Template

US IT Acceptable Use Policy Template

About this template

Crafted by
Whale logo
US IT Acceptable Use Policy Template

Purpose and Scope

This policy sets standard operating rules for using [Organisation Name]’s technology systems, including computers, mobile devices, email, network infrastructure, software, and cloud services.

It applies to all employees, contractors, and authorized third parties with system access, whether working on-site or remotely.

This document outlines operational standards. It is not an employment contract and does not change the at-will nature of employment where applicable by law.

Working through related paperwork at the same time? See also our UK IT & Acceptable Use Policy Template, Privacy Notice for Employees Template and UK Data Breach Response Procedure Template.

Policy Statement

[Organisation Name] provides IT systems to support business operations. Users must operate these systems lawfully, securely, and professionally. Limited personal use is allowed within defined limits, but all systems and data remain company property.

Nothing in this policy restricts employee rights protected by labor laws, including discussions about working conditions, wages, or employment terms.

Responsibilities

  • Policy Owner ([Role]): Keeps this policy current, approves written exceptions, and reviews security incidents.
  • IT Lead ([Role]): Manages user accounts and permissions, deploys updates, and leads technical incident response.
  • Managers: Ensure team members review this policy. Submit access change requests whenever staff join, transfer, or depart.
  • All Users: Follow all system rules, complete security training, and immediately report security risks or incidents.

Acceptable Use

  • Access systems only through your assigned account. Never share or use another person’s login credentials.
  • Install and use only software and cloud services approved by [Role].
  • Store all business records and work files in approved company repositories, never on local drives, personal cloud storage, or external drives.
  • Lock your screen whenever you leave your device, whether in the office or working remotely.
  • Use designated company channels for all business communications to maintain clear corporate records.

Unacceptable Use

  • Do not share passwords, multi-factor authentication codes, or credentials with anyone inside or outside the company.
  • Do not access, store, or send material that is illegal, discriminatory, sexually explicit, or harassing.
  • Do not transfer company or customer data to personal email, unauthorized personal storage, or external services.
  • Do not attempt to gain unauthorized access to data, accounts, or network resources.
  • Do not disable or tamper with security controls, including antivirus software, endpoint encryption, or screen lock timers.
  • Do not use company systems to run a personal business, generate side income, or conduct unlawful activities.

Use our templates to fast-track your documentation

Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.

Passwords, Devices, and Security Basics

  • Use strong, unique passwords for every work account. Change credentials immediately if you suspect a breach.
  • Enable multi-factor authentication on all accounts where configured by [Role].
  • Treat unexpected requests for credentials, money transfers, or urgent action as suspicious. Verify the request through a secondary, trusted channel before acting.
  • Install system security updates within [Number] days of release.
  • Report lost or stolen equipment to [Role] as soon as you notice it missing.

Personal Use and Monitoring

You may use company email and internet for limited personal use during non-working hours, as long as it does not disrupt operations, consume excessive bandwidth, or violate this policy. Management may restrict personal use privileges at any time based on operational needs.

[Organisation Name] monitors system activity, including access logs, network traffic, and usage patterns, to maintain security, keep systems running smoothly, and meet legal requirements. Expect no privacy when creating, sending, receiving, or storing content on company systems. Targeted reviews of user communications require written authorization from [Role] and formal documentation.

Incident Response Procedure

  1. Report suspected security incidents, such as clicked phishing links, lost devices, misdirected sensitive emails, or suspicious account activity, to [Role] immediately.
  2. [Role] takes containment action right away, including isolating affected devices, resetting credentials, and preserving system logs for investigation.
  3. [Role] evaluates data exposure risks to determine if legal notification rules apply under state or regional laws.
  4. Log the incident, root cause analysis, and corrective actions in [System/Location] to improve security controls and update training.

Records and Review

  • Store signed acknowledgments, training logs, and incident reports in [System/Location].
  • [Role] reviews this policy annually and after any major security incident.
  • Next Scheduled Review Date: [Date].

FAQs on an IT acceptable use policy

An IT acceptable use policy sets standard operating rules for using your organisation’s technology systems, including computers, mobile devices, email, network infrastructure, software, and cloud services.

Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.

This template covers acceptable use, unacceptable use, passwords, devices, and security basics and personal use and monitoring.

Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.

Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.

Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.

Use our templates to fast-track your documentation

Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.