Project

General

Profile

Acceptable Use Policy » History » Version 1

David Leedom, 03/25/2026 06:43 PM

1 1 David Leedom
# Acceptable Use Policy
2
3
{{toc}}
4
5
---
6
7
## Document Control
8
9
| Field              | Details                              |
10
|--------------------|--------------------------------------|
11
| **Policy Title**   | Acceptable Use Policy                |
12
| **Policy Owner**   | [IT Security / CISO Name]            |
13
| **Approved By**    | [Executive Sponsor Name]             |
14
| **Effective Date** | [YYYY-MM-DD]                         |
15
| **Review Cycle**   | Annual (or upon significant change)  |
16
| **Classification** | Internal                             |
17
18
### Version History
19
20
| Version | Date       | Author          | Description of Changes           |
21
|---------|------------|-----------------|----------------------------------|
22
| 1.0     | YYYY-MM-DD | [Author Name]   | Initial policy creation          |
23
| 1.1     | YYYY-MM-DD | [Author Name]   | [Brief description of changes]   |
24
| 1.2     | YYYY-MM-DD | [Author Name]   | [Brief description of changes]   |
25
26
---
27
28
## 1. Purpose
29
30
This Acceptable Use Policy (AUP) defines the acceptable and prohibited uses of Catalyst Aviation's information systems, networks, data, and technology resources. The purpose of this policy is to protect Catalyst Aviation, its employees, partners, and clients from harm caused by the misuse of company assets and data.
31
32
This policy supports Catalyst Aviation's commitment to SOC 2 Trust Services Criteria, specifically Common Criteria CC6.1 through CC6.8 (Logical and Physical Access Controls).
33
34
---
35
36
## 2. Scope
37
38
This policy applies to:
39
40
- All employees, contractors, consultants, temporary staff, and third-party agents ("users") who access Catalyst Aviation systems or data.
41
- All company-owned and personal devices used to access company resources.
42
- All company networks, cloud environments, SaaS platforms, email systems, and communication tools.
43
44
---
45
46
## 3. General Acceptable Use
47
48
### 3.1 Acceptable Use
49
50
Company information systems are provided primarily for business purposes. Users are expected to:
51
52
- Use company systems responsibly, ethically, and in compliance with all applicable laws and regulations.
53
- Protect their authentication credentials and never share passwords or access tokens.
54
- Lock or log out of workstations when unattended.
55
- Report any suspected security incidents, policy violations, or vulnerabilities immediately to [IT Security Team / Helpdesk email].
56
- Complete all required security awareness training within designated timeframes.
57
58
### 3.2 Prohibited Use
59
60
Users must not:
61
62
- Use company systems for illegal activities, harassment, discrimination, or any purpose that violates company policy.
63
- Attempt to bypass, disable, or interfere with security controls, firewalls, or access restrictions.
64
- Install unauthorized software, browser extensions, or hardware on company-owned devices without prior IT approval.
65
- Access, download, or distribute obscene, offensive, or inappropriate material using company resources.
66
- Use company systems for personal commercial gain or to operate a personal business.
67
- Share, forward, or store company data in unauthorized locations or with unauthorized individuals.
68
69
---
70
71
## 4. Authentication and Access Control
72
73
- Users must use unique credentials and must not share accounts or passwords under any circumstances.
74
- Multi-factor authentication (MFA) is required for all systems that support it, including VPN, email, cloud platforms, and administrative consoles.
75
- Passwords must comply with Catalyst Aviation's Password Policy (minimum length, complexity, rotation requirements).
76
- Access to systems and data is granted on a least-privilege basis. Users should only request access necessary to perform their job functions.
77
- Users must notify IT immediately if they suspect their credentials have been compromised.
78
79
---
80
81
## 5. Data Handling and Classification
82
83
### 5.1 Data Classification Levels
84
85
All company data must be handled according to its classification level:
86
87
| Classification   | Description                                                                 | Examples                                      |
88
|------------------|-----------------------------------------------------------------------------|-----------------------------------------------|
89
| **Confidential** | Highly sensitive data; unauthorized disclosure causes significant harm      | PII, financial records, credentials, PHI      |
90
| **Internal**     | Internal business data; not intended for public release                     | Internal memos, project plans, org charts     |
91
| **Public**       | Information approved for public distribution                                | Marketing materials, published blog content   |
92
93
### 5.2 Handling Requirements
94
95
| Requirement          | Confidential                          | Internal                            | Public             |
96
|----------------------|---------------------------------------|-------------------------------------|--------------------|
97
| **Storage**          | Encrypted, access-controlled systems  | Approved company systems only       | No restrictions    |
98
| **Transmission**     | Encrypted in transit (TLS/VPN)        | Encrypted in transit preferred      | No restrictions    |
99
| **Sharing**          | Need-to-know, approved channels only  | Internal recipients only            | No restrictions    |
100
| **Disposal**         | Secure deletion / shredding           | Secure deletion                     | Standard disposal  |
101
| **Labeling**         | Required                              | Recommended                         | Optional           |
102
103
### 5.3 Data Handling Rules
104
105
- Users must not store Confidential or Internal data on personal devices, personal cloud accounts (e.g., personal Google Drive, Dropbox), or removable media unless explicitly authorized and encrypted.
106
- Data must not be transmitted via unencrypted channels (e.g., unencrypted email, SMS, public file-sharing services).
107
- Users must follow data retention and disposal schedules as defined in the Data Retention Policy.
108
- Any accidental exposure or loss of Confidential data must be reported immediately to [IT Security / Privacy Officer].
109
110
---
111
112
## 6. Remote Work and BYOD
113
114
