An acceptable use policy earns its place in two moments: when someone needs to know whether something is allowed, and when someone has done something and you need to act. Most versions fail the second test, because they are vague where they need to be specific and silent on monitoring.
1. Scope and audience
Who it applies to — employees, contractors, temporary staff, third parties with access — and what it covers: company systems, company data, and personal devices used for work. Ambiguity here is what makes enforcement fail.
2. Acceptable use
State the principle plainly: systems are provided for business purposes, and users are responsible for activity under their accounts. Then be concrete about what is expected — protecting credentials, locking screens, reporting suspected incidents promptly, and using only approved services for company data.
3. Prohibited use
Specific, not moralising. Typically: sharing credentials; attempting to bypass security controls; installing unapproved software; connecting unapproved devices to corporate networks; accessing data without a business need; using company systems for illegal activity or harassment; and moving company data to personal accounts or storage.
Write prohibitions you are willing to enforce consistently. A rule that is routinely broken and never acted on undermines the whole document — and it is the first thing a defence lawyer or tribunal will point at.
4. Personal use
Say something realistic. "No personal use" is unenforceable in most workplaces and pretending otherwise weakens the policy. "Reasonable personal use is permitted provided it does not interfere with work, consume significant resources, or breach any other section" is defensible and honest.
5. Monitoring notice
The clause with genuine legal weight. State what may be monitored, on what basis, and for what purposes. In many jurisdictions monitoring without prior notice is unlawful, and evidence gathered that way may be unusable in a disciplinary process — so this section is what makes the rest actionable. Have it reviewed locally, particularly where employee representatives or works councils are involved.
Keep policies approved, current and acknowledged
GRC Copilot tracks policy versions, approvals and per-employee acknowledgements — the evidence auditors ask for most often.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
6. Devices and remote working
Cover company devices and, separately, personal devices used for work: what is required (encryption, screen lock, current OS, ability to remote-wipe company data), what is prohibited, and what happens on departure. Be explicit that enrolling a personal device grants the organisation specific rights over company data on it — people should understand that before enrolling, not after.
7. Data handling
Link to your classification scheme rather than restating it. Cover approved storage and sharing locations, sending data externally, printing, and removable media. Say plainly that company data must not be moved to personal accounts, which is the most common real-world violation.
8. AI and third-party services
The section most policies are missing. Cover which AI tools are approved, what data may and may not be entered into them, whether outputs need review before use, and that entering confidential or personal data into an unapproved service is a data disclosure.
A prohibition alone will fail — usage moves out of sight. Pair the rule with a sanctioned, genuinely easier path, and say where to request approval for something new.
9. Enforcement
State that violations may lead to disciplinary action up to dismissal, and link explicitly to the disciplinary process. Frameworks require a disciplinary process that covers security violations and that staff know about — an unpublicised one deters nobody.
10. Acknowledgement
Record who acknowledged which version and when. This is the single most requested artefact in an HR-security audit and it is trivially easy to capture at the point of acceptance — and almost impossible to reconstruct later.
Keeping it usable
Aim for a few pages of plain language. Long policies are not read, and unread policies do not change behaviour or survive a tribunal. Review annually, reissue for acknowledgement when material sections change, and make sure the version people signed is retrievable.
Frequently asked questions
Should the AUP be separate from the security policy?
Usually yes. The security policy sets organisational direction; the AUP tells individuals what is expected of them, in language they can act on.
Do we need signatures?
You need evidence of acknowledgement. An auditable click-through record is sufficient and easier to maintain than paper.
Can we monitor without saying so?
In many jurisdictions, no — and evidence obtained that way may be unusable. Give notice and take local legal advice.
How do we handle BYOD fairly?
Be explicit about what the organisation can and cannot see or erase on a personal device, and make enrolment a genuine choice where possible.
Key takeaways
- Write prohibitions you will enforce consistently.
- The monitoring notice is what makes the policy actionable — get it reviewed locally.
- Add an AI section, paired with a sanctioned easier path.
- Capture acknowledgement per version; it is the most requested HR-security artefact.