Skip to content

Acceptable Use Policy

What is Acceptable Use Policy?

A document that outlines the rules and guidelines for using an organization's IT resources, defining permitted and prohibited activities for users.

Information Security

What the standards actually require on acceptable use policy

Requirements naming acceptable use policy across 6 standards, quoted from the control text.

Implement policies specifying proper functions, manner of performance, and physical attributes for workstations accessing ePHI. NIST recommends acceptable use policy and remote worker provisions.

164.310(b) · Workstation Use (Standard)

Standard 7 per Section 35 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall be processed in a manner that ensures appropriate security including protection against unauthorised or unlawful processing + accidental loss + destruction or...

JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience · Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pseudonymisation + Risk-Based Security

Implement policies specifying proper functions, manner of performance, and physical attributes for workstations accessing ePHI. NIST recommends acceptable use policy and remote worker provisions.

164.310(b) · Workstation Use (Standard)

Per Philippines RA 10175 Sections 4(a) and Cybercrime Offences: prevent + cooperate in investigation of cybercrime offences. Requirements include (a) understand Illegal Access (Section 4(a)(1)) - unauthorised access to computer systems + (b) Illegal Intercepti...

PHILCC-1 · Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)

Questions people ask about acceptable use policy

What is Acceptable Use Policy?
A document that outlines the rules and guidelines for using an organization's IT resources, defining permitted and prohibited activities for users.
Why is Acceptable Use Policy important for compliance?
Acceptable Use Policy is a key concept in Information Security. Understanding acceptable use policy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Acceptable Use Policy?
Acceptable Use Policy appears in the requirement text of HIPAA Security Rule, Israel Protection of Privacy Law (5741-1981), Jamaica Data Protection Act 2020, Monetary Authority of Singapore Technology Risk Management Guidelines, NIST SP 800-66 Rev 2. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Acceptable Use Policy?
Explore our compliance framework pages to see how acceptable use policy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Acceptable Use Policy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.