
What is an acceptable use policy?
An acceptable use policy, or AUP, is a workplace policy that sets rules for how authorized users may use an organization’s technology resources, that usually includes systems, networks, accounts, devices, applications, internet access, email, collaboration tools, remote access, cloud services, and organizational data.
A practical AUP does three things:
- Defines permitted, restricted, and prohibited use.
- Sets user responsibilities, such as protecting credentials, handling data appropriately, and reporting suspected incidents.
- Creates a record that users received and acknowledged the rules that apply to their access.
NIST describes “rules of behavior” and user acknowledgement as security controls for information systems, including acknowledgement after updates where appropriate (NIST SP 800-53 Rev. 5). An AUP should not be treated as a substitute for legal advice, HR procedures, access controls, security training, or technical safeguards. It documents expected behavior and supports a broader security and governance program.
Who needs an acceptable use policy, and who should it apply to?
Organizations that give people access to company systems, networks, applications, devices, data, or internet services may basically use an AUP to explain what that access allows and what it does not. This is especially useful when users can work remotely, connect personal devices, install software, use collaboration tools, access sensitive information, or interact with third-party platforms.
A workplace AUP may apply to:
- Employees.
- Contractors and consultants.
- Temporary workers and interns.
- Vendors or service providers with system access.
- Guests or other authorized users with limited access.
Do not assume every group should sign the same document. Determine the applicable policy, contract language, or access terms based on the person’s role, level of access, employment or supplier relationship, and local requirements. Security, HR, Legal, Privacy, Compliance, and Procurement should review this scoping before adoption.
Workplace AUPs are different from adjacent documents:
- A school or student AUP focuses on student access, safeguarding, and educational use.
- A university AUP often covers academic networks, research systems, and institutional users.
- A SaaS or customer acceptable-use policy governs how customers may use a provider’s service.
- A workplace AUP governs internal use of organizational technology and data.
Acceptable use policy checklist: the clauses to include
Use the following as an annotated drafting checklist, not as a legally complete template. Adapt it with Security, IT, HR, Legal, Privacy, and Compliance review before adoption.
| Policy section | What it should cover | Drafting prompt or clause direction | Owner/reviewer |
|---|---|---|---|
| Purpose and objective | Why the policy exists | State that the policy defines appropriate use of organizational technology, systems, networks, data, and accounts. Avoid promising that the policy alone prevents incidents or ensures compliance. | Security, IT, Compliance |
| Scope and covered users | Who must follow it | Define whether it applies to employees, contractors, temporary workers, interns, vendors, guests, or other authorized users. For third parties, align with contracts and access terms. | HR, Legal, Procurement, Security |
| Covered resources | What the rules apply to | Include company-owned and approved systems, accounts, devices, networks, applications, internet access, cloud services, remote access tools, collaboration platforms, and organizational data. | IT, Security |
| User responsibilities | Baseline expectations | Require users to follow the policy, use access only for authorized purposes, protect assigned resources, and report suspected misuse or incidents. | Security, HR |
| Acceptable use | Normal permitted activity | Describe business use that supports assigned work, complies with policy, and respects security, confidentiality, and professional conduct expectations. | HR, Security |
| Restricted use requiring approval | Activity allowed only under conditions | Identify actions that require approval, such as using personal devices, external file-sharing tools, new software, administrative access, or certain AI tools. | IT, Security, Privacy |
| Prohibited use | Activity not allowed | Prohibit unauthorized access, credential sharing, bypassing controls, malicious activity, harassment, illegal activity, unauthorized data sharing, and disruption of systems or networks. | Legal, HR, Security |
| Credential and access security | Account protection | Cover password or passphrase expectations, multi-factor authentication where applicable, no shared accounts unless approved, and prompt reporting of suspected compromise. | IT, Security |
| Data handling and confidentiality | How users may handle information | Reference data classification, confidentiality, approved storage locations, external sharing rules, and restrictions on uploading sensitive data to unapproved services. | Privacy, Legal, Security |
| Software, downloads, and tools | Use of applications and services | Require approved software and licensed tools. Address unapproved downloads, browser extensions, shadow IT, and unauthorized cloud services. | IT, Security, Legal |
| Email, messaging, internet, and collaboration tools | Everyday communication channels | Set expectations for professional use, phishing caution, approved business channels, external sharing, and retention or recordkeeping requirements where relevant. | IT, HR, Compliance |
| BYOD and remote work references | Personal devices and offsite access | Cross-reference BYOD, mobile device, and remote work policies. Address secure connections, device protection, screen privacy, and reporting lost or stolen devices. | IT, Security, HR |
| AI-use expectations | Use of generative AI or automated tools | Where relevant, cross-reference approved AI-use rules and data-handling requirements. Clarify whether sensitive, confidential, customer, or regulated data may be entered into AI tools. | Security, Privacy, Legal |
| Monitoring and privacy notice | Visibility into use of systems | Explain what activity may be logged or reviewed, why monitoring occurs, and how monitoring relates to security, operations, compliance, or investigations. Review wording for applicable privacy law. | Privacy, Legal, Security |
| Exceptions and approvals | How deviations are handled | Define who can approve exceptions, what information is required, how risk is assessed, how long exceptions last, and where records are kept. | Security, Compliance, IT |
| Violations and response | What happens when rules are broken | State that violations may lead to access changes, investigation, training, HR review, contractual action, or other response based on severity, context, and applicable requirements. | HR, Legal, Security |
| Acknowledgement | Evidence that users received the policy | Require users to acknowledge the policy before or when access is granted, and re-acknowledge after material updates where appropriate. | HR, IT, Compliance |
| Review and updates | Keeping the policy current | Assign an owner and review the policy periodically or when tools, risks, work patterns, laws, or organizational requirements change. | Security, Compliance, Legal |
Security-related policies should reflect organizational context and be communicated, enforced, reviewed, and updated as requirements, threats, technology, and the organization’s mission change (NIST Cybersecurity Framework 2.0). That makes the checklist a starting point for policy design, not a one-time drafting exercise.
