responsible manner.
  10. Avoid actions that could compromise organizational security.

4. User Responsibilities

Users are responsible for:

  • Protecting assigned devices.
  • Keeping credentials confidential.
  • Locking devices when unattended.
  • Using approved applications and services.
  • Handling information according to its classification.
  • Avoiding unauthorized data sharing.
  • Installing software only where authorized.
  • Reporting lost or stolen devices.
  • Reporting suspicious emails, links, files, or activities.
  • Following remote-working requirements.
  • Cooperating with security investigations.

Users should not assume that information stored on a company-managed system is automatically secure simply because the system is managed by the organization.


5. Acceptable Use of Information

Organizational information should be accessed and used only when there is a legitimate business need.

Users should:

  • Access only information necessary for their role.
  • Follow need-to-know principles.
  • Respect information classifications.
  • Use approved storage locations.
  • Verify recipients before sharing information.
  • Protect confidential information during discussions and meetings.
  • Avoid copying sensitive information unnecessarily.
  • Follow retention and disposal requirements.

Example

A customer-support employee may access customer support records required to resolve a customer issue.

The employee should not browse unrelated customer records simply because technical access is available.


6. Passwords and Authentication

Users must:

  • Keep passwords confidential.
  • Use organization-approved authentication mechanisms.
  • Use MFA where required.
  • Avoid sharing accounts.
  • Avoid storing passwords in unsecured files.
  • Report suspected credential compromise.
  • Use approved password-management tools where provided.

Users must not:

  • Share passwords with colleagues.
  • Approve MFA requests they did not initiate.
  • Use another person’s account.
  • Attempt to bypass authentication controls.
  • Disable security mechanisms without authorization.

7. Use of Corporate Devices

Corporate devices should be used responsibly and securely.

Users should:

  • Keep operating systems and applications updated.
  • Use approved security controls.
  • Lock the device when unattended.
  • Protect devices from theft or unauthorized access.
  • Avoid connecting unauthorized storage devices where prohibited.
  • Report loss or theft immediately.
  • Return devices when requested or upon termination.

Users must not intentionally disable:

  • Endpoint protection
  • Encryption
  • Security monitoring
  • Firewall controls
  • Device management
  • Logging
  • Other security mechanisms

unless specifically authorized.


8. Personal Devices

Where personal devices are permitted for business purposes, users must comply with applicable security requirements.

These may include:

  • Device encryption
  • Screen lock
  • MFA
  • Approved applications
  • Mobile device management
  • Secure storage
  • Remote-wipe capability where applicable
  • Restrictions on local storage of confidential information

The organization may restrict access from personal devices where the security risk is unacceptable.


9. Email and Messaging

Corporate email and messaging systems should be used responsibly.

Users should:

  • Verify unexpected requests.
  • Check recipients before sending sensitive information.
  • Avoid opening suspicious attachments.
  • Avoid clicking suspicious links.
  • Report suspected phishing.
  • Use approved channels for confidential information.
  • Follow data classification requirements.

Users must not intentionally send confidential information to unauthorized recipients.

Example

Before emailing a customer report containing confidential information, the employee should:

Verify recipient → Verify attachment → Confirm authorization → Send using approved channel


10. Internet and Web Usage

Internet access provided by the organization is primarily intended for legitimate business purposes.

Users must not use organizational resources to:

  • Access illegal content.
  • Conduct fraudulent activities.
  • Distribute malicious software.
  • Circumvent security controls.
  • Conduct unauthorized security testing.
  • Attack or disrupt external systems.
  • Download unauthorized software.
  • Access systems without authorization.

Limited personal use may be permitted where it:

  • Does not interfere with work.
  • Does not create security risk.
  • Does not violate law or organizational policy.
  • Does not consume excessive resources.

The organization may define more restrictive rules where required.


11. Software Installation

Only approved or authorized software may be installed on organizational devices and systems.

Users must not install:

  • Pirated software
  • Unlicensed software
  • Cracked applications
  • Unauthorized remote-access tools
  • Unapproved browser extensions
  • Software that introduces unacceptable security risk

Requests for business software should follow the organization’s approved software/procurement process.


12. Cloud Services and SaaS Applications

Employees must use approved cloud and SaaS services for organizational information.

Users should not upload confidential or restricted information to an external service unless the service is authorized for that purpose.

Examples of potentially sensitive services include:

  • File-sharing platforms
  • AI tools
  • Online document editors
  • Collaboration platforms
  • Code repositories
  • Data-analysis platforms
  • Customer-management systems

Example

An employee should not upload a customer database or confidential customer document to a public AI tool merely to summarize it unless the tool and processing have been approved for that type of information.


