Acceptable Use & Workstation Security
Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal
1. Purpose
This policy sets out how people are expected to use {{COMPANY_LEGAL_NAME}}'s systems responsibly and how endpoints must be configured to keep company data safe.
2. Scope
This policy applies to everyone who uses company systems and to every device that connects to company networks or handles company data.
3. Policy statements
3.1 Acceptable use
Company assets are provided for authorized business purposes. Limited personal use is fine as long as it creates no risk. Illegal, harassing, or copyright-infringing activity is never permitted.
3.2 Workstation configuration and updates
Endpoints must run full-disk encryption, a host firewall, and automatic operating-system patching. Screens lock automatically after ten minutes of inactivity and require a password or PIN to resume.
3.3 Email and messaging
Company data must not be forwarded to personal email accounts. Business conversations belong in approved, sanctioned messaging tools.
3.4 Removable media and printing
Sensitive documents are collected from printers immediately and shredded once no longer needed. Company data on removable media must be encrypted and securely destroyed when finished.
3.5 Personal devices and local storage
Personal devices used for work (BYOD) must meet endpoint requirements (PIN, encryption, and patching) and be registered with IT. Company data is stored only in approved, encrypted containers or applications, never loose on a personal device.
3.6 Compliance measurement
A quarterly workstation review confirms encryption, auto-lock settings, and patch status across the fleet.
3.7 Continual improvement
Rules are refreshed as new collaboration tools are adopted and as endpoint threats evolve.
4. Roles and responsibilities
| Role | Responsibility |
|---|---|
| Executive sponsor | Accountable for the program; approves this policy |
| {{POLICY_OWNER_ROLE}} | Maintains this policy and its procedures |
| Managers | Enforce the policy within their teams |
| All personnel | Comply; report issues promptly |
5. Compliance and exceptions
Breaches lead to access suspension until remediation, with severe cases escalated to HR. A temporary deviation (for example, lab or test work) requires documented approval, a time limit, and, where relevant, compensating controls. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.
6. Review
This policy is reviewed at least annually and when significant change occurs.
Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.