Acceptable Use Policy (AUP) Template
Ground rules for company devices, networks, email, and internet use — including prohibited activities, user responsibilities, and consequences, aligned with ISO 27001 control A.5.10.
In short
An Acceptable Use Policy (AUP) sets the boundaries for how personnel may use organisational devices, networks, email, and information — what is permitted, what is prohibited, and the consequences of breach. ISO 27001 control A.5.10 requires such rules to be established and communicated.
- Format
- DOCX
- Size
- 15 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
The AUP is the document employees most often sign and least often read. The cause is not lazy readers but the writing: eight pages of abstract prohibitions tell nobody what they may actually do that day.
This template is written in sentences that read without technical background, and organises rules around real situations: using work devices for personal matters, installing software, using work email on a personal phone, and taking data offsite. The decisive part is not the prohibition list but the explanation of why each boundary exists.
Most Useful For
- Organisations with no written rules on device and data use
- HR teams needing a document for the new-joiner onboarding pack
- Companies pursuing ISO 27001 who need evidence the rules reached all personnel
What's Inside
Scope & bound parties
Employees, contractors, interns, and third parties using organisational assets.
Device & network use
Personal use limits, software installation, and connecting foreign devices.
Email & communication
Rules for work email use, attachment handling, and communicating on the organisation's behalf.
Data handling
Rules for copying, sharing, and removing information according to its classification.
Absolute prohibitions
Acts prohibited without exception, including credential sharing and circumventing security controls.
Acknowledgement & consequences
An acknowledgement page and breach consequences — the evidence that the policy was genuinely communicated.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.5.10 | Acceptable use of information and associated assets. |
| ISO/IEC 27001:2022 | Controls A.6.2 & A.6.3 | Terms and conditions of employment, and information security awareness, education and training. |
| ISO/IEC 27001:2022 | Control A.5.1 | Topic-specific policies supporting the information security policy. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Must every employee sign the AUP?
The standard requires evidence that the rules were communicated and understood, not a signature as such. A signature — wet or electronic — is simply the easiest evidence to produce at audit, which is why this template includes an acknowledgement page.
How should personal use of work devices be handled?
A total ban is rarely realistic and hard to enforce. What lasts is setting reasonable limits and naming explicitly what is never permitted. What matters is that the boundary is written down rather than left to individual interpretation.
Is an AUP the same as an information security policy?
They sit at different levels. The information security policy states organisation-level principles and is signed by top management. The AUP translates those principles into day-to-day rules of behaviour for everyone using organisational assets.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Policy, Procedure & Form Template Pack
A ready-to-use collection of information security policy, procedure, and form templates.
Free DownloadAI Usage Policy Template
A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.
Free DownloadRemote Working Policy Template
Security standards for remote and hybrid work: devices, home networks, VPN, document storage, and physical security — aligned with ISO 27001 control A.6.7.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.