How to define acceptable, restricted, and prohibited use
The most useful AUPs separate behavior into three categories. This helps users understand not just what is banned, but what is allowed and what requires approval.
Acceptable use
Acceptable use is normal business use that supports the user’s role and follows organizational policy. Examples include:
- Using approved applications to perform assigned work.
- Accessing systems and data the user is authorized to use.
- Communicating with colleagues, customers, and partners through approved channels.
- Using company internet access for reasonable work-related research.
- Reporting suspicious emails, lost devices, or suspected account compromise.
Restricted use
Restricted use may be allowed only with approval, specific controls, or defined conditions. Examples include:
- Connecting a personal device to company systems.
- Using external cloud storage or file-transfer tools.
- Installing new software, browser extensions, or developer tools.
- Accessing systems from unusual locations or unmanaged networks.
- Using generative AI tools for work tasks.
- Sharing data with vendors, consultants, or external collaborators.
- Using administrative privileges or service accounts.
This category is useful because not every risky activity should be banned. Some activities may be appropriate. When the business need, data type, approval path, and safeguards are clear.
Prohibited use
Prohibited use should be specific enough that users and managers can recognize violations. Common categories include:
- Attempting unauthorized access to systems, accounts, data, or networks.
- Sharing passwords, tokens, MFA prompts, or other credentials.
- Bypassing security controls or disabling required protections.
- Installing unapproved software or using unauthorized services to process company data.
- Using company systems for illegal, malicious, fraudulent, or deceptive activity.
- Harassment, abusive communication, threats, or discriminatory conduct through workplace systems.
- Copying, distributing, or using content in a way that violates applicable law or organizational policy.
- Sharing confidential, customer, employee, regulated, or proprietary data without authorization.
- Disrupting systems, networks, services, or other users’ access.
- Uploading sensitive organizational data into unapproved AI, collaboration, or cloud tools.
Avoid vague language such as “inappropriate use is forbidden” without examples. Users need enough detail to make daily decisions, and managers need enough structure to respond consistently.
How to roll out, acknowledge, enforce, and review an AUP
An AUP only works operationally—really, works in day-to-day use—if people receive it, understand it, acknowledge it, and know how exceptions and violations will be handled. NIST CSF 2.0 includes awareness and training, access permission management, data protection, prevention of unauthorized software, and monitoring for potentially adverse events as cybersecurity outcomes; an AUP should be accompanied by these practical safeguards rather than treated as the safeguard itself (NIST Cybersecurity Framework 2.0).
A concise rollout workflow looks like this:
- Assign ownership. Name a policy owner, usually in Security, IT, Compliance, or Operations, with HR and Legal involvement.
- Draft with cross-functional input. Include Security, IT, HR, Legal, Privacy, Compliance, Procurement, and business owners where relevant.
- Review sensitive clauses carefully. Pay particular attention to monitoring, privacy, disciplinary response, contractor access, BYOD, remote work, and AI-use language.
- Communicate the policy in plain language. Explain what changed, who it applies to, when it takes effect, and where to ask questions.
- Train users on the highest-risk examples. Focus on credentials, phishing, data sharing, approved tools, remote access, AI use where relevant, and incident reporting.
- Collect acknowledgement. Record that covered users received and acknowledged the policy. Reconfirm acknowledgement after material updates where appropriate.
- Define exception handling. Use a documented, risk-aware process for exceptions, with an approver, expiry date, conditions, and record of the decision.
- Enforce proportionately. Combine reminders, training, access controls, logging where appropriate, manual review, HR escalation, and documented decisions based on severity and context.
- Maintain records. Keep current policy versions, acknowledgement records, exception approvals, review notes, and update history.
- Review regularly and after material change. Revisit the AUP when tools, work patterns, risks, legal requirements, or organizational responsibilities change.
Monitoring deserves special care. If worker monitoring is in scope, the policy should describe it clearly, state its purpose, and keep measures proportionate to the aim. In UK data-protection contexts, workers generally must be informed about monitoring, subject to narrow exceptions (UK Information Commissioner’s Office). Other jurisdictions may differ, so monitoring notice, lawful basis, retention, covert monitoring, and use in disciplinary processes should be reviewed by Legal and Privacy.
Enforcement does not require a specific monitoring product. Basically, a vendor-neutral approach can include communication, training, role-based access, approval workflows, logging, documented review, and escalation through HR or Legal when needed.
How an AUP fits with your broader compliance and security program
An AUP should fit with related policies, not absorb them. Keep it practical and focused on user behavior and cross-reference more detailed policies where needed, such as:
- Information security policy.
- Data classification or data handling policy.
- BYOD and mobile device policy.
- Remote work policy.
- AI acceptable use policy.
- Incident reporting process.
- Vendor access or third-party risk procedures.
- HR disciplinary procedures.
The policy should reflect how systems actually work. If users rely on unmanaged file-sharing, personal devices, informal AI tools, or ad hoc vendor access, the AUP should not pretend those risks do not exist. It should either route them into approved processes or clearly restrict them.
This is where policy maintenance becomes a practical compliance activity: assign ownership, keep acknowledgement evidence, record exceptions, review access-related controls, and update the policy when the environment changes. Ciphrix approaches this from an operational perspective: policies, controls, acknowledgements, exceptions, and evidence should be maintained as part of a practical compliance system rather than stored as static documents.
A usable AUP is not the longest policy. It is the one users can understand, acknowledge, and follow—and that the organization can review, evidence, and enforce in a proportionate way, in practice.