13. Use of Generative AI and AI Services

Where the organization permits the use of generative AI tools, users must follow approved AI-security and data-handling requirements.

Users should not enter into unapproved AI services:

  • Customer confidential information
  • Credentials
  • API keys
  • Encryption keys
  • Personal data
  • Security incident details
  • Source code
  • Proprietary business information
  • Restricted information

unless explicitly authorized.

AI-generated output should also be reviewed before being used for business-critical decisions or external communications.


14. Source Code and Development Resources

Developers must protect organizational source code and development environments.

Users must:

  • Use approved repositories.
  • Follow repository access controls.
  • Protect credentials and secrets.
  • Follow secure development requirements.
  • Use approved dependency sources.
  • Follow code-review requirements.
  • Avoid storing secrets in source code.
  • Avoid copying proprietary source code to unauthorized locations.

Production credentials must not be stored in source-code repositories.


15. Cloud Infrastructure

Access to cloud infrastructure must be authorized and controlled.

Users must:

  • Use individual accounts where technically feasible.
  • Use MFA for privileged access.
  • Follow least-privilege principles.
  • Use approved administrative mechanisms.
  • Protect cloud credentials.
  • Avoid making unauthorized production changes.
  • Follow change-management requirements.

AWS Example

A developer should not directly modify a production AWS security group simply because they technically have access.

Where the change is required:

Request → Assess → Approve → Change → Verify → Record

should be followed according to the organization’s change-management process.


16. Removable Media

Use of removable media should be restricted according to information security requirements.

Where removable media is authorized:

  • Use approved devices.
  • Protect sensitive information.
  • Encrypt sensitive information where required.
  • Scan media where appropriate.
  • Do not use unknown USB devices.
  • Securely dispose of media when no longer required.

Users should not connect unknown USB devices to organizational systems.


17. Remote Working

When working remotely, users should:

  • Use secure network connections.
  • Protect company devices.
  • Prevent unauthorized persons from viewing confidential information.
  • Avoid discussing sensitive information where it can be overheard.
  • Use approved remote-access mechanisms.
  • Lock devices when unattended.
  • Report lost or stolen equipment.

Public Wi-Fi should be used only in accordance with organizational security requirements.


18. Physical Security

Users must protect physical information and devices.

Examples include:

  • Laptops
  • Mobile phones
  • USB devices
  • Printed documents
  • Access cards
  • Security tokens

Users should not leave confidential information unattended in public areas.

Where applicable, users should follow clean-desk and clear-screen requirements.


19. Prohibited Activities

Unless specifically authorized, users must not:

  • Access another person’s account.
  • Attempt to bypass security controls.
  • Perform unauthorized vulnerability scanning.
  • Conduct unauthorized penetration testing.
  • Introduce malware.
  • Disable security software.
  • Circumvent monitoring.
  • Conduct unauthorized network interception.
  • Obtain credentials belonging to others.
  • Modify production systems without authorization.
  • Copy confidential information for personal use.
  • Upload restricted information to unauthorized services.
  • Use company resources for illegal activities.
  • Conduct activities that could damage the organization’s reputation or systems.

20. Security Testing

Security testing must be authorized before being performed.

Employees and contractors must not independently perform:

  • Penetration testing
  • Vulnerability scanning
  • Port scanning
  • Exploitation testing
  • Social engineering
  • Denial-of-service testing
  • Credential testing

against organizational or third-party systems unless the activity is formally authorized and appropriately scoped.

Example

A developer should not run a penetration-testing tool against a customer’s production environment simply because they are investigating an issue.

Testing should follow:

Authorization → Scope → Test → Record Results → Remediate → Retest


21. Monitoring and Logging

The organization may monitor the use of organizational systems where permitted by applicable law and organizational requirements.

Monitoring may include:

  • Authentication activity
  • Administrative activity
  • Security events
  • Network activity
  • Endpoint activity
  • Cloud activity
  • Application activity
  • Data access
  • Security alerts

Monitoring should be performed for legitimate purposes such as:

  • Security
  • Incident investigation
  • Troubleshooting
  • Compliance
  • System protection
  • Fraud prevention

Applicable privacy and legal requirements should be considered when implementing monitoring.


22. Privacy and Personal Data

Users must handle personal data according to applicable privacy requirements and organizational policies.

