ISO 27001 · the acceptable use policy
The acceptable use policy, written from a few answers
The acceptable use policy is the one document every person in the company reads and signs, so it has to be short, plain and true to how the company works; this page writes it in twelve sections from a few answers, in the company's own voice, with the rules an auditor looks for on accounts, devices, remote work, data, services, AI tools, personal use, monitoring, reporting, leaving and breaches.
The policy
Twelve sections in the order a reader meets them; an empty entry is written as a gap to fill, not skipped.
# Acceptable use policy: [company] Policy owner: [the policy owner] · Approved by: [top management] Written on with the free page on getstandardos.com against the Annex A controls of ISO/IEC 27001:2022 on the use of information and assets, authentication, endpoint devices, remote working and the return of assets. The wording is StandardOS's own, in the company's voice. ## 1. Who this applies to, and to what This policy applies to everyone who works under the control of [company] or has access to its information: employees, contractors, interns, and the staff of suppliers who hold an account with us. It covers the company's information wherever it is, every account the company gives you, every device you use for work, the company's networks and the services it subscribes to. It is short on purpose; the security policy and the procedures behind it say more, and where this document is silent, ask before you act. ## 2. Accounts and passwords - Your accounts are yours alone: never share a password, a session or a token, and never log in as somebody else. - Use the company password manager for every work password; every password is long, unique and generated, and multi-factor authentication is on wherever the service offers it. - Tell us the moment you suspect an account is compromised, and change the password after the report, not before. ## 3. Devices - Every device used for work has disk encryption on, the operating system and applications updated within days of a release, a screen lock after a short idle time, and the company's endpoint protection installed where the company provides it. - Do not disable, uninstall or work around those protections, and do not install software from outside the official stores or the approved list. - Lost or stolen devices are reported the same day so that access can be revoked and the device wiped. - Work is done on company-issued devices only; personal phones and computers are not used for work data, work accounts or work mail. ## 4. Working outside the office - Work from anywhere is allowed under the same rules: the screen is locked when you step away, confidential work is not done where the screen or the call can be seen or overheard, and devices are never left in a car. - Public networks are used only through the company VPN or with the services' own encryption; a home network has a changed router password and current firmware. - Printouts of confidential information are avoided, and where unavoidable, kept locked and destroyed when done. ## 5. Handling information - Information is confidential unless it has been published by the company: treat customer data, personal data, source code, contracts, financials and plans as confidential, and share them only with people who need them for their work. - Work data lives in the company's approved services and nowhere else: not in personal accounts, personal cloud drives, private messaging or removable media, and not in a tool the company has not approved. - Personal data is handled as the privacy notice and the record of processing say, and never more than the purpose needs. ## 6. Software, cloud services and AI tools - Use the services the company has approved; a new tool, plugin or subscription is requested before it touches work data, so that the company can assess it and put it on the list. - Connect services to each other, or grant an app access to your work account, only for approved tools; a permission prompt is a question for the owner, not a click. - Licences are respected: no pirated software, no shared seats, no use of a customer's or a former employer's material without a right to it. - The approved services are: [to be completed]. - AI assistants and generators are used only through the tools the company has approved, and confidential or personal data is never put into them unless the tool is on the approved list with that use allowed; generated output is reviewed before it goes to a customer or into the product. ## 7. Email, messaging and the web - Work mail and work messaging go through the company's accounts; auto-forwarding to a personal address is off, and a suspicious message is reported rather than answered, opened or forwarded. - Nothing illegal, harassing or discriminatory is written, sent or stored on company systems, and nothing that would embarrass the company if it were read in public. - Only the people the company has named speak for it in public, to the press or to authorities. ## 8. Personal use, and what the company can see Reasonable personal use of company devices and internet access is allowed as long as it does not interfere with work, break any rule above, cost the company money or expose it to risk; personal files are kept apart from work data and are not backed up by the company. [company] logs the use of its accounts, devices, networks and services for security and for the law, and can read those logs when investigating an incident or a suspected breach of this policy; it does not read personal messages or files, and it tells people what is logged and why. ## 9. Reporting a problem Report anything that looks wrong, at once, through [to be completed]: a suspicious message, a lost device, a mistaken send, an account behaving oddly, a rule you could not follow. Reporting early is never held against anyone; not reporting is. ## 10. Leaving On the last day, or on the day a role ends, every company device, key and card is returned, every work account is closed by the company, work data on any personal device is wiped, and confidentiality continues after leaving. ## 11. Breaches of this policy A breach of this policy is handled under the disciplinary procedure and, for contractors and suppliers, under the contract; an honest mistake reported early is treated as what it is. ## 12. Acknowledgement I have read this policy, I understand it, and I will follow it in my work for [company]. Name, date, signature: [to be completed] Approved by [top management] on [date]; owned by [the policy owner]; reviewed at least once a year and whenever the company's tools, devices or risks change. This policy is written from the answers given. It is not certification or legal advice; the certification body reads the policy for its rules, its approval and the acknowledgements, and employment law on monitoring and personal use differs by country.
In StandardOS the policy knows who has read it
The acceptable use policy in StandardOS is a versioned document beside the security policy and the incident plan, approved and reviewed on the calendar, and the awareness record shows who has read it and when, which is the list the auditor asks for.
The information security policyThe incident response planThe Annex A controls