All posts
Continuous Compliance10 min readAug 16, 2026

Acceptable use policy

Ashish / CEO/Co-Founder
Acceptable use policy

What is an acceptable use policy?

An acceptable use policy, or AUP, is a workplace policy that sets rules for how authorized users may use an organization’s technology resources, that usually includes systems, networks, accounts, devices, applications, internet access, email, collaboration tools, remote access, cloud services, and organizational data.

A practical AUP does three things:

  • Defines permitted, restricted, and prohibited use.
  • Sets user responsibilities, such as protecting credentials, handling data appropriately, and reporting suspected incidents.
  • Creates a record that users received and acknowledged the rules that apply to their access.

NIST describes “rules of behavior” and user acknowledgement as security controls for information systems, including acknowledgement after updates where appropriate (NIST SP 800-53 Rev. 5). An AUP should not be treated as a substitute for legal advice, HR procedures, access controls, security training, or technical safeguards. It documents expected behavior and supports a broader security and governance program.

Who needs an acceptable use policy, and who should it apply to?

Organizations that give people access to company systems, networks, applications, devices, data, or internet services may basically use an AUP to explain what that access allows and what it does not. This is especially useful when users can work remotely, connect personal devices, install software, use collaboration tools, access sensitive information, or interact with third-party platforms.

A workplace AUP may apply to:

  • Employees.
  • Contractors and consultants.
  • Temporary workers and interns.
  • Vendors or service providers with system access.
  • Guests or other authorized users with limited access.

Do not assume every group should sign the same document. Determine the applicable policy, contract language, or access terms based on the person’s role, level of access, employment or supplier relationship, and local requirements. Security, HR, Legal, Privacy, Compliance, and Procurement should review this scoping before adoption.

Workplace AUPs are different from adjacent documents:

  • A school or student AUP focuses on student access, safeguarding, and educational use.
  • A university AUP often covers academic networks, research systems, and institutional users.
  • A SaaS or customer acceptable-use policy governs how customers may use a provider’s service.
  • A workplace AUP governs internal use of organizational technology and data.

Acceptable use policy checklist: the clauses to include

Use the following as an annotated drafting checklist, not as a legally complete template. Adapt it with Security, IT, HR, Legal, Privacy, and Compliance review before adoption.

Policy sectionWhat it should coverDrafting prompt or clause directionOwner/reviewer
Purpose and objectiveWhy the policy existsState that the policy defines appropriate use of organizational technology, systems, networks, data, and accounts. Avoid promising that the policy alone prevents incidents or ensures compliance.Security, IT, Compliance
Scope and covered usersWho must follow itDefine whether it applies to employees, contractors, temporary workers, interns, vendors, guests, or other authorized users. For third parties, align with contracts and access terms.HR, Legal, Procurement, Security
Covered resourcesWhat the rules apply toInclude company-owned and approved systems, accounts, devices, networks, applications, internet access, cloud services, remote access tools, collaboration platforms, and organizational data.IT, Security
User responsibilitiesBaseline expectationsRequire users to follow the policy, use access only for authorized purposes, protect assigned resources, and report suspected misuse or incidents.Security, HR
Acceptable useNormal permitted activityDescribe business use that supports assigned work, complies with policy, and respects security, confidentiality, and professional conduct expectations.HR, Security
Restricted use requiring approvalActivity allowed only under conditionsIdentify actions that require approval, such as using personal devices, external file-sharing tools, new software, administrative access, or certain AI tools.IT, Security, Privacy
Prohibited useActivity not allowedProhibit unauthorized access, credential sharing, bypassing controls, malicious activity, harassment, illegal activity, unauthorized data sharing, and disruption of systems or networks.Legal, HR, Security
Credential and access securityAccount protectionCover password or passphrase expectations, multi-factor authentication where applicable, no shared accounts unless approved, and prompt reporting of suspected compromise.IT, Security
Data handling and confidentialityHow users may handle informationReference data classification, confidentiality, approved storage locations, external sharing rules, and restrictions on uploading sensitive data to unapproved services.Privacy, Legal, Security
Software, downloads, and toolsUse of applications and servicesRequire approved software and licensed tools. Address unapproved downloads, browser extensions, shadow IT, and unauthorized cloud services.IT, Security, Legal
Email, messaging, internet, and collaboration toolsEveryday communication channelsSet expectations for professional use, phishing caution, approved business channels, external sharing, and retention or recordkeeping requirements where relevant.IT, HR, Compliance
BYOD and remote work referencesPersonal devices and offsite accessCross-reference BYOD, mobile device, and remote work policies. Address secure connections, device protection, screen privacy, and reporting lost or stolen devices.IT, Security, HR
AI-use expectationsUse of generative AI or automated toolsWhere relevant, cross-reference approved AI-use rules and data-handling requirements. Clarify whether sensitive, confidential, customer, or regulated data may be entered into AI tools.Security, Privacy, Legal
Monitoring and privacy noticeVisibility into use of systemsExplain what activity may be logged or reviewed, why monitoring occurs, and how monitoring relates to security, operations, compliance, or investigations. Review wording for applicable privacy law.Privacy, Legal, Security
Exceptions and approvalsHow deviations are handledDefine who can approve exceptions, what information is required, how risk is assessed, how long exceptions last, and where records are kept.Security, Compliance, IT
Violations and responseWhat happens when rules are brokenState that violations may lead to access changes, investigation, training, HR review, contractual action, or other response based on severity, context, and applicable requirements.HR, Legal, Security
AcknowledgementEvidence that users received the policyRequire users to acknowledge the policy before or when access is granted, and re-acknowledge after material updates where appropriate.HR, IT, Compliance
Review and updatesKeeping the policy currentAssign an owner and review the policy periodically or when tools, risks, work patterns, laws, or organizational requirements change.Security, Compliance, Legal

Security-related policies should reflect organizational context and be communicated, enforced, reviewed, and updated as requirements, threats, technology, and the organization’s mission change (NIST Cybersecurity Framework 2.0). That makes the checklist a starting point for policy design, not a one-time drafting exercise.

How to define acceptable, restricted, and prohibited use

The most useful AUPs separate behavior into three categories. This helps users understand not just what is banned, but what is allowed and what requires approval.

Acceptable use

Acceptable use is normal business use that supports the user’s role and follows organizational policy. Examples include:

  • Using approved applications to perform assigned work.
  • Accessing systems and data the user is authorized to use.
  • Communicating with colleagues, customers, and partners through approved channels.
  • Using company internet access for reasonable work-related research.
  • Reporting suspicious emails, lost devices, or suspected account compromise.

Restricted use

Restricted use may be allowed only with approval, specific controls, or defined conditions. Examples include:

  • Connecting a personal device to company systems.
  • Using external cloud storage or file-transfer tools.
  • Installing new software, browser extensions, or developer tools.
  • Accessing systems from unusual locations or unmanaged networks.
  • Using generative AI tools for work tasks.
  • Sharing data with vendors, consultants, or external collaborators.
  • Using administrative privileges or service accounts.

This category is useful because not every risky activity should be banned. Some activities may be appropriate. When the business need, data type, approval path, and safeguards are clear.

Prohibited use

Prohibited use should be specific enough that users and managers can recognize violations. Common categories include:

  • Attempting unauthorized access to systems, accounts, data, or networks.
  • Sharing passwords, tokens, MFA prompts, or other credentials.
  • Bypassing security controls or disabling required protections.
  • Installing unapproved software or using unauthorized services to process company data.
  • Using company systems for illegal, malicious, fraudulent, or deceptive activity.
  • Harassment, abusive communication, threats, or discriminatory conduct through workplace systems.
  • Copying, distributing, or using content in a way that violates applicable law or organizational policy.
  • Sharing confidential, customer, employee, regulated, or proprietary data without authorization.
  • Disrupting systems, networks, services, or other users’ access.
  • Uploading sensitive organizational data into unapproved AI, collaboration, or cloud tools.

