1.6 KiB
1.6 KiB
Acceptable Use Guidance
Document owner: [Owner/Role]
Approved by: [Steering Committee / CISO]
Effective date: [YYYY-MM-DD]
Review cadence: [Annually]
1. Purpose & Scope
Implementation guidance for the Acceptable Use Policy. Applies to all staff and to managers handling exceptions.
2. Shadow IT / Shadow AI — Practical Detection
- Monitor SaaS discovery via CASB/SSO login patterns (unsanctioned app sign-ins via "Login with Google/Microsoft" are the easiest signal).
- Common shadow-AI entry point: pasting internal docs/code into a public chatbot for "just a quick summary" — treat this as the default failure mode to educate against, not an edge case.
- Provide an approved, low-friction AI tool option so staff aren't forced into shadow use to get work done — a policy with no sanctioned alternative just pushes usage underground.
3. Approval Fast-Path
- Low-risk tools (no data beyond TLP:CLEAR/GREEN touches the tool): lightweight self-service approval with automatic logging.
- Any tool touching TLP:AMBER+: security review required before use, checking for a no-train/no-retain data processing clause.
4. Onboarding Checklist
✅ New hires acknowledge this policy before systems access is granted.
✅ Approved SaaS/AI tool list published and easy to find (not buried in a wiki no one reads).
✅ Reporting channel for suspected phishing/shadow IT is one click away, not a multi-step process.