[Company Logo][Company Name]
- Policy No.:
- [Reference Number]
- Version:
- [Version Number]
- Effective Date:
- [Date]
- Policy Owner:
- Information Technology
1. Purpose
This policy defines acceptable and unacceptable use of the IT resources of [Company Name], to protect employees, customers and the company from security, legal and reputational risks.
2. Scope
It applies to all employees, contractors, interns and third parties who use company devices, networks, email, applications, cloud services or data, from any location.
3. Definitions
- IT resources: hardware, software, networks, accounts, cloud services and data owned or licensed by the company.
- User: any person given access to IT resources.
- Credentials: user IDs, passwords, tokens and authentication devices.
4. Policy
4.1 Permitted use: IT resources are provided for business purposes. Limited personal use is allowed if it is brief, lawful, does not affect work and does not consume significant resources.
4.2 Prohibited use: Users must not:
- Access, store or share illegal, obscene, defamatory or discriminatory material.
- Install unlicensed or unapproved software, browser extensions or AI tools that process company data without approval.
- Attempt unauthorised access, scan networks, bypass security controls or disable antivirus.
- Share credentials or use another person's account.
- Use resources for personal business, crypto-mining, gambling or political campaigning.
- Copy company data to personal devices, personal email or unapproved cloud storage.
- Send harassing messages or impersonate others.
4.3 Accounts: Passwords must be at least [Number] characters, unique and changed when compromised. Multi-factor authentication is mandatory for email and remote access.
4.4 Monitoring: The company may log and review use of its systems for security, compliance and investigations. Users should not expect privacy in content stored or sent on company systems, though monitoring will be proportionate and access to logs restricted.
5. Procedure
- Users accept this policy before accounts are activated and every year thereafter.
- Software or tool requests go through [IT Helpdesk] for approval.
- Suspected incidents, phishing or lost devices are reported to [IT Security Email] immediately.
- Access is reviewed by managers every [Number] months and removed on exit.
6. Responsibilities
- Users: follow this policy and report incidents.
- Managers: approve access on need-to-know and ensure team compliance.
- IT: provide secure systems, monitor and respond to incidents.
- HR: include the policy in onboarding and handle disciplinary matters.
7. Non-compliance
Violations may lead to suspension of access and action under the Disciplinary Policy, and where the law is broken, reporting to authorities.
8. Review & Approval
IT will review this policy annually or after a significant incident.
Approved by
[Authorised Signatory][Designation]Date:
[Date]User acknowledgement
[Employee Name]Employee ID:
[Employee ID]Date:
[Date]