Acceptable Use Policy (AUP)
An acceptable use policy defines how employees may use company systems, data, and accounts — the baseline document behind shadow IT, AI, and BYOD rules.
An acceptable use policy (AUP) is the document that defines how employees may use an organization's systems, networks, accounts, and data — and how they may not. It typically covers personal use of company devices, handling of confidential information, software installation, external services and AI tools, and the consequences of violations. Most employees meet it once, as a signature line in onboarding paperwork; whether it ever influences behavior again is what separates a control from a formality.
How it works
The AUP draws the official boundary that other security efforts depend on. Incident response needs it to establish that an action was unauthorized; HR and legal need it to act on violations; auditors ask for it under frameworks such as ISO 27001 and PCI DSS. In daily life, though, the policy competes with convenience. Where it is vague, outdated, or silent — on personal cloud drives, on unsanctioned apps, on pasting work data into personal AI accounts, on work from personal devices (BYOD) — employees fill the silence with whatever gets the job done. The gap between what the policy imagines and what people actually do is where unmanaged risk accumulates, usually invisibly until an incident surfaces it.
How to defend
Write the AUP for the reader, not the auditor: short, concrete, and current enough to name the tools employees actually reach for, including generative AI. Pair every prohibition with a sanctioned path — a policy that only says no to personal file sharing, without providing an approved equivalent, is a request to be ignored. Revisit it on a schedule, because a document that predates AI assistants cannot govern them. And close the loop with training: a rule read once at onboarding decays like any other memory, so the policies that matter should reappear in ongoing awareness training and in moment-of-risk reminders. Our guide to shadow AI at work shows what happens when policy and practice drift apart — and how to pull them back together.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo