betterjobs

Free form template · Word

Cybersecurity Policy Acknowledgement

A cybersecurity policy acknowledgement is a signed confirmation that an employee has read the company's information security policy and agrees to its key rules on passwords, phishing, devices, data handling and incident reporting. HR or IT collects it at joining and after each annual awareness training.

  • Editable Word (.docx)
  • Made for India
  • 14 fill-in fields highlighted
  • Free, no sign-up

Preview of the form

[Highlighted] = fill in
[Company Logo][Company Name]

CYBERSECURITY POLICY ACKNOWLEDGEMENT

Policy:
[Policy Name], Version [Policy Version]
Policy available at:
[Intranet Link / HR Portal]
Date:
[Date]
Name[Employee Name]
Employee ID[Employee ID]
Designation[Designation]
Department[Department]
Category: Employee / Intern / Contractor / Consultant
Security awareness training attended on[DD/MM/YYYY]

Key Rules I Agree to Follow

  1. Passwords: I will use strong, unique passwords for company accounts, keep MFA enabled and never share passwords or OTPs with anyone, including IT staff.
  2. Phishing: I will not click links or open attachments in unexpected emails or messages, and will report suspicious messages to [Email ID].
  3. Devices: I will lock my screen when away, keep company devices updated, and not disable antivirus or encryption.
  4. Removable media: I will not use USB drives or external storage unless approved by IT.
  5. Software: I will install only approved software and will not use unapproved cloud tools or AI tools to process company or client data.
  6. Data: I will handle data according to its classification, share confidential data only with authorised persons, and not send company data to personal email or chat accounts.
  7. Remote work: I will use the company VPN and avoid unsecured public Wi-Fi for company work.
  8. Physical security: I will wear my ID card, prevent tailgating and keep confidential papers locked.
  9. Incidents: I will report any lost device, suspected breach or virus to IT immediately at [Mobile Number].

Monitoring and Consequences

I understand that company systems, email, internet usage and devices may be monitored for security purposes as described in the policy. Violation of the policy may lead to withdrawal of access and disciplinary action in accordance with company rules, after due process.

Declaration

I confirm that I have read and understood the [Policy Name] and the key rules above, have had the opportunity to ask questions, and agree to comply with them during my association with [Company Name].

Employee
[Employee Name]
Date: [Date]
Recorded by
[HR Name] / [IT Security Name]
Date: [Date]

What this template includes

  • Policy name, version and where to read it
  • Plain-language summary of the most important rules
  • Phishing and suspicious email reporting
  • Rules for devices, removable media and personal devices
  • Data classification and sharing rules
  • Consent to monitoring and consequences of breach

When to use it

  • During induction for every new employee, intern and contractor
  • After annual security awareness training
  • When the information security policy is revised
  • For client audits that require proof of employee awareness

How to customise this template

  1. 1Insert your policy title, version and intranet link
  2. 2Keep the rule summary to the top 8–10 behaviours you care about
  3. 3Add your phishing report address and helpdesk number
  4. 4Include client-specific requirements for IT or BPO projects
  5. 5Record the training date if signed after training

HR tips

  • Collect the acknowledgement after a short training, not as a box-ticking form at induction
  • Re-collect it every year so the record stays current
  • Keep the language simple and avoid copying the full policy
  • Store acknowledgements where auditors can retrieve them by employee ID

Monitoring and disciplinary terms should match your published policies, standing orders and applicable data protection law; review with a legal adviser.

For HR & hiring managers

Hire top talent from BetterJobs

Experienced and fresher candidates across India — blue, grey and white collar. Post a job in 5 minutes and start receiving applications.

  • Post in 5 minutesDescribe the role in one line — we write the job description.
  • Verified applicantsEvery applicant has a verified mobile number.
  • Resume databaseSearch experienced candidates by skill, city and experience.

Frequently asked questions

Why do employees sign a cybersecurity policy acknowledgement?+

It shows that the employee was informed of the security rules and agreed to follow them, which supports awareness programmes, client audits and fair handling of breaches.

How often should the acknowledgement be renewed?+

Many companies renew it annually with security awareness training, and whenever the policy changes significantly.

Do contractors need to sign it?+

Yes, anyone with access to company systems or data should sign, including contractors, interns and consultants.