1. Purpose
The purpose of this Acceptable Use Policy is to define how organizational information, information systems, devices, applications, cloud services, networks, and other technology resources may be used.
The policy is intended to:
- Protect organizational information and systems.
- Prevent unauthorized or inappropriate use.
- Reduce security risks caused by misuse, negligence, or unsafe behavior.
- Establish clear expectations for employees, contractors, and third parties.
- Support confidentiality, integrity, and availability of information.
- Provide a basis for security awareness, monitoring, and incident management.
Core principle:
Organizational technology and information should be used for authorized business purposes, securely, responsibly, and in accordance with applicable requirements.
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Temporary workers
- Interns
- Third-party users
- Service providers with authorized access
It applies to organizational:
- Laptops and desktops
- Mobile devices
- Servers
- Cloud environments
- SaaS applications
- Corporate email
- Collaboration platforms
- Internet access
- Networks
- Source-code repositories
- Business applications
- Customer systems
- Removable media
- Information and data
- Credentials and authentication mechanisms
The policy applies whether resources are accessed from company premises, home, customer locations, or other authorized locations.
3. Acceptable Use Principles
Users are expected to:
- Use organizational resources only for authorized purposes.
- Protect organizational information from unauthorized access.
- Use only accounts and access rights assigned to them.
- Follow information classification and handling requirements.
- Protect passwords, MFA devices, tokens, keys, and other credentials.
- Report suspected security incidents promptly.
- Follow applicable security, privacy, legal, and contractual requirements.
- Respect intellectual property and licensing requirements.
- Use company systems in a professional and responsible manner.
- Avoid actions that could compromise organizational security.
4. User Responsibilities
Users are responsible for:
- Protecting assigned devices.
- Keeping credentials confidential.
- Locking devices when unattended.
- Using approved applications and services.
- Handling information according to its classification.
- Avoiding unauthorized data sharing.
- Installing software only where authorized.
- Reporting lost or stolen devices.
- Reporting suspicious emails, links, files, or activities.
- Following remote-working requirements.
- Cooperating with security investigations.
Users should not assume that information stored on a company-managed system is automatically secure simply because the system is managed by the organization.
5. Acceptable Use of Information
Organizational information should be accessed and used only when there is a legitimate business need.
Users should:
- Access only information necessary for their role.
- Follow need-to-know principles.
- Respect information classifications.
- Use approved storage locations.
- Verify recipients before sharing information.
- Protect confidential information during discussions and meetings.
- Avoid copying sensitive information unnecessarily.
- Follow retention and disposal requirements.
Example
A customer-support employee may access customer support records required to resolve a customer issue.
The employee should not browse unrelated customer records simply because technical access is available.
6. Passwords and Authentication
Users must:
- Keep passwords confidential.
- Use organization-approved authentication mechanisms.
- Use MFA where required.
- Avoid sharing accounts.
- Avoid storing passwords in unsecured files.
- Report suspected credential compromise.
- Use approved password-management tools where provided.
Users must not:
- Share passwords with colleagues.
- Approve MFA requests they did not initiate.
- Use another person’s account.
- Attempt to bypass authentication controls.
- Disable security mechanisms without authorization.
7. Use of Corporate Devices
Corporate devices should be used responsibly and securely.
Users should:
- Keep operating systems and applications updated.
- Use approved security controls.
- Lock the device when unattended.
- Protect devices from theft or unauthorized access.
- Avoid connecting unauthorized storage devices where prohibited.
- Report loss or theft immediately.
- Return devices when requested or upon termination.
Users must not intentionally disable:
- Endpoint protection
- Encryption
- Security monitoring
- Firewall controls
- Device management
- Logging
- Other security mechanisms
unless specifically authorized.
8. Personal Devices
Where personal devices are permitted for business purposes, users must comply with applicable security requirements.
These may include:
- Device encryption
- Screen lock
- MFA
- Approved applications
- Mobile device management
- Secure storage
- Remote-wipe capability where applicable
- Restrictions on local storage of confidential information
The organization may restrict access from personal devices where the security risk is unacceptable.
9. Email and Messaging
Corporate email and messaging systems should be used responsibly.
Users should:
- Verify unexpected requests.
- Check recipients before sending sensitive information.
- Avoid opening suspicious attachments.
- Avoid clicking suspicious links.
- Report suspected phishing.
- Use approved channels for confidential information.
- Follow data classification requirements.
Users must not intentionally send confidential information to unauthorized recipients.
Example
Before emailing a customer report containing confidential information, the employee should:
Verify recipient → Verify attachment → Confirm authorization → Send using approved channel
10. Internet and Web Usage
Internet access provided by the organization is primarily intended for legitimate business purposes.
Users must not use organizational resources to:
- Access illegal content.
- Conduct fraudulent activities.
