betterjobs

Free policy template · Word

IT Acceptable Use Policy

An IT acceptable use policy (AUP) is the umbrella rulebook for how employees may use all company IT resources — computers, networks, accounts, software, cloud tools and printers. It lists what is permitted and prohibited, sets account and password rules, explains monitoring, and is signed by every user before access is given.

  • Editable Word (.docx)
  • Made for India
  • 11 fill-in fields highlighted
  • Free, no sign-up

Preview of the policy

[Highlighted] = fill in
[Company Logo][Company Name]

IT ACCEPTABLE USE POLICY

Policy No.:
[Reference Number]
Version:
[Version Number]
Effective Date:
[Date]
Policy Owner:
Information Technology

1. Purpose

This policy defines acceptable and unacceptable use of the IT resources of [Company Name], to protect employees, customers and the company from security, legal and reputational risks.

2. Scope

It applies to all employees, contractors, interns and third parties who use company devices, networks, email, applications, cloud services or data, from any location.

3. Definitions

  • IT resources: hardware, software, networks, accounts, cloud services and data owned or licensed by the company.
  • User: any person given access to IT resources.
  • Credentials: user IDs, passwords, tokens and authentication devices.

4. Policy

4.1 Permitted use: IT resources are provided for business purposes. Limited personal use is allowed if it is brief, lawful, does not affect work and does not consume significant resources.

4.2 Prohibited use: Users must not:

  1. Access, store or share illegal, obscene, defamatory or discriminatory material.
  2. Install unlicensed or unapproved software, browser extensions or AI tools that process company data without approval.
  3. Attempt unauthorised access, scan networks, bypass security controls or disable antivirus.
  4. Share credentials or use another person's account.
  5. Use resources for personal business, crypto-mining, gambling or political campaigning.
  6. Copy company data to personal devices, personal email or unapproved cloud storage.
  7. Send harassing messages or impersonate others.

4.3 Accounts: Passwords must be at least [Number] characters, unique and changed when compromised. Multi-factor authentication is mandatory for email and remote access.
4.4 Monitoring: The company may log and review use of its systems for security, compliance and investigations. Users should not expect privacy in content stored or sent on company systems, though monitoring will be proportionate and access to logs restricted.

5. Procedure

  1. Users accept this policy before accounts are activated and every year thereafter.
  2. Software or tool requests go through [IT Helpdesk] for approval.
  3. Suspected incidents, phishing or lost devices are reported to [IT Security Email] immediately.
  4. Access is reviewed by managers every [Number] months and removed on exit.

6. Responsibilities

  • Users: follow this policy and report incidents.
  • Managers: approve access on need-to-know and ensure team compliance.
  • IT: provide secure systems, monitor and respond to incidents.
  • HR: include the policy in onboarding and handle disciplinary matters.

7. Non-compliance

Violations may lead to suspension of access and action under the Disciplinary Policy, and where the law is broken, reporting to authorities.

8. Review & Approval

IT will review this policy annually or after a significant incident.

Approved by
[Authorised Signatory]
[Designation]
Date: [Date]
User acknowledgement
[Employee Name]
Employee ID: [Employee ID]
Date: [Date]

What this template includes

  • Covered resources — devices, network, accounts, SaaS tools, printers
  • Permitted use — business purposes with limited personal use
  • Prohibited use — illegal content, hacking, crypto-mining, piracy, harassment
  • Account and password rules — no sharing, multi-factor authentication
  • Monitoring notice — no expectation of privacy on company systems
  • User acknowledgement — signed before access

When to use it

  • Giving system access to new joiners and needing a signed acknowledgement
  • A client or ISO/SOC audit asks for your acceptable use policy
  • Employees install personal software or share accounts
  • Explaining that company systems may be monitored

How to customise this template

  1. 1List your key systems and SaaS tools
  2. 2Set password length and MFA requirements
  3. 3Decide the extent of personal use allowed
  4. 4Insert your IT helpdesk and incident reporting contact
  5. 5Cross-refer to the Internet, Email and Information Security policies

HR tips

  • Keep the AUP short and readable — users actually need to understand it
  • Make acceptance part of the first login, and renew annually
  • Explain monitoring openly; hidden monitoring erodes trust
  • Revoke access on the last working day, not after

Monitoring and use of employee data must be proportionate and comply with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 and related rules. Review this template with legal and IT security advisers.

For HR & hiring managers

Hire top talent from BetterJobs

Experienced and fresher candidates across India — blue, grey and white collar. Post a job in 5 minutes and start receiving applications.

  • Post in 5 minutesDescribe the role in one line — we write the job description.
  • Verified applicantsEvery applicant has a verified mobile number.
  • Resume databaseSearch experienced candidates by skill, city and experience.

Frequently asked questions

What is an acceptable use policy?+

It is a policy that sets out the rules for using an organisation's computers, networks and software, including what is allowed, what is prohibited and the consequences of misuse.

Can a company monitor employees' work computers?+

A company can generally monitor its own systems for security and compliance if employees are informed, the monitoring is proportionate and data is handled lawfully. Disclose it in the AUP.

How is an AUP different from an information security policy?+

The AUP tells users how to behave on IT systems. The information security policy is broader, setting the organisation's controls for protecting information, including access control, risk and incident management.

All 50 hr policies →