Policies / Policy

Acceptable Use Policy

A plain-language policy for responsible use of systems and shared resources.

Type: PolicyTypical time: Review quarterly

Template

  1. Users must access only systems, data, and resources they are authorized to use.
  2. Shared resources must not be used for illegal, abusive, intentionally disruptive, or unrelated high-risk activity.
  3. Credentials must not be shared, reused across unsafe contexts, or stored in public locations.
  4. Users are responsible for reporting suspected compromise, misuse, or accidental exposure.
  5. Administrative access should be limited to people with a current operational need.
  6. Activity may be reviewed where needed for security, reliability, or policy enforcement.
  7. Exceptions should be documented with owner, scope, and expiration date.

Expected output

A concise policy statement adaptable to local requirements.

Use notes

OwnerAssign one person responsible for keeping the template current.
ReviewReview after significant changes, incidents, staffing changes, or tool changes.
RiskAdapt the template to local policies, contractual duties, privacy requirements, and operational risk.