## 1. Purpose

This policy defines acceptable use of company systems, devices, networks, applications, internet access, email, cloud services, and data.

The purpose is to reduce cybersecurity risk while allowing employees to perform their work effectively.

## 2. Scope

This policy applies to employees, contractors, temporary workers, and other authorized users of company technology or information.

**It applies to:**

- Company devices
- Approved personal devices used for work
- Email
- Internet access
- Messaging and collaboration tools
- Cloud and SaaS services
- Company accounts
- File storage
- Customer and employee information
- Company networks and remote access

## 3. Approved Business Use

Company systems should primarily be used for legitimate business activities.

**Limited personal use may be permitted where it:**

- Does not interfere with work
- Does not create cybersecurity risk
- Does not violate law or company policy
- Does not consume unreasonable company resources

## 4. Accounts and Credentials

**Users must:**

- Use their own assigned account where possible.
- Protect passwords and authentication credentials.
- Use the approved password manager where provided.
- Use MFA where required.
- Never approve an unexpected MFA request.
- Never share credentials unless an approved business process specifically requires controlled credential sharing.
- Never attempt to access systems or information they are not authorized to use.

## 5. Software, SaaS, and AI Tools

Users should only install or use approved software and services for company work.

**Company information should not be entered into unapproved:**

- Cloud applications
- File-sharing platforms
- AI tools
- Browser extensions
- Messaging applications
- Online converters
- Personal productivity services

New tools that will store, process, or transmit company information should be approved before use where required.

## 6. Email and Messaging

**Users should be cautious with:**

- Unexpected links
- Attachments
- QR codes
- Login requests
- Urgent payment requests
- Bank-detail changes
- Password or MFA requests
- Messages claiming to be executives, vendors, customers, or IT support

Suspicious messages should be reported promptly

## 7. Data Handling

**Users must:**

- Store company information in approved locations.
- Share sensitive information only with authorized recipients.
- Check recipients before sending sensitive information.
- Avoid public sharing unless specifically approved.
- Avoid sending company information to personal email accounts.
- Avoid using personal cloud storage for company data.

Report accidental disclosure promptly.

## 8. Device Use

**Users should:**

- Lock devices when unattended.
- Install required updates.
- Use company security software.
- Protect devices from theft or loss.
- Avoid disabling security controls.
- Report lost or stolen devices immediately.

Users should not deliberately bypass device restrictions or security settings.

## 9. Remote Work

**When working remotely, users should:**

- Use approved remote access methods.
- Protect devices from unauthorized access.
- Avoid public or shared computers for company work.
- Take reasonable precautions when using public Wi-Fi.
- Prevent unauthorized people from viewing sensitive company information.

## 10. Prohibited Activities

**Users must not knowingly:**

- Install malware
- Attempt unauthorized access
- Disable security controls without approval
- Circumvent company monitoring or access controls
- Use company systems for illegal activity
- Copy sensitive company data without business need
- Deliberately expose company information publicly
- Use another person's account without authorization
- Use company technology to attack or test external systems without authorization

## 11. Monitoring and Privacy

The company may monitor company-owned systems, accounts, networks, and services for legitimate security, operational, legal, and compliance purposes, subject to applicable law and company policy.

Users should not assume that activity performed through company systems is private.

## 12. Reporting

Users should immediately report:

- Suspicious emails
- Possible credential compromise
- Unexpected MFA prompts
- Lost devices
- Malware warnings
- Data mistakes
- Payment fraud attempts
- Unusual account activity
- Other suspected cybersecurity problems

## 13. Violations

Violations may result in access restrictions, corrective action, disciplinary action, contract action, or other measures appropriate to the circumstances and applicable law.

## Practical Rule

Use company technology for legitimate work, protect company information, use approved tools, and report anything suspicious quickly.
