# Acceptable use policy

Source: https://aestech.com.au/policy-templates/#acceptable-use-policy
Markdown URL: https://aestech.com.au/policy-templates/acceptable-use-policy.md

Use for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines acceptable use of company information, devices, networks, SaaS tools, AI tools and communication systems.

2. User responsibilities
Users must:
- Protect company and customer information according to its classification.
- Use approved systems for company work.
- Lock screens when unattended.
- Report suspected security events immediately.
- Use company-approved AI tools only for permitted data types.
- Follow password, MFA and device security requirements.

3. Prohibited activity
Users must not:
- Share credentials.
- Store confidential data in unapproved tools.
- Bypass security controls.
- Install unapproved software on managed devices.
- Upload customer, source-code or confidential information to unapproved AI systems.

4. Monitoring and enforcement
The company may monitor company systems to protect security, meet legal obligations and investigate misuse. Violations may lead to access removal or disciplinary action.

Evidence: signed acknowledgements, training completion, exception approvals, monitoring records and incident tickets.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md