- Distribute malicious software.
- Circumvent security controls.
- Conduct unauthorized security testing.
- Attack or disrupt external systems.
- Download unauthorized software.
- Access systems without authorization.
Limited personal use may be permitted where it:
- Does not interfere with work.
- Does not create security risk.
- Does not violate law or organizational policy.
- Does not consume excessive resources.
The organization may define more restrictive rules where required.
11. Software Installation
Only approved or authorized software may be installed on organizational devices and systems.
Users must not install:
- Pirated software
- Unlicensed software
- Cracked applications
- Unauthorized remote-access tools
- Unapproved browser extensions
- Software that introduces unacceptable security risk
Requests for business software should follow the organization’s approved software/procurement process.
12. Cloud Services and SaaS Applications
Employees must use approved cloud and SaaS services for organizational information.
Users should not upload confidential or restricted information to an external service unless the service is authorized for that purpose.
Examples of potentially sensitive services include:
- File-sharing platforms
- AI tools
- Online document editors
- Collaboration platforms
- Code repositories
- Data-analysis platforms
- Customer-management systems
Example
An employee should not upload a customer database or confidential customer document to a public AI tool merely to summarize it unless the tool and processing have been approved for that type of information.
13. Use of Generative AI and AI Services
Where the organization permits the use of generative AI tools, users must follow approved AI-security and data-handling requirements.
Users should not enter into unapproved AI services:
- Customer confidential information
- Credentials
- API keys
- Encryption keys
- Personal data
- Security incident details
- Source code
- Proprietary business information
- Restricted information
unless explicitly authorized.
AI-generated output should also be reviewed before being used for business-critical decisions or external communications.
14. Source Code and Development Resources
Developers must protect organizational source code and development environments.
Users must:
- Use approved repositories.
- Follow repository access controls.
- Protect credentials and secrets.
- Follow secure development requirements.
- Use approved dependency sources.
- Follow code-review requirements.
- Avoid storing secrets in source code.
- Avoid copying proprietary source code to unauthorized locations.
Production credentials must not be stored in source-code repositories.
15. Cloud Infrastructure
Access to cloud infrastructure must be authorized and controlled.
Users must:
- Use individual accounts where technically feasible.
- Use MFA for privileged access.
- Follow least-privilege principles.
- Use approved administrative mechanisms.
- Protect cloud credentials.
- Avoid making unauthorized production changes.
- Follow change-management requirements.
AWS Example
A developer should not directly modify a production AWS security group simply because they technically have access.
Where the change is required:
Request → Assess → Approve → Change → Verify → Record
should be followed according to the organization’s change-management process.
16. Removable Media
Use of removable media should be restricted according to information security requirements.
Where removable media is authorized:
- Use approved devices.
- Protect sensitive information.
- Encrypt sensitive information where required.
- Scan media where appropriate.
- Do not use unknown USB devices.
- Securely dispose of media when no longer required.
Users should not connect unknown USB devices to organizational systems.
17. Remote Working
When working remotely, users should:
- Use secure network connections.
- Protect company devices.
- Prevent unauthorized persons from viewing confidential information.
- Avoid discussing sensitive information where it can be overheard.
- Use approved remote-access mechanisms.
- Lock devices when unattended.
- Report lost or stolen equipment.
Public Wi-Fi should be used only in accordance with organizational security requirements.
18. Physical Security
Users must protect physical information and devices.
Examples include:
- Laptops
- Mobile phones
- USB devices
- Printed documents
- Access cards
- Security tokens
Users should not leave confidential information unattended in public areas.
Where applicable, users should follow clean-desk and clear-screen requirements.
19. Prohibited Activities
Unless specifically authorized, users must not:
- Access another person’s account.
- Attempt to bypass security controls.
- Perform unauthorized vulnerability scanning.
- Conduct unauthorized penetration testing.
- Introduce malware.
- Disable security software.
- Circumvent monitoring.
- Conduct unauthorized network interception.
- Obtain credentials belonging to others.
- Modify production systems without authorization.
- Copy confidential information for personal use.
- Upload restricted information to unauthorized services.
- Use company resources for illegal activities.
- Conduct activities that could damage the organization’s reputation or systems.
20. Security Testing
Security testing must be authorized before being performed.
Employees and contractors must not independently perform:
- Penetration testing
- Vulnerability scanning
- Port scanning
- Exploitation testing
- Social engineering
- Denial-of-service testing
- Credential testing
against organizational or third-party systems unless the activity is formally authorized and appropriately scoped.
Example
A developer should not run a penetration-testing tool against a customer’s production environment simply because they are investigating an issue.
Testing should follow:
Authorization → Scope → Test → Record Results → Remediate → Retest
21. Monitoring and Logging
The organization may monitor the use of organizational systems where permitted by applicable law and organizational requirements.