Users should:

  • Access personal data only when required.
  • Avoid unnecessary copying.
  • Use approved systems.
  • Protect personal data from unauthorized disclosure.
  • Follow retention and deletion requirements.
  • Report suspected data breaches.

23. Intellectual Property and Licensing

Users must respect:

  • Copyright
  • Software licenses
  • Customer intellectual property
  • Third-party intellectual property
  • Organizational intellectual property
  • Confidentiality obligations

Users must not use pirated software or unauthorized copyrighted material for business purposes.


24. Third-Party Access

Third parties may access organizational systems only when:

  • Access is authorized.
  • Business need is established.
  • Appropriate security requirements are satisfied.
  • Access is limited to required resources.
  • Access is monitored where appropriate.
  • Access is removed when no longer required.

Third-party users should not share organizational credentials.


25. Data Transfer and Sharing

Before transferring confidential or restricted information, users should verify:

  1. What information is being transferred?
  2. What is its classification?
  3. Who is receiving it?
  4. Is the recipient authorized?
  5. Is the transfer method approved?
  6. Is encryption required?
  7. Is there a contractual or legal restriction?

Users should use approved secure-transfer mechanisms for sensitive information.


26. Personal Use

The organization may permit limited personal use of certain resources, subject to management approval and security requirements.

Personal use must not:

  • Interfere with work.
  • Create security risks.
  • Consume excessive resources.
  • Violate law or organizational policies.
  • Introduce unauthorized software.
  • Involve inappropriate or prohibited activities.

The organization may prohibit personal use for particular systems or assets.


27. Security Incident Reporting

Users must promptly report suspected security incidents.

Examples include:

  • Lost or stolen device
  • Phishing email
  • Accidental data disclosure
  • Malware
  • Suspicious login
  • Credential compromise
  • Unauthorized access
  • Data sent to the wrong recipient
  • Lost security token
  • Unapproved software installation
  • Suspicious cloud activity

Users should not attempt to conceal a security incident.

Reporting Flow

Detect → Stop/Contain if Safe → Report → Record → Assess → Investigate → Respond → Learn


28. Exceptions

Exceptions to this policy must be:

  • Business justified.
  • Risk assessed.
  • Approved by an authorized person.
  • Documented.
  • Time-bound where appropriate.
  • Reviewed periodically.

Example:

A security engineer may temporarily require elevated privileges for an emergency production incident.

The exception should document:

  • Reason
  • Scope
  • Duration
  • Risk
  • Compensating controls
  • Approver
  • Closure

29. Non-Compliance

Failure to comply with this policy may result in:

  • Security investigation
  • Access restriction
  • Additional training
  • Corrective action
  • Disciplinary action
  • Contractual action
  • Legal action where applicable

The response should be proportionate to the circumstances and consistent with applicable organizational procedures.


30. Roles and Responsibilities

Management

  • Approve the policy.
  • Provide resources.
  • Support enforcement.

Security/ISMS Manager

  • Maintain the policy.
  • Provide guidance.
  • Monitor compliance.
  • Coordinate awareness.
  • Support investigations.

IT/Cloud/Engineering

  • Implement technical controls.
  • Manage systems and access.
  • Support monitoring and security.

HR

  • Include acceptable-use requirements in employee onboarding.
  • Support disciplinary processes where applicable.
  • Coordinate offboarding requirements.

Managers

  • Ensure team members understand applicable requirements.
  • Approve access and exceptions where authorized.

Employees and Contractors

  • Follow this policy.
  • Protect organizational resources.
  • Report security concerns.
  • Complete required security awareness training.

Third Parties

  • Follow applicable organizational security requirements.
  • Use access only for authorized purposes.
  • Report incidents.

31. Awareness and Training

Users should receive acceptable-use and information-security awareness training.

Training should cover:

  • Password and MFA security
  • Phishing
  • Data handling
  • Device security
  • Remote working
  • Cloud and SaaS usage
  • AI tool usage
  • Incident reporting
  • Social engineering
  • Secure information sharing

Training should be provided during onboarding and periodically thereafter, based on organizational requirements.


32. Acceptable vs Unacceptable Use

AcceptableUnacceptable
Using approved SaaS applicationsUsing unauthorized SaaS for confidential data
Using MFASharing MFA approvals
Accessing required customer informationBrowsing unrelated customer records
Using approved cloud environmentsCreating unauthorized production resources
Reporting phishingIgnoring or forwarding phishing
Using licensed softwareInstalling pirated software
Authorized security testingUnauthorized penetration testing
Securely sharing customer dataSending customer data to personal email
Using approved AI toolsUploading restricted information to unapproved AI tools
Locking devicesLeaving unlocked devices unattended

33. AWS SaaS Startup Example

Consider a 30-person SaaS startup operating primarily in AWS.

