Template

Acceptable Use Policy

What employees may and may not do with company systems, data, devices, and AI tools.

Intended audience
Every employee and contractor
Difficulty
Beginner
Estimated time
25 minutes
Access
Free
NIST CSF
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Draft acceptable-use statements that cover company accounts, data storage, and AI tool usage.
  • List prohibited actions in concrete terms, such as credential sharing or moving data to personal storage.
  • Write a lawful, clear statement of what monitoring may occur.
  • Design an acknowledgment step that creates a record of who agreed and when.

1. Purpose and scope

Applies to all company systems, accounts, and data.

2. Acceptable use

  • Use company accounts for company work.
  • Store company data only in approved systems.
  • Use approved AI tools only, and never paste confidential data into unapproved ones.

3. Prohibited use

  • Sharing credentials or bypassing security controls.
  • Installing unapproved software or connecting unapproved services.
  • Moving company data to personal accounts or storage.

4. Monitoring

State clearly and lawfully what may be monitored.

5. Acknowledgment

Employees sign to confirm they have read and understood.

Key takeaways

  • Acceptable use policies work best when they name specific behaviors, like using a company password manager, instead of general good-behavior language.
  • AI tool usage should be addressed explicitly: which tools are approved, and what must never be pasted into an unapproved one.
  • Prohibited use should call out credential sharing and moving company data to personal accounts, since those are common real-world violations.
  • A monitoring statement protects both the organization and employees by setting expectations in writing before any monitoring occurs.
  • Signed acknowledgment is the evidence that ties an individual employee to the policy version they agreed to follow.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.

Matched on shared frameworks, topics, and program packs.

Guide

Building a Security Program from Scratch

A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.

Beginner
14 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Exercise

Complete a Readiness Scorecard

Score yourself honestly across six areas and turn the two lowest into a short plan.

Beginner
15 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Checklist

Cybersecurity Self-Assessment Checklist

A fast, honest look at your current security posture across identity, devices, data, people, and response.

Beginner
25 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Checklist

Small Business Security Checklist

The thirty-day baseline: the controls that stop the majority of small-business incidents, ordered by impact.

Beginner
30 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Checklist

Vendor Security Review Checklist

A proportionate review for the vendors that actually hold your data — without sending a two-hundred-question survey.

Beginner
20 min
Free
NIST CSF
SOC 2

Published · v1.0.0 · 2026-08-01

Checklist

Employee Security Awareness Checklist

The habits every employee should be able to demonstrate, written as a self-check rather than a lecture.

Beginner
10 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.