Policies, Procedures & FormsFree

Acceptable Use Policy (AUP) Template

Ground rules for company devices, networks, email, and internet use — including prohibited activities, user responsibilities, and consequences, aligned with ISO 27001 control A.5.10.

In short

An Acceptable Use Policy (AUP) sets the boundaries for how personnel may use organisational devices, networks, email, and information — what is permitted, what is prohibited, and the consequences of breach. ISO 27001 control A.5.10 requires such rules to be established and communicated.

Format
DOCX
Size
15 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

The AUP is the document employees most often sign and least often read. The cause is not lazy readers but the writing: eight pages of abstract prohibitions tell nobody what they may actually do that day.

This template is written in sentences that read without technical background, and organises rules around real situations: using work devices for personal matters, installing software, using work email on a personal phone, and taking data offsite. The decisive part is not the prohibition list but the explanation of why each boundary exists.

Most Useful For

  • Organisations with no written rules on device and data use
  • HR teams needing a document for the new-joiner onboarding pack
  • Companies pursuing ISO 27001 who need evidence the rules reached all personnel

What's Inside

01

Scope & bound parties

Employees, contractors, interns, and third parties using organisational assets.

02

Device & network use

Personal use limits, software installation, and connecting foreign devices.

03

Email & communication

Rules for work email use, attachment handling, and communicating on the organisation's behalf.

04

Data handling

Rules for copying, sharing, and removing information according to its classification.

05

Absolute prohibitions

Acts prohibited without exception, including credential sharing and circumventing security controls.

06

Acknowledgement & consequences

An acknowledgement page and breach consequences — the evidence that the policy was genuinely communicated.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Control A.5.10Acceptable use of information and associated assets.
ISO/IEC 27001:2022Controls A.6.2 & A.6.3Terms and conditions of employment, and information security awareness, education and training.
ISO/IEC 27001:2022Control A.5.1Topic-specific policies supporting the information security policy.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Must every employee sign the AUP?

The standard requires evidence that the rules were communicated and understood, not a signature as such. A signature — wet or electronic — is simply the easiest evidence to produce at audit, which is why this template includes an acknowledgement page.

How should personal use of work devices be handled?

A total ban is rarely realistic and hard to enforce. What lasts is setting reasonable limits and naming explicitly what is never permitted. What matters is that the boundary is written down rather than left to individual interpretation.

Is an AUP the same as an information security policy?

They sit at different levels. The information security policy states organisation-level principles and is signed by top management. The AUP translates those principles into day-to-day rules of behaviour for everyone using organisational assets.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.