Acceptable Usage Policy

Fill in the details

The preview updates as you type.

Acceptable Usage Policy

Acceptable Usage Policy

Company Name: 
Effective Date: 
Policy Owner: 
Approved By: 
IT Department Head: 

PURPOSE & SCOPE
- This policy defines the acceptable use of the Organization's information technology resources, including computer systems, networks, email, internet access, and software applications. It establishes the standards of behavior expected of all users to protect organizational assets.
- This policy applies to all employees, contractors, consultants, temporary workers, and any other individuals who are granted access to the Organization's IT resources, regardless of their location or the device used to access those resources.
- The IT Department Head shall be responsible for the implementation, communication, and enforcement of this policy, including the monitoring of compliance and the investigation of reported violations.

ACCEPTABLE USE STANDARDS
- Organization IT resources are provided primarily for business purposes. Limited personal use is permitted provided it does not interfere with work duties, consume excessive bandwidth, or violate any provision of this policy.
- Users shall protect their authentication credentials, including passwords and multi-factor authentication tokens, and shall not share these credentials with any other person. Users are accountable for all activity conducted under their credentials.
- Users shall not install, download, or execute unauthorised software, browser extensions, or applications on Organization-owned devices without prior written approval from the IT department.

PROHIBITED ACTIVITIES
- Users shall not use Organization IT resources to access, download, store, or distribute material that is illegal, obscene, defamatory, discriminatory, harassing, or otherwise offensive. This includes but is not limited to pornographic material, hate speech, and pirated software.
- Users shall not attempt to gain unauthorised access to any system, network, account, or data to which they have not been granted access. This includes probing or testing the security of systems without explicit written authorisation from the IT department.
- Users shall not use Organization IT resources for commercial activities unrelated to the Organization's business, political campaigning, religious proselytising, gambling, or any activity that could bring the Organization into disrepute.

MONITORING & PRIVACY
- The Organization reserves the right to monitor, log, and audit the use of its IT resources to ensure compliance with this policy, detect security threats, and investigate suspected violations. Users should have no expectation of privacy when using Organization systems.
- Monitoring shall be conducted in a manner that is proportionate, lawful, and consistent with applicable privacy legislation. The Organization shall not target individual users for monitoring without reasonable cause and appropriate management authorisation.
- Monitoring logs and audit records shall be retained for a minimum of 12 months and shall be accessible only to authorised IT security personnel, management, and Legal Counsel on a need-to-know basis.

ENFORCEMENT & POLICY REVIEW
- Violations of this policy shall result in disciplinary action proportionate to the severity of the violation, up to and including termination of employment and referral to law enforcement where criminal conduct is involved.
- Users who become aware of any violation of this policy, or who suspect that Organization IT resources have been compromised, shall report the matter immediately to the IT Help Desk or the Information Security team.
- This policy shall be reviewed at least annually by the IT Department Head in consultation with the Information Security team and Legal Counsel. All users shall acknowledge acceptance of any material amendments.
The complete guide

Everything you need to know

01What Is an Acceptable Usage Policy?

An acceptable usage policy, often called an AUP, sets the rules for how employees may use company technology, including computers, networks, email, internet access, and software. It defines permitted and prohibited activities, expectations around security and personal use, and the consequences of misuse. The policy protects company systems and data by making clear, before any incident occurs, exactly what responsible use of company resources looks like for every employee.

02Why Companies Need an Acceptable Usage Policy

Company devices and networks are constant targets for security threats, and careless use is a leading cause of breaches and data loss. An AUP reduces this risk by setting clear behavioral rules, from password practices to what may not be downloaded or shared. It also protects the company legally by defining boundaries around harassment, illegal content, and confidentiality. When rules are written and acknowledged, enforcement is fair and employees cannot claim they were unaware.

03What an Acceptable Usage Policy Should Include

State the scope: which devices, networks, accounts, and users are covered. List acceptable and prohibited uses, including rules on personal use, downloading software, accessing inappropriate content, and sharing confidential data. Cover security expectations such as passwords, device locking, and reporting suspicious activity. Address monitoring, making clear the company may review usage of its systems, and the use of personal devices. End with the consequences of violations and a requirement for employees to acknowledge the policy.

Keep your hiring moving

Ready to interview your shortlist?

Send one link. Candidates record answers on their own time and AI ranks your shortlist, no scheduling, no back-and-forth.

Frequently asked questions