### 6.1 Remote Access Requirements
115
116
- Remote access to company systems must occur through the company-approved VPN or zero-trust access solution.
117
- Users must ensure their home network is secured with WPA2/WPA3 encryption and a strong, unique router password.
118
- Work performed in public locations (e.g., cafes, airports) must use a VPN at all times; users should use privacy screens and avoid accessing Confidential data on public Wi-Fi without VPN protection.
119
- Remote sessions must be terminated when not actively in use.
120
121
### 6.2 Bring Your Own Device (BYOD)
122
123
Personal devices used to access company resources must meet the following minimum requirements:
124
125
- Operating system is up to date with the latest security patches.
126
- Device-level encryption is enabled (e.g., FileVault, BitLocker, or equivalent).
127
- A screen lock with a strong passcode or biometric authentication is enabled.
128
- Antivirus/endpoint protection software is installed and current (if applicable to the platform).
129
- The device must not be jailbroken or rooted.
130
- Company reserves the right to remotely wipe company data from personal devices upon termination or suspected compromise.
131
132
### 6.3 Physical Security
133
134
- Company-issued devices must be physically secured at all times (locked in a bag, drawer, or safe when unattended).
135
- Loss or theft of any device containing company data must be reported to IT within 24 hours.
136
137
---
138
139
## 7. Cloud Services and SaaS Usage
140
141
### 7.1 Approved Services
142
143
- Users may only use cloud services and SaaS platforms that have been vetted and approved by IT / Information Security.
144
- A current list of approved services is maintained at [link to approved software register or wiki page].
145
- Users must not sign up for or use unapproved cloud services to store, process, or transmit company data (commonly referred to as "Shadow IT").
146
147
### 7.2 SaaS Account Management
148
149
- All SaaS accounts must be provisioned through IT or an approved self-service process.
150
- Company SSO (Single Sign-On) must be used wherever supported.
151
- Users must enable MFA on any SaaS account that does not support SSO.
152
- Users must not use personal email addresses to create accounts for company business purposes.
153
154
### 7.3 Cloud Data Storage
155
156
- Company data stored in cloud platforms must reside in approved regions and comply with data residency requirements.
157
- Sharing permissions in cloud storage (e.g., Google Drive, SharePoint, Confluence) must follow least-privilege principles. Default sharing should be restricted to specific named individuals, not "anyone with the link."
158
- Users must periodically review and revoke unnecessary sharing permissions on files and folders they own.
159
160
### 7.4 Third-Party Integrations and API Access
161
162
- Connecting third-party applications or integrations to company SaaS platforms (e.g., OAuth app connections, Slack bots, browser extensions) requires prior IT Security approval.
163
- Users must not grant broad or unnecessary permissions to third-party integrations.
164
165
---
166
167
## 8. Email and Communications
168
169
- Company email and messaging systems (e.g., Slack, Teams) are for business use. Limited personal use is permitted provided it does not interfere with job duties or violate this policy.
170
- Users must not open suspicious attachments or click unverified links. Suspected phishing emails must be reported to [phishing report alias or IT Security].
171
- Auto-forwarding company email to external personal accounts is prohibited.
172
- Confidential information must not be sent via email unless encrypted or shared via an approved secure method.
173
174
---
175
176
## 9. Monitoring and Privacy
177
178
Catalyst Aviation reserves the right to monitor, log, audit, and review all activity on company-owned systems, networks, and accounts. This includes but is not limited to:
179
180
- Email and messaging content
181
- Web browsing activity
182
- File access and transfers
183
- VPN and remote access logs
184
- Cloud and SaaS activity logs
185
186
Users should have no expectation of privacy when using company resources. Monitoring is conducted in accordance with applicable laws and regulations.
187
188
---
189
190
## 10. Incident Reporting
191
192
Users are required to immediately report any of the following to [IT Security Team / Contact]:
193
194
- Suspected or confirmed security breaches or data leaks
195
- Lost or stolen devices containing company data
196
- Suspected phishing, social engineering, or unauthorized access
197
- Violations of this policy by any user
198
199
Reports can be submitted via [email, ticketing system, or hotline]. Good-faith reporting will not result in retaliation.
200
201
---
202
203
## 11. Enforcement and Consequences
204
205
Violation of this policy may result in disciplinary action, up to and including:
206
207
- Revocation of system access
208
- Formal written warning
209
- Suspension or termination of employment or contract
210
- Legal action where warranted
211
212
The severity of the response will be proportional to the nature and impact of the violation. All violations will be documented and reviewed by [HR and IT Security / Compliance Officer].
213
214
---
215
216
## 12. Policy Review
217
218
This policy is reviewed at least annually or whenever a significant change occurs in the business environment, technology infrastructure, or regulatory requirements. All material changes will be communicated to users and require re-acknowledgment.
219
220
---
221
222
## 13. Acknowledgment
223
224
By accessing Catalyst Aviation systems and resources, I acknowledge that I have read, understood, and agree to comply with this Acceptable Use Policy.
225
226
| Field                | Details             |
227
|----------------------|---------------------|
228
| **Employee Name**    | __________________  |
229
| **Signature**        | __________________  |
230
| **Date**             | __________________  |
231
| **Manager Name**     | __________________  |
232
| **Manager Signature**| __________________  |
233
234
---
235
236
## Related Policies
237
238
- Information Security Policy
239
- Password Policy
240
- Data Classification and Handling Policy
241
- Data Retention and Disposal Policy
242
- Incident Response Plan
243
- Remote Work Policy
244
- Vendor / Third-Party Risk Management Policy
245
246
---
247
248
*This document is the property of Catalyst Aviation and is classified as Internal. Unauthorized distribution is prohibited.*