An acceptable use policy (AUP) is a written set of rules describing how people may use a set of technology resources, such as systems, networks, devices, data and online services, and what is not allowed. Inside a company, the AUP tells employees and contractors what they can do with company laptops, email, internet access, cloud apps and data. Service providers publish their own AUPs too, setting the rules customers must follow on an internet connection, cloud platform or messaging service. Both kinds set expectations and give a basis for action when rules are broken.
At a glance
- An internal AUP sets rules for employees and contractors; a provider’s AUP sets rules for its customers.
- Common topics include prohibited activities, account and password rules, personal devices, approved software, AI tools, monitoring and consequences.
- Users usually acknowledge the internal AUP when they join and periodically after that.
- An AUP sets expectations; technical controls and training are what make it stick.
- Breaking a provider’s AUP can lead to suspension or termination of service.
What problem it solves
People can’t follow rules nobody wrote down. Without an AUP, staff make their own decisions about personal email for work files, unapproved apps, AI chatbots or sharing passwords, and the organization has a weak footing if it needs to discipline someone or explain to an auditor how it set expectations.
An AUP gives everyone the same baseline and connects to everything else: security awareness training teaches it, data classification defines what data needs special handling, and technical controls enforce it. Cyber insurers, customers and auditors commonly ask whether one exists and whether staff acknowledged it.
On the provider side, an AUP protects the provider’s network and other customers from spam, abuse and illegal activity, and tells buyers what they can’t do with the service.
How it works
Write it. HR, IT, security and legal agree on scope and rules. Good AUPs are short, plain and specific: what’s allowed, what isn’t and why, with examples.
Cover the current risks. Typical sections address company devices and bring your own device (BYOD), approved software and shadow IT, generative AI tools and shadow AI, remote work, data handling by classification, social media, email and messaging, and reporting lost devices or suspected incidents.
Explain monitoring. State whether and how activity on company systems may be monitored, in line with local law. Rules on employee monitoring vary by country and state, so have counsel review this section.
Get acknowledgment. Users accept the policy at onboarding and after significant changes, often annually, through HR systems or security awareness training (SAT) platforms.
Back it with controls. Use tools such as mobile device management (MDM), web and DNS filtering and data loss prevention to enforce the parts that can be enforced, and review exceptions.
Respond to violations. Define the process and consequences, coordinated with HR, and watch for patterns that may signal an insider threat.
When it matters for buyers
- When adopting new tools such as AI assistants or collaboration apps. Update the AUP before rollout so staff know the rules.
- When allowing personal devices. BYOD without written rules creates disputes over data, monitoring and wiping.
- When a cyber insurer or customer asks for policy evidence. A current, acknowledged AUP is a common checklist item.
- When buying internet, cloud, email or calling services. Read the provider’s AUP, especially for bulk messaging, hosting or high-volume calling, to avoid surprise suspensions.
Our governance, risk and compliance and security awareness training overviews cover help with policies and getting staff to follow them.
Questions to ask vendors
- Can you share your acceptable use policy before we sign, and how often does it change?
- What activities lead to suspension, and do you warn before suspending service?
- How do you handle an AUP complaint against our account, and how can we respond?
- For training platforms: can we deliver our own AUP and track acknowledgment?
- For device and security tools: which parts of our AUP can your product enforce automatically?
- For AI and SaaS tools: can admins restrict features or data types to match our policy?
How it differs from a BYOD policy
A bring your own device (BYOD) policy covers one topic: using personal phones, tablets and computers for work, including security requirements, support, privacy and what happens to company data when someone leaves. An AUP is broader and covers how people use all company technology and data. Many organizations keep BYOD rules as a section of the AUP or as a separate policy that the AUP references. Either way, the two should agree on monitoring, data handling and consequences.
