Acceptable
Use Policy.
Rules of the road for using Cyber Compliance Pro IT systems, networks and cloud services — designed to keep our people, our data and our customers safe.
1 Purpose of This Acceptable Use Policy
This acceptable use policy outlines acceptable and unacceptable use of the organisation’s IT systems and resources to ensure their secure and responsible use. It sets clear expectations so that every user can do their work confidently while protecting the organisation, its customers and its data from avoidable risk.
2 Scope of This Acceptable Use Policy
This acceptable use policy applies to all employees, contractors and third-party users accessing or using organisational IT systems, including email, internet, cloud services, collaboration platforms, corporate devices and mobile devices — whether owned by the organisation or personally owned and used for work.
3 Acceptable Use
Users are expected to:
Use organisational IT systems only for authorised business activities.
Protect user credentials and never share passwords with anyone, including colleagues.
Report any suspected security incidents, phishing attempts or breaches immediately.
Ensure data is accessed and stored securely in line with information classification levels.
4 Unacceptable Use
The following activities are prohibited:
Accessing, storing or distributing offensive, illegal or discriminatory material.
Using IT systems for personal financial gain or unauthorised commercial activity.
Circumventing or attempting to bypass security controls such as firewalls, filters, MFA or endpoint protection.
Downloading unauthorised software or knowingly introducing malware to any system.
Connecting unapproved personal devices to the corporate network.
5 Monitoring & Privacy
As a result, the organisation reserves the right to monitor IT systems to ensure compliance with this policy and to protect the security and integrity of its systems and data. Specifically, users have no expectation of privacy when using corporate resources.
Note. Overall, monitoring is carried out in accordance with applicable laws and our Privacy Policy. Personal information collected through monitoring is handled with the same care as any other personal information we hold.
6 Acceptable Use Policy Enforcement
Ultimately, non-compliance with this policy may lead to disciplinary action, including revocation of access privileges or termination of employment or engagement. Where conduct may also constitute a criminal offence, the matter may be referred to the appropriate authorities.
Report an incident. If you believe this policy has been breached, or you suspect a security incident, contact the Information Security Officer immediately at security@cybercompliancepro.com.
7 Review
Typically, this policy must be reviewed annually or whenever significant technology, business or legal changes occur. The effective date at the top of this page indicates the most recent revision.
8 Contact Details
For questions about this policy, or to report suspected non-compliance, please contact: