# Acceptable Use Guidance **Document owner:** [Owner/Role] **Approved by:** [Steering Committee / CISO] **Effective date:** [YYYY-MM-DD] **Review cadence:** [Annually] --- ## 1. Purpose & Scope Implementation guidance for the [Acceptable Use Policy](acceptable_use_policy.md). Applies to all staff and to managers handling exceptions. --- ## 2. Shadow IT / Shadow AI — Practical Detection - Monitor SaaS discovery via CASB/SSO login patterns (unsanctioned app sign-ins via "Login with Google/Microsoft" are the easiest signal). - Common shadow-AI entry point: pasting internal docs/code into a public chatbot for "just a quick summary" — treat this as the default failure mode to educate against, not an edge case. - Provide an approved, low-friction AI tool option so staff aren't forced into shadow use to get work done — a policy with no sanctioned alternative just pushes usage underground. ## 3. Approval Fast-Path - Low-risk tools (no data beyond TLP:CLEAR/GREEN touches the tool): lightweight self-service approval with automatic logging. - Any tool touching TLP:AMBER+: security review required before use, checking for a no-train/no-retain data processing clause. ## 4. Onboarding Checklist ✅ New hires acknowledge this policy before systems access is granted. ✅ Approved SaaS/AI tool list published and easy to find (not buried in a wiki no one reads). ✅ Reporting channel for suspected phishing/shadow IT is one click away, not a multi-step process. --- ## 5. References - **[ISO/IEC 27001:2022](https://www.iso.org/standard/27001)** - **[CIS Controls v8.1](https://www.cisecurity.org/controls/v8-1)**