Menu

How to Create an Acceptable Use Policy (AUP)? Explained

How to Create an Acceptable Use Policy (AUP)? Explained

A security control can block an unauthorized login, but it cannot always prevent an authorized user from making an unsafe decision. An employee with legitimate access can forward a business document to a personal email account, respond to a convincing phishing message, upload proprietary code to an unapproved AI tool, or install unauthorized software on a company device. These are not necessarily failures of technical security; they are user-behavior risks occurring within legitimate access. The security challenge, therefore, is not only controlling who gets access, but also establishing clear boundaries around what users can do once they have it.

The issue is becoming more relevant across Africa's rapidly expanding digital environment. INTERPOL's 2026 Africa Cyberthreat Assessment reports that AI is linked to 55% of reported cybercrime across Africa, while its 2025 assessment identified online scams, ransomware, and business email compromise among the region's major cyberthreats. This changes how organizations should think about an Acceptable Use Policy (AUP). It should not be a document that simply lists prohibited websites or tells employees not to misuse company devices. A modern AUP establishes boundaries for legitimate access, defining how users can work with company systems, data, cloud services, communication platforms, and emerging technologies without creating unnecessary risk.

The real question is therefore not simply “Do we have an AUP?” but “Have we clearly defined what secure technology use looks like in the way our people actually work?” This article explains how to create an acceptable use policy that answers that question.

What Is an Acceptable Use Policy?

An Acceptable Use Policy is a formal set of rules defining how users are permitted to use an organization's technology resources and information. It can apply to employees, contractors, temporary workers, third parties, and other individuals with authorized access. At a practical level, an AUP answers questions such as:

  • Which company devices and systems can users access?
  • What software and applications are permitted?
  • How should company information be handled?
  • Can employees use personal devices or cloud storage?
  • What are the rules for email and internet usage?
  • Can employees use generative AI tools?
  • Which activities are prohibited?
  • How should security incidents be reported?
  • What happens when the policy is violated?

NIST describes user agreements and acceptable-use agreements as mechanisms for specifying user responsibilities when accessing systems or exchanging information. NIST SP 800-53 also calls for rules describing expected behavior and documented acknowledgment before access is authorized.

Why Does an Organization Need an AUP?

An AUP creates a practical connection between cybersecurity requirements and everyday employee behavior. Security teams can deploy sophisticated technical controls, but users will still make decisions about where they store files, which applications they use, who they share information with, and what they upload to online services. A clear policy establishes a common baseline for those decisions. It can address risks involving unauthorized software, inappropriate internet use, sensitive data sharing, personal devices, remote access, cloud applications, and AI tools. For organizations operating in Africa, an AUP can also provide a consistent baseline across geographically distributed offices, remote employees, contractors, and third-party users. CIS emphasizes that AUPs should be understandable to users regardless of their technical expertise and should be regularly updated and enforced.

What Should an Acceptable Use Policy Cover?

The acceptable use policy requirements should reflect how an organization actually uses technology, handles information, and manages risk. Rather than creating a long list of generic restrictions, the policy should establish clear rules for the systems, data, applications, and behaviors that could affect security. The following acceptable use policy components provide a practical foundation.

Company Devices and Systems

Define acceptable use of laptops, desktops, mobile devices, servers, networks, applications, and other organizational assets. Clarify which activities are permitted, which require authorization, and what users are responsible for when accessing company resources.

Internet and Network Usage

Set expectations for web browsing, downloads, streaming, unauthorized websites, network scanning, and attempts to bypass security controls. SANS notes that unrestricted internet access can introduce security and compliance risks, making clear usage rules an important part of an AUP.

Email and Communication Platforms

Establish rules for corporate email, messaging, video conferencing, and collaboration platforms. Address phishing, suspicious attachments, unauthorized forwarding, impersonation, and the sharing of sensitive information through communication channels.

Passwords and Authentication

Define user responsibilities for protecting credentials and complying with authentication requirements. The policy should make clear that passwords, authentication tokens, and other credentials must not be shared, bypassed, or deliberately exposed.

Software, SaaS, and Applications

Specify which software and cloud applications users may install or access and when approval is required. This is particularly important for shadow IT, where employees independently adopt SaaS platforms, browser extensions, file-sharing services, or other tools outside organizational oversight.

Data Handling and Sharing

Explain how users should access, store, transfer, share, retain, and dispose of organizational information. Requirements should reflect the sensitivity of the data and address situations such as personal email, removable media, cloud storage, external sharing, and unauthorized data transfers.

Personal Devices and BYOD

Where personal devices are permitted, establish requirements for secure configuration, approved applications, remote access, organizational data storage, and separation of personal and business information. The policy should also clarify what security controls and monitoring may apply to BYOD environments.

