34 lines
1.6 KiB
Markdown
34 lines
1.6 KiB
Markdown
# Acceptable Use Guidance
|
|
|
|
**Document owner:** [Owner/Role]
|
|
**Approved by:** [Steering Committee / CISO]
|
|
**Effective date:** [YYYY-MM-DD]
|
|
**Review cadence:** [Annually]
|
|
|
|
---
|
|
|
|
## 1. Purpose & Scope
|
|
Implementation guidance for the [Acceptable Use Policy](acceptable_use_policy.md). Applies to all staff and to managers handling exceptions.
|
|
|
|
---
|
|
|
|
## 2. Shadow IT / Shadow AI — Practical Detection
|
|
- Monitor SaaS discovery via CASB/SSO login patterns (unsanctioned app sign-ins via "Login with Google/Microsoft" are the easiest signal).
|
|
- Common shadow-AI entry point: pasting internal docs/code into a public chatbot for "just a quick summary" — treat this as the default failure mode to educate against, not an edge case.
|
|
- Provide an approved, low-friction AI tool option so staff aren't forced into shadow use to get work done — a policy with no sanctioned alternative just pushes usage underground.
|
|
|
|
## 3. Approval Fast-Path
|
|
- Low-risk tools (no data beyond TLP:CLEAR/GREEN touches the tool): lightweight self-service approval with automatic logging.
|
|
- Any tool touching TLP:AMBER+: security review required before use, checking for a no-train/no-retain data processing clause.
|
|
|
|
## 4. Onboarding Checklist
|
|
✅ New hires acknowledge this policy before systems access is granted.
|
|
✅ Approved SaaS/AI tool list published and easy to find (not buried in a wiki no one reads).
|
|
✅ Reporting channel for suspected phishing/shadow IT is one click away, not a multi-step process.
|
|
|
|
---
|
|
|
|
## 5. References
|
|
- **[ISO/IEC 27001:2022](https://www.iso.org/standard/27001)**
|
|
- **[CIS Controls v8.1](https://www.cisecurity.org/controls/v8-1)**
|