Files
policies/Security/acceptable_use_guidance.md

1.6 KiB

Acceptable Use Guidance

Document owner: [Owner/Role]
Approved by: [Steering Committee / CISO]
Effective date: [YYYY-MM-DD]
Review cadence: [Annually]


1. Purpose & Scope

Implementation guidance for the Acceptable Use Policy. Applies to all staff and to managers handling exceptions.


2. Shadow IT / Shadow AI — Practical Detection

  • Monitor SaaS discovery via CASB/SSO login patterns (unsanctioned app sign-ins via "Login with Google/Microsoft" are the easiest signal).
  • Common shadow-AI entry point: pasting internal docs/code into a public chatbot for "just a quick summary" — treat this as the default failure mode to educate against, not an edge case.
  • Provide an approved, low-friction AI tool option so staff aren't forced into shadow use to get work done — a policy with no sanctioned alternative just pushes usage underground.

3. Approval Fast-Path

  • Low-risk tools (no data beyond TLP:CLEAR/GREEN touches the tool): lightweight self-service approval with automatic logging.
  • Any tool touching TLP:AMBER+: security review required before use, checking for a no-train/no-retain data processing clause.

4. Onboarding Checklist

New hires acknowledge this policy before systems access is granted.
Approved SaaS/AI tool list published and easy to find (not buried in a wiki no one reads).
Reporting channel for suspected phishing/shadow IT is one click away, not a multi-step process.


5. References