Avoid vague language such as “inappropriate use is forbidden” without examples. Users need enough detail to make daily decisions, and managers need enough structure to respond consistently.

How to roll out, acknowledge, enforce, and review an AUP

An AUP only works operationally—really, works in day-to-day use—if people receive it, understand it, acknowledge it, and know how exceptions and violations will be handled. NIST CSF 2.0 includes awareness and training, access permission management, data protection, prevention of unauthorized software, and monitoring for potentially adverse events as cybersecurity outcomes; an AUP should be accompanied by these practical safeguards rather than treated as the safeguard itself (NIST Cybersecurity Framework 2.0).

A concise rollout workflow looks like this:

  1. Assign ownership. Name a policy owner, usually in Security, IT, Compliance, or Operations, with HR and Legal involvement.
  2. Draft with cross-functional input. Include Security, IT, HR, Legal, Privacy, Compliance, Procurement, and business owners where relevant.
  3. Review sensitive clauses carefully. Pay particular attention to monitoring, privacy, disciplinary response, contractor access, BYOD, remote work, and AI-use language.
  4. Communicate the policy in plain language. Explain what changed, who it applies to, when it takes effect, and where to ask questions.
  5. Train users on the highest-risk examples. Focus on credentials, phishing, data sharing, approved tools, remote access, AI use where relevant, and incident reporting.
  6. Collect acknowledgement. Record that covered users received and acknowledged the policy. Reconfirm acknowledgement after material updates where appropriate.
  7. Define exception handling. Use a documented, risk-aware process for exceptions, with an approver, expiry date, conditions, and record of the decision.
  8. Enforce proportionately. Combine reminders, training, access controls, logging where appropriate, manual review, HR escalation, and documented decisions based on severity and context.
  9. Maintain records. Keep current policy versions, acknowledgement records, exception approvals, review notes, and update history.
  10. Review regularly and after material change. Revisit the AUP when tools, work patterns, risks, legal requirements, or organizational responsibilities change.

Monitoring deserves special care. If worker monitoring is in scope, the policy should describe it clearly, state its purpose, and keep measures proportionate to the aim. In UK data-protection contexts, workers generally must be informed about monitoring, subject to narrow exceptions (UK Information Commissioner’s Office). Other jurisdictions may differ, so monitoring notice, lawful basis, retention, covert monitoring, and use in disciplinary processes should be reviewed by Legal and Privacy.

Enforcement does not require a specific monitoring product. Basically, a vendor-neutral approach can include communication, training, role-based access, approval workflows, logging, documented review, and escalation through HR or Legal when needed.

How an AUP fits with your broader compliance and security program

An AUP should fit with related policies, not absorb them. Keep it practical and focused on user behavior and cross-reference more detailed policies where needed, such as:

  • Information security policy.
  • Data classification or data handling policy.
  • BYOD and mobile device policy.
  • Remote work policy.
  • AI acceptable use policy.
  • Incident reporting process.
  • Vendor access or third-party risk procedures.
  • HR disciplinary procedures.

The policy should reflect how systems actually work. If users rely on unmanaged file-sharing, personal devices, informal AI tools, or ad hoc vendor access, the AUP should not pretend those risks do not exist. It should either route them into approved processes or clearly restrict them.

This is where policy maintenance becomes a practical compliance activity: assign ownership, keep acknowledgement evidence, record exceptions, review access-related controls, and update the policy when the environment changes. Ciphrix approaches this from an operational perspective: policies, controls, acknowledgements, exceptions, and evidence should be maintained as part of a practical compliance system rather than stored as static documents.

A usable AUP is not the longest policy. It is the one users can understand, acknowledge, and follow—and that the organization can review, evidence, and enforce in a proportionate way, in practice.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents