# Acceptable Use Policy (AUP)

> ISO/IEC 27001:2022 A.5.10 – rules for acceptable use of information
> and assets. Every employee/contractor signs acknowledgment.

| Field | Value |
|-------|-------|
| Document ID | POL-AUP-001 |
| Applies to | All staff + contractors |
| Approved by | Management |
| Effective | YYYY-MM-DD |

## 1. Purpose

Define acceptable and prohibited use of organizational information
assets (devices, networks, data, services) to protect CIA.

## 2. General rules

- Use assets for authorized business purposes only
- Follow classification handling rules for all data accessed
- No sharing credentials; MFA mandatory
- Report suspected incidents immediately (per DOC-ISMS-020)

## 3. Acceptable use

| Category | Allowed | Conditions |
|----------|---------|------------|
| Work devices | business tasks + limited personal use | no policy violations |
| Email | business communication | no sensitive data unencrypted |
| Internet | work + reasonable personal browsing | no prohibited content |
| Software | approved list only | IT installs; no self-installed |
| Cloud services | sanctioned SaaS only | data classification rules apply |
| Remote work | VPN + encrypted device | no public Wi-Fi without VPN |

## 4. Prohibited activities

- Unauthorized access to systems/data (even within own permissions)
- Copying Restricted data to personal devices/accounts
- Disabling security controls (MDM, AV, encryption)
- Using unapproved software/services for work data
- Bypassing monitoring or logging
- Sharing Restricted/Confidential data externally without approval

## 5. Monitoring notice

Organization may monitor usage for security and compliance –
disclosed as required by applicable law.

## 6. Violations

Consequences: warning through termination; may include legal action.

## 7. Acknowledgment

I have read and agree to this policy.

Signed: ______________ Date: ________ Name: ______________