Generative AI and Emerging Technologies

Modern acceptable use policy guidelines should address how employees can use generative AI and other emerging technologies. Clearly define what information may be entered into external AI platforms, which tools are approved, and what restrictions apply to confidential data, customer information, source code, credentials, and intellectual property.

Security Incidents and Policy Violations

Users should know how to report suspected phishing, lost devices, accidental data disclosure, compromised credentials, or other security incidents. The AUP should also explain how violations are handled and when disciplinary or corrective action may apply.

A strong AUP ultimately does more than tell employees what not to do. It establishes clear expectations for how technology, information, and organizational resources should be used safely in everyday operations.

Choose INTERCERT for independent, internationally recognized Audits and Assessments.

How to Create an Acceptable Use Policy: 8 Practical Steps

Knowing how to write an acceptable use policy is less about finding the right template and more about translating real technology risks into clear user expectations. A strong AUP should reflect how people actually work, the systems they use, the information they access, and the risks those activities create.

Define the Purpose and Scope

Start by establishing why the AUP exists and who it applies to. Define the users, devices, networks, applications, cloud services, information, and other organizational resources covered by the policy. Include employees, contractors, temporary staff, and third parties where applicable.

Identify Real-World User and Technology Risks

Examine how technology is actually being used across the organization. Consider risks involving unauthorized software, personal devices, cloud applications, remote access, data sharing, social media, removable media, and generative AI. For organizations operating across Africa, the AUP should reflect the organization's actual geographic, operational, and technology environment rather than relying on generic assumptions.

Define Permitted and Prohibited Activities

Avoid vague statements such as “use company resources responsibly.” Users should be able to understand exactly what is permitted and what is prohibited. For example, instead of simply banning unauthorized applications, specify whether users can install software, browser extensions, SaaS platforms, file-sharing services, or AI tools without prior authorization.

Establish Clear Data Handling Rules

Connect the AUP with the organization's information security and data classification requirements. Explain how users should access, store, transmit, share, and dispose of different types of information. CIS recommends addressing the permitted use of enterprise data and assets, including how enterprise information may be transmitted to other parties.

Address Remote Work, BYOD, and Cloud Services

Technology use no longer stops at the corporate network. Define expectations for remote access, personal devices, home networks, public Wi-Fi, removable media, cloud storage, and collaboration platforms. Where BYOD is permitted, clarify the security requirements users must follow and the boundaries around organizational data.

Define Security Incident Reporting

Users should know what needs to be reported and where to report it. Cover situations such as phishing attempts, lost devices, accidental data disclosure, malware, compromised credentials, suspicious activity, and unauthorized access. Clear reporting expectations can reduce the time between identifying a potential incident and taking action.

Establish Exceptions and Enforcement

Legitimate business requirements may occasionally require an exception. Define who can approve exceptions, what justification is required, how long an exception remains valid, and when it should be reviewed. The AUP should also clearly communicate the consequences of violating organizational rules so that enforcement is consistent and predictable.

Communicate, Obtain Acknowledgment, and Review

An AUP has little value if employees cannot understand or remember it. Provide appropriate awareness when users receive access to organizational resources and obtain acknowledgment of their responsibilities. CIS recommends that users confirm their understanding of acceptable-use rules, while NIST emphasizes documented acknowledgment of rules of behavior before system access and periodic re-acknowledgment when requirements change.

The result should be a living policy, not a document created once and forgotten. Review the AUP when there are significant changes to technology, regulations, business processes, threats, or working practices so that its rules continue to reflect how the organization actually operates.

What Makes an AUP Effective?

The best acceptable use policy best practices are not about creating the longest possible document. An effective AUP translates security expectations into clear, practical, and enforceable rules that users can apply in their everyday work.

  • Clear and Easy to Understand: The policy should use straightforward language and avoid unnecessary technical terminology. Employees should be able to understand what is expected of them without needing cybersecurity expertise.
  • Specific and Actionable: Define actual behaviors rather than relying on vague statements such as “use systems responsibly.” Users should know which activities are permitted, restricted, prohibited, or require prior approval.
  • Relevant to the Real Environment: The policy should reflect the technologies and working practices employees actually use, including cloud applications, remote work, personal devices, collaboration platforms, and generative AI.
  • Enforceable in Practice: AUP requirements should connect to access controls, technical safeguards, monitoring, approval workflows, and clearly defined consequences. A rule that cannot be consistently enforced is unlikely to change user behavior.
  • Consistent Across Users: Apply appropriate requirements consistently to employees, contractors, temporary workers, and third parties. Exceptions should be formally approved and documented rather than informally granted.
  • Reviewed and Updated: An AUP should evolve as the organization's technology, threats, business processes, and regulatory obligations change. Regular reviews ensure that yesterday's acceptable-use rules do not become today's security gaps.

SANS similarly emphasizes defining both acceptable and prohibited behavior across IT systems, internet access, and communication technologies, reinforcing the role of an AUP in establishing accountability and reducing avoidable security risks.

Common Mistakes When Creating an Acceptable Use Policy

Even a well-intentioned AUP can become ineffective when its rules do not reflect how people actually work. The following mistakes can turn an acceptable use policy into a document that exists for compliance purposes but has little impact on day-to-day security.

Writing a Generic Policy

Statements such as “use technology appropriately” are too open to interpretation. An effective AUP should address specific activities users encounter, such as installing software, sharing files, accessing cloud applications, using personal devices, or handling sensitive information.

Ignoring Modern Technology

An AUP focused only on desktops, email, and internet browsing can quickly become outdated. Organizations should consider cloud services, smartphones, remote work, collaboration platforms, SaaS applications, removable media, and generative AI when defining acceptable use.

Focusing Only on Prohibited Activities

Telling users what they cannot do is only half the equation. The policy should also explain what secure behavior looks like, for example, how to share sensitive information, report suspicious messages, use approved applications, or handle company devices.

Creating Rules That Cannot Be Enforced

A policy should be realistic about what the organization can monitor and enforce. If an activity is prohibited but there are no reasonable technical, administrative, or investigative mechanisms to identify violations, the rule may have limited practical value.

Leaving Exceptions Undefined

Business operations may occasionally require an exception to a standard rule. Without a formal process for requesting, approving, documenting, and reviewing exceptions, employees may create informal workarounds that introduce additional risk.

Failing to Address Third-Party Users

Contractors, consultants, vendors, and other external users may receive access to organizational systems and information. Where applicable, the AUP should clearly establish the acceptable-use expectations that apply to these users.

Treating the AUP as a One-Time Document

Technology, threats, regulations, and working practices continuously change. An AUP that was appropriate two years ago may not address today's risks. CIS recommends regularly updating and enforcing acceptable-use rules to reflect enterprise needs.

Acceptable Use Policy Structure: A Practical Template

Organizations developing their first AUP do not need to start with a blank page. A well-defined acceptable use policy structure provides a practical foundation, but the document should ultimately reflect the organization's technology environment, workforce, information assets, security risks, and applicable legal or regulatory obligations. The following acceptable use policy template can serve as a starting point:

  • Purpose
  • Scope
  • Definitions
  • Authorized Users
  • Acceptable Use of Systems and Devices
  • Internet and Email Usage
  • Software and Applications
  • Data Protection and Sharing
  • Remote Work and BYOD
  • Cloud and SaaS Usage
  • Generative AI Usage
  • Prohibited Activities
  • Security Incident Reporting
  • Monitoring and Privacy
  • Exceptions
  • Policy Violations and Enforcement
  • User Acknowledgment
  • Policy Review and Revision

This AUP template should be adapted to the organization's actual systems, risks, workforce, and legal obligations rather than copied without modification. CIS provides an AUP template aligned with its Controls as another useful reference for organizations developing their own policy.

How Does an AUP Connect With Cybersecurity Frameworks?

An AUP should not exist as an isolated document. It can reinforce broader cybersecurity governance by translating technical and organizational requirements into expected user behavior. For example, an AUP can complement controls covering:

  • Asset management
  • Account management
  • Access control
  • Data protection
  • Secure configuration
  • Security awareness
  • Incident response
  • Cloud usage
  • Third-party access

CIS maintains an AUP template alongside other policy resources, including policies for data management, account and credential management, software asset management, and incident response. This allows organizations to build a more coherent policy environment instead of creating disconnected documents that contradict one another.

An Acceptable Use Policy should align with the organization’s broader cybersecurity and information security requirements. Relevant ISO 27001 Controls can provide a structured basis for defining acceptable use of information assets, access privileges, devices, and organizational systems.

Partner with INTERCERT for independent Audits and Assessments aligned with internationally recognized standards.

Embedding Acceptable Use into Security Governance 

An effective Acceptable Use Policy is not simply a list of prohibited activities or another document stored in an organization’s policy repository. It establishes a clear connection between user behavior, technology use, information protection, and cybersecurity risk. For organizations across Africa, that connection becomes increasingly important as cloud services, remote work, mobile devices, third-party access, and generative AI become part of everyday operations. A strong AUP defines what users can do, what they must avoid, how sensitive information should be handled, and how violations or security incidents are addressed.

Creating the policy is only the starting point. Its value comes from making the requirements understandable, aligning them with technical and organizational controls, obtaining user acknowledgment, and reviewing them as technology and risks evolve. Organizations looking to strengthen their information security governance can also align their AUP with established frameworks and certification requirements to create a more consistent and demonstrable control environment.

Organizations looking to improve their information security framework can leverage INTERCERT’s independent assessment capabilities and certification expertise. Through qualified auditors and globally recognized certification practices, INTERCERT helps organizations demonstrate that their security and governance processes align with established standards, providing credible assurance to customers, business partners, and other stakeholders.

 

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved