Files
policies/Security/acceptable_use_policy.md
T

62 lines
3.7 KiB
Markdown

# Acceptable Use Policy
**Document owner:** [Owner/Role]
**Approved by:** [Steering Committee / CISO]
**Effective date:** [YYYY-MM-DD]
**Review cadence:** [Annually]
---
## 1. Purpose & Scope
This policy defines acceptable use of [Organization] systems, accounts, and data by all employees, contractors, and vendors with access to those systems.
---
## 2. Policy Statements
### 2.1 General Use
- Systems and accounts **must** be used primarily for authorized business purposes.
- Incidental personal use is permitted where it does not interfere with duties, consume disproportionate resources, or violate this policy.
### 2.2 Prohibited Activities
- Unauthorized access to systems or data outside one's role (see [Access Control Policy §3.1](access_control_policy.md)).
- Disabling, bypassing, or circumventing security controls (MFA, endpoint protection, logging) without a documented exception.
- Sharing credentials or allowing account use by another person, including "temporary" sharing for convenience.
- Illegal activity, harassment, or use that damages [Organization]'s reputation.
### 2.3 Email & Communication
- Business email **must not** be used for unrelated personal accounts of consequence (banking, unrelated business ventures).
- Suspected phishing **must** be reported, not just deleted.
### 2.4 Cloud Services & Shadow IT
- New SaaS tools, including AI/LLM tools, **must** be approved before use with company data — unsanctioned tools create the "knowledge/AI leak" risk described in the organization's Antifragile Enterprise Manifest (Pillar 4: Sovereign Intelligence): data and reasoning sent to an unapproved third party is cognition the organization no longer controls.
- Approved AI tools **must** be used per any organization-specific data handling addendum; TLP:AMBER+STRICT/RED data (per [Data Classification Policy](data_classification_policy.md)) **must not** be submitted to a cloud AI service without verified contractual no-train/no-retain terms.
### 2.5 Personal & BYOD Devices
- Personal devices accessing company data **must** meet minimum security baseline (screen lock, encryption, current OS) — full BYOD/MDM requirements are covered in a dedicated device management policy where one exists.
### 2.6 Monitoring Notice
- [Organization] **may** monitor system and account usage as permitted by applicable law, for security and operational purposes. Users **should** have no expectation of privacy in company systems beyond what law requires.
### 2.7 Enforcement
- Violations **may** result in disciplinary action, up to and including termination of access or employment.
---
## 3. Antifragility Alignment
This policy is built to the five pillars of the organization's internal **Antifragile Enterprise Manifest**.
| Pillar | Applied In | How |
|---|---|---|
| **1. Structural Decoupling** | §2.4 | Approval gate on new SaaS/AI tools prevents unmapped, unmanaged dependencies from silently accumulating |
| **2. Optionality Preservation** | §2.4 | Requiring no-train/no-retain terms before sending sensitive data to a vendor preserves control over that data later |
| **3. Stress-to-Signal Conversion** | §2.3 | Reported phishing (not just deleted) becomes signal that feeds security awareness and control updates |
| **4. Sovereign Intelligence** | §2.4 | This is the pillar's most direct policy expression: shadow AI/cloud use is exactly the "AI leak" the manifest warns about |
| **5. Asymmetric Payoff Design (Barbell)** | §2.4 | Extra scrutiny concentrated on AMBER+STRICT/RED data reaching AI tools; low-sensitivity personal use stays lightly governed |
---
## 4. References
- **[ISO/IEC 27001:2022](https://www.iso.org/standard/27001)**
- **[CIS Controls v8.1](https://www.cisecurity.org/controls/v8-1)**