Employees may:

  • Access AWS resources according to their role.
  • Use approved GitHub repositories.
  • Use approved collaboration tools.
  • Access customer information required for their role.
  • Use approved AI tools within defined data-handling restrictions.
  • Work remotely using approved security controls.

Employees may not:

  • Share AWS credentials.
  • Copy production customer data to personal storage.
  • Create unauthorized AWS accounts/resources.
  • Disable CloudTrail or security monitoring.
  • Upload customer data to an unapproved AI service.
  • Directly modify production without authorization.
  • Use personal GitHub repositories for company source code.

The policy therefore converts general security expectations into everyday user behavior.


34. Audit Evidence

Evidence may include:

  • Approved Acceptable Use Policy
  • Employee acknowledgements
  • Security awareness records
  • Acceptable-use training
  • Access-control records
  • Software approval records
  • SaaS approval records
  • Security monitoring logs
  • Incident reports
  • Exception records
  • Disciplinary/corrective-action records where appropriate
  • Device management records
  • Cloud access records

An auditor may sample employees and verify:

Policy → Awareness → User Acknowledgement → Actual Controls → Monitoring → Incident/Exception Handling


35. Common Mistakes

Mistake 1 — Making the policy only about internet browsing

Acceptable use covers information, devices, cloud, SaaS, applications, credentials, AI tools, data sharing, and security activities.

Mistake 2 — Making it excessively restrictive

The policy should establish realistic security expectations rather than prohibit ordinary business activities unnecessarily.

Mistake 3 — Ignoring cloud and SaaS

Modern startups rely heavily on cloud services and SaaS applications.

Mistake 4 — Ignoring AI tools

Employees may unintentionally expose confidential information through public AI services.

Mistake 5 — No incident-reporting requirement

Users need a clear mechanism for reporting mistakes and suspicious activity.

Mistake 6 — No distinction between authorized and unauthorized security testing

Employees should understand that technical ability does not automatically constitute authorization.

Mistake 7 — Policy without awareness

A policy is much more effective when users understand what is expected of them.


36. Relationship with Other ISMS Documents

The Acceptable Use Policy should connect with:

Information Security Policy
→ Overall security direction

Information & Asset Inventory
→ What resources users are expected to protect

Asset Classification Procedure
→ How information should be handled

Access Control Policy
→ Who can access systems and information

Security Awareness Policy
→ How users are trained

Incident Management Procedure
→ What users should do when something goes wrong

Data Protection/Privacy Policy
→ How personal information should be handled

Change Management
→ How production changes are controlled

Secure Development Policy
→ How developers use development resources

Supplier Security
→ How third-party users are controlled

Employee Joiner-Mover-Leaver Process
→ How access and assets are managed throughout employment

The relationship is:

User → Asset → Information → Authorized Use → Security Controls → Monitoring → Incident Reporting → Improvement


37. Quick Audit Checklist

CheckYes/NoEvidence
Is an Acceptable Use Policy approved?
Does it cover employees and relevant third parties?
Are organizational devices covered?
Are cloud and SaaS services covered?
Are information-handling requirements defined?
Are password/MFA responsibilities defined?
Are prohibited activities documented?
Is unauthorized security testing addressed?
Are AI tools addressed where relevant?
Are remote-working requirements addressed?
Are removable media requirements addressed?
Is software installation controlled?
Is incident reporting defined?
Are exceptions documented?
Is monitoring addressed appropriately?
Are users trained?
Are policy acknowledgements retained?
Is the policy periodically reviewed?
Are actual practices consistent with the policy?

38. Policy Review

This policy should be reviewed periodically and whenever significant changes occur, such as:

  • New technology
  • New cloud services
  • Significant changes in remote working
  • Introduction of AI tools
  • New regulatory requirements
  • Major security incidents
  • Changes to business operations
  • Significant changes in the organization’s risk profile

Changes should be approved by the designated authority.


39. Final Principle

An Acceptable Use Policy should answer one simple question:

How should people use the organization’s information and technology without creating unnecessary security risk?

The practical model is:

Understand → Authorize → Use Securely → Protect → Monitor → Report → Correct → Learn → Improve

The objective is not to prevent employees from using technology. It is to ensure that technology, information, cloud services, and organizational resources are used responsibly, securely, and only for authorized purposes.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *