On this pagePolicy Details

Information Security and Acceptable Use Policy

Policy Details

Company[Company legal name]
Scope[Covered services systems and people]
Policy Version[Company policy version]
Status[Draft or Approved]
Effective Date[Effective date or Pending approval]
Policy Owner[Policy owner role]
Approving Role[Approving role]
Next Review[Next review date]
Security Reporting Channel[Security reporting channel]
Backup Security Contact[Backup security contact]

Security Rules

1. Scope and Responsibility

Upon authorized adoption, these rules apply to [Company legal name] (the Company) within the scope stated in Policy Details. They apply to employees and other authorized users working within that scope. Contractor access requirements are established through the relevant engagement and access terms. The rules cover work performed remotely as well as at Company premises. Nothing in this policy restricts legally protected reporting or communications.

The Policy Owner maintains this policy, coordinates security work with system owners and escalates unresolved risks to the Approving Role. Managers explain the rules relevant to each person's duties and arrange the access and training those duties require. Users follow these rules and report difficulties or suspected incidents through the reporting channels below.

2. Authorized Use and Access

Use work accounts and information only for authorized duties. Request new or changed access through [Access request channel]. The responsible manager and system owner must approve the access needed for the role before it is granted. Administrative privileges are limited to tasks that require them and use separate administrative accounts where supported.

Do not share personal work-account credentials, lend an authenticated session or approve an unexpected authentication request. Use a different password for each account and keep passwords in a Company-authorized password manager. Enable multi-factor authentication for work accounts that support it. A system that cannot meet these requirements needs a documented exception before use.

Do not disable security safeguards, install unauthorized software, access another person's information without permission or test systems outside an expressly authorized testing scope. Use Company resources lawfully and respect others' intellectual property.

3. Devices and Workspaces

Use devices authorized by the Company for work. Keep their operating systems and applications supported and updated, with automatic security updates enabled where available. Enable storage encryption on laptops and other devices holding work data, and maintain the endpoint protection required by the system owner. Report an incompatible safeguard rather than disabling it.

Lock the screen before leaving a device unattended and enable automatic screen locking. Protect devices against loss and unauthorized use. Keep confidential papers and screens out of public view; secure papers when not in use and use authorized confidential disposal arrangements.

4. Personal Devices

Personal-device access to work information: [Personal device rule].

5. Personal-Device Authorization

Where the rule permits personal devices, a device may be used only after the system owner authorizes it and confirms that it meets the device rules above. Keep work information in the approved work services rather than personal accounts. Before access begins, the Company and user must establish how work information will be removed without deleting unrelated personal information, including when the device is lost or the engagement ends.

6. Information Handling

For staff communication, document storage and collaboration, use [Approved staff work services]. Other work systems, including production services, require the responsible system owner's approval before use. Do not put nonpublic work information in personal email, personal storage, unapproved applications or unapproved AI services.

Share nonpublic information only with authorized recipients who need it for the work. Check recipients and permissions before sharing. Use restricted links or an approved encrypted transfer method instead of public links. Do not move work information to removable storage without the system owner's approval.

Keep records in their designated work locations so they remain available to the Company. Follow applicable retention instructions and preservation holds; ask the Policy Owner before deleting records if those instructions are unclear. Do not independently destroy potential incident evidence.

7. Remote Working

Use an authorized device and approved access methods when working remotely. Do not use a shared public computer for work accounts. Protect remote meetings, screens and conversations from unauthorized access.

Use encrypted connections to work services. On a network whose security is uncertain, use the Company's approved secure remote-access method or a trusted connection instead. Stop and report unexpected certificate warnings or requests to bypass connection safeguards.

8. Security Reporting

Report a lost device, suspicious sign-in, suspected disclosure, malware warning or other suspected security incident promptly to [Security reporting channel]. If that channel is unavailable, compromised or unsuitable for the concern, use [Backup security contact]. Do not wait to prove that an incident occurred.

Give the time, affected service or device and a brief account of what happened, without sending passwords or unnecessary personal or customer information. Preserve available evidence and follow the authorized responder's directions. Do not conduct an independent investigation, erase Company devices or Company information without the responder's direction, or contact a suspected attacker. The Policy Owner coordinates response and appropriate internal escalation.

The Company will not retaliate against a person for a good-faith security report. No internal reporting requirement prevents a legally protected report to a government agency or other protected communication.

9. Joining, Changing Roles and Leaving

Before granting access, the manager identifies the policies and security instruction relevant to the role and makes them available to the user. The Company records delivery and requests acknowledgment of the identified policy versions. Role-specific training is assigned and its completion is recorded separately.

Managers notify the access administrator through the access-request channel when duties change or an engagement will end. The administrator adjusts or removes access at the authorized change or departure time and records the action. Suspected misuse is escalated for an immediate access decision.

On departure, return Company equipment and transfer work records to the designated owner. Do not retain copies merely because they were created during the engagement.

10. Personal-Device Departure

Remove Company accounts and information from authorized personal devices using the agreed process, subject to preservation instructions.

11. Exceptions and Maintenance

An exception requires the Approving Role's recorded decision identifying its scope, reason, risk, alternative safeguards, responsible owner and expiry or review date. The Policy Owner keeps the exception record and follows up when the decision expires or conditions change.

The Policy Owner reviews this policy by the Next Review date and after a material change in services, risks or obligations, or an incident that reveals a gap. Approved revisions are versioned and communicated to affected users. The Company may investigate suspected violations and take protective access measures or other action consistent with applicable law and its other policies.

Additional adopted policies and procedures are identified in [Related policy titles versions and locations]. A proposed or unavailable document is not incorporated merely by being mentioned in a draft.

Authored by OpenAgreements contributors. Licensed under CC BY 4.0.