Acceptable Use Policy (AUP)
AUP – allowed/prohibited, acknowledgment
使い方: Needs the signed acknowledgment line; an unsigned AUP can't be enforced.
プレビュー
Acceptable Use Policy (AUP)
ISO/IEC 27001:2022 A.5.10 – rules for acceptable use of information and assets. Every employee/contractor signs acknowledgment.
| Field | Value |
|---|---|
| Document ID | POL-AUP-001 |
| Applies to | All staff + contractors |
| Approved by | Management |
| Effective | YYYY-MM-DD |
1. Purpose
Define acceptable and prohibited use of organizational information assets (devices, networks, data, services) to protect CIA.
2. General rules
- Use assets for authorized business purposes only
- Follow classification handling rules for all data accessed
- No sharing credentials; MFA mandatory
- Report suspected incidents immediately (per DOC-ISMS-020)
3. Acceptable use
| Category | Allowed | Conditions |
|---|---|---|
| Work devices | business tasks + limited personal use | no policy violations |
| business communication | no sensitive data unencrypted | |
| Internet | work + reasonable personal browsing | no prohibited content |
| Software | approved list only | IT installs; no self-installed |
| Cloud services | sanctioned SaaS only | data classification rules apply |
| Remote work | VPN + encrypted device | no public Wi-Fi without VPN |
4. Prohibited activities
- Unauthorized access to systems/data (even within own permissions)
- Copying Restricted data to personal devices/accounts
- Disabling security controls (MDM, AV, encryption)
- Using unapproved software/services for work data
- Bypassing monitoring or logging
- Sharing Restricted/Confidential data externally without approval
5. Monitoring notice
Organization may monitor usage for security and compliance – disclosed as required by applicable law.
6. Violations
Consequences: warning through termination; may include legal action.
7. Acknowledgment
I have read and agree to this policy.
Signed: ______________ Date: ________ Name: ______________