# Acceptable Use Policy

> **Template — adapt before use.** Replace `[bracketed]` placeholders and have an owner approve it. Starting point only; not legal advice.

| | |
|---|---|
| **Owner** | [Role] | **Approved** | [YYYY-MM-DD] | **Review** | Annual | **Version** | 1.0 |

## 1. Purpose & scope
Defines acceptable use of [Company Name] systems, devices, networks, and data by all employees, contractors, and third parties.

## 2. Acceptable use
- Use company resources for legitimate business purposes; incidental personal use must not interfere with work or violate this policy.
- Protect credentials; never share passwords or MFA factors.
- Lock devices when unattended; report lost or stolen devices immediately.
- Store company data only in approved systems; do not move sensitive data to personal accounts, devices, or unapproved cloud services.

## 3. Prohibited use
- Accessing data or systems without authorization.
- Disabling or circumventing security controls (antivirus, encryption, MFA, logging).
- Installing unapproved software or connecting unapproved devices to company networks.
- Using company resources for illegal activity, harassment, or to infringe intellectual property.
- Sending sensitive data over unapproved channels.

## 4. Monitoring
The company may monitor use of its systems to the extent permitted by law. Users should have no expectation of privacy in company systems beyond what law requires.

## 5. Enforcement
Violations may result in disciplinary action up to termination and, where applicable, legal action. Exceptions require written approval from the policy owner.

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