Monitoring may include:
- Authentication activity
- Administrative activity
- Security events
- Network activity
- Endpoint activity
- Cloud activity
- Application activity
- Data access
- Security alerts
Monitoring should be performed for legitimate purposes such as:
- Security
- Incident investigation
- Troubleshooting
- Compliance
- System protection
- Fraud prevention
Applicable privacy and legal requirements should be considered when implementing monitoring.
22. Privacy and Personal Data
Users must handle personal data according to applicable privacy requirements and organizational policies.
Users should:
- Access personal data only when required.
- Avoid unnecessary copying.
- Use approved systems.
- Protect personal data from unauthorized disclosure.
- Follow retention and deletion requirements.
- Report suspected data breaches.
23. Intellectual Property and Licensing
Users must respect:
- Copyright
- Software licenses
- Customer intellectual property
- Third-party intellectual property
- Organizational intellectual property
- Confidentiality obligations
Users must not use pirated software or unauthorized copyrighted material for business purposes.
24. Third-Party Access
Third parties may access organizational systems only when:
- Access is authorized.
- Business need is established.
- Appropriate security requirements are satisfied.
- Access is limited to required resources.
- Access is monitored where appropriate.
- Access is removed when no longer required.
Third-party users should not share organizational credentials.
25. Data Transfer and Sharing
Before transferring confidential or restricted information, users should verify:
- What information is being transferred?
- What is its classification?
- Who is receiving it?
- Is the recipient authorized?
- Is the transfer method approved?
- Is encryption required?
- Is there a contractual or legal restriction?
Users should use approved secure-transfer mechanisms for sensitive information.
26. Personal Use
The organization may permit limited personal use of certain resources, subject to management approval and security requirements.
Personal use must not:
- Interfere with work.
- Create security risks.
- Consume excessive resources.
- Violate law or organizational policies.
- Introduce unauthorized software.
- Involve inappropriate or prohibited activities.
The organization may prohibit personal use for particular systems or assets.
27. Security Incident Reporting
Users must promptly report suspected security incidents.
Examples include:
- Lost or stolen device
- Phishing email
- Accidental data disclosure
- Malware
- Suspicious login
- Credential compromise
- Unauthorized access
- Data sent to the wrong recipient
- Lost security token
- Unapproved software installation
- Suspicious cloud activity
Users should not attempt to conceal a security incident.
Reporting Flow
Detect → Stop/Contain if Safe → Report → Record → Assess → Investigate → Respond → Learn
28. Exceptions
Exceptions to this policy must be:
- Business justified.
- Risk assessed.
- Approved by an authorized person.
- Documented.
- Time-bound where appropriate.
- Reviewed periodically.
Example:
A security engineer may temporarily require elevated privileges for an emergency production incident.
The exception should document:
- Reason
- Scope
- Duration
- Risk
- Compensating controls
- Approver
- Closure
29. Non-Compliance
Failure to comply with this policy may result in:
- Security investigation
- Access restriction
- Additional training
- Corrective action
- Disciplinary action
- Contractual action
- Legal action where applicable
The response should be proportionate to the circumstances and consistent with applicable organizational procedures.
30. Roles and Responsibilities
Management
- Approve the policy.
- Provide resources.
- Support enforcement.
Security/ISMS Manager
- Maintain the policy.
- Provide guidance.
- Monitor compliance.
- Coordinate awareness.
- Support investigations.
IT/Cloud/Engineering
- Implement technical controls.
- Manage systems and access.
- Support monitoring and security.
HR
- Include acceptable-use requirements in employee onboarding.
- Support disciplinary processes where applicable.
- Coordinate offboarding requirements.
Managers
- Ensure team members understand applicable requirements.
- Approve access and exceptions where authorized.
Employees and Contractors
- Follow this policy.
- Protect organizational resources.
- Report security concerns.
- Complete required security awareness training.
Third Parties
- Follow applicable organizational security requirements.
- Use access only for authorized purposes.
- Report incidents.
31. Awareness and Training
Users should receive acceptable-use and information-security awareness training.
Training should cover:
- Password and MFA security
- Phishing
- Data handling
- Device security
- Remote working
- Cloud and SaaS usage
- AI tool usage
- Incident reporting
- Social engineering
- Secure information sharing
Training should be provided during onboarding and periodically thereafter, based on organizational requirements.
32. Acceptable vs Unacceptable Use
| Acceptable | Unacceptable |
|---|---|
| Using approved SaaS applications | Using unauthorized SaaS for confidential data |
| Using MFA | Sharing MFA approvals |
| Accessing required customer information | Browsing unrelated customer records |
| Using approved cloud environments | Creating unauthorized production resources |
| Reporting phishing | Ignoring or forwarding phishing |
| Using licensed software | Installing pirated software |
| Authorized security testing | Unauthorized penetration testing |
| Securely sharing customer data | Sending customer data to personal email |
| Using approved AI tools | Uploading restricted information to unapproved AI tools |
| Locking devices | Leaving unlocked devices unattended |
33. AWS SaaS Startup Example
Consider a 30-person SaaS startup operating primarily in AWS.
Employees may:
- Access AWS resources according to their role.
- Use approved GitHub repositories.
- Use approved collaboration tools.
- Access customer information required for their role.
- Use approved AI tools within defined data-handling restrictions.
- Work remotely using approved security controls.
Employees may not:
- Share AWS credentials.
- Copy production customer data to personal storage.
- Create unauthorized AWS accounts/resources.
- Disable CloudTrail or security monitoring.
- Upload customer data to an unapproved AI service.
- Directly modify production without authorization.
- Use personal GitHub repositories for company source code.
The policy therefore converts general security expectations into everyday user behavior.
34. Audit Evidence
Evidence may include:
- Approved Acceptable Use Policy
- Employee acknowledgements
- Security awareness records
- Acceptable-use training
- Access-control records
- Software approval records
- SaaS approval records
- Security monitoring logs
- Incident reports
- Exception records
- Disciplinary/corrective-action records where appropriate
- Device management records
- Cloud access records
An auditor may sample employees and verify:
Policy → Awareness → User Acknowledgement → Actual Controls → Monitoring → Incident/Exception Handling
35. Common Mistakes
Mistake 1 — Making the policy only about internet browsing
Acceptable use covers information, devices, cloud, SaaS, applications, credentials, AI tools, data sharing, and security activities.
Mistake 2 — Making it excessively restrictive
The policy should establish realistic security expectations rather than prohibit ordinary business activities unnecessarily.
Mistake 3 — Ignoring cloud and SaaS
Modern startups rely heavily on cloud services and SaaS applications.
Mistake 4 — Ignoring AI tools
Employees may unintentionally expose confidential information through public AI services.
Mistake 5 — No incident-reporting requirement
Users need a clear mechanism for reporting mistakes and suspicious activity.
Mistake 6 — No distinction between authorized and unauthorized security testing
Employees should understand that technical ability does not automatically constitute authorization.
Mistake 7 — Policy without awareness
A policy is much more effective when users understand what is expected of them.
36. Relationship with Other ISMS Documents
The Acceptable Use Policy should connect with:
Information Security Policy
→ Overall security direction
Information & Asset Inventory
→ What resources users are expected to protect
Asset Classification Procedure
→ How information should be handled
Access Control Policy
→ Who can access systems and information
Security Awareness Policy
→ How users are trained
Incident Management Procedure
→ What users should do when something goes wrong
Data Protection/Privacy Policy
→ How personal information should be handled
Change Management
→ How production changes are controlled
Secure Development Policy
→ How developers use development resources
Supplier Security
→ How third-party users are controlled
Employee Joiner-Mover-Leaver Process
→ How access and assets are managed throughout employment
The relationship is:
User → Asset → Information → Authorized Use → Security Controls → Monitoring → Incident Reporting → Improvement
37. Quick Audit Checklist
| Check | Yes/No | Evidence |
|---|---|---|
| Is an Acceptable Use Policy approved? | ||
| Does it cover employees and relevant third parties? | ||
| Are organizational devices covered? | ||
| Are cloud and SaaS services covered? | ||
| Are information-handling requirements defined? | ||
| Are password/MFA responsibilities defined? | ||
| Are prohibited activities documented? | ||
| Is unauthorized security testing addressed? | ||
| Are AI tools addressed where relevant? | ||
| Are remote-working requirements addressed? | ||
| Are removable media requirements addressed? | ||
| Is software installation controlled? | ||
| Is incident reporting defined? | ||
| Are exceptions documented? | ||
| Is monitoring addressed appropriately? | ||
| Are users trained? | ||
| Are policy acknowledgements retained? | ||
| Is the policy periodically reviewed? | ||
| Are actual practices consistent with the policy? |
38. Policy Review
This policy should be reviewed periodically and whenever significant changes occur, such as:
- New technology
- New cloud services
- Significant changes in remote working
- Introduction of AI tools
- New regulatory requirements
- Major security incidents
- Changes to business operations
- Significant changes in the organization’s risk profile
Changes should be approved by the designated authority.
39. Final Principle
An Acceptable Use Policy should answer one simple question:
How should people use the organization’s information and technology without creating unnecessary security risk?
The practical model is:
Understand → Authorize → Use Securely → Protect → Monitor → Report → Correct → Learn → Improve
The objective is not to prevent employees from using technology. It is to ensure that technology, information, cloud services, and organizational resources are used responsibly, securely, and only for authorized purposes.
