1 / 9100%
1
Acceptable Use Policy
Acceptable Use Policy for Grand Incorporated.
Scott Price
Liberty University
Studies in Information Security, CSIS 340
February 8, 2021
2
Acceptable Use Policy
Acceptable Use Policy for Grand Incorporated.
Overview
The Acceptable Use policy for Grand Incorporated is a general overview of the
technology of Grand incorporated and to include any company owned asset as well as personal
devices used to access company information and addresses the acceptable use of these
technologies. Information security is of the upmost importance and these guidelines will aid in
decision making and proper use of assets. As stated in (Talesh S. 2018) Data breaches are a major
threat to businesses of any size. They are many issues that may arise from a data breach from
financial to public image and they all threaten the survival of companies. The goal of This
acceptable use policy is to provide guidelines that will help mitigate the risk of cyber-attacks.
The information technology team will establish guidelines and provide training materials, yet it
is the responsibility of each department and employee to learn and adhere to the guidelines.
Purpose
The Acceptable use policy is for Grand Incorporated is the guide and rules surrounding
the acceptable use of technology at Grand Incorporated. Any unacceptable behavior puts Grand
Incorporated at unnecessary risks including financial and cyber-attack. According to (Wekina
2014) there are many researchers that believe the most breaches of security are the result of
human error. The goal of Acceptable use policies is to eliminate these errors by providing an
outline of proper behaviors by individuals within Grand Incorporated.
General Objective
The protection of Data and Technology is of great importance to Grand Incorporated and
thus the acceptable use policy exist to mitigate risk to Grand Incorporated, its employees, and
those with whom Grand Incorporated conducts business. With adherence to the policy and
3
Acceptable Use Policy
oversight by department heads as well as information technology and information security staff
the potential risks will be mitigated, and important information safeguarded from cyber-attack
and potential theft. This policy extends to anyone accessing Grand Incorporated systems and
information.
Protocol
All employees and vendors are responsible for their behavior when conducting business
on behalf of Grand Incorporated and are expected to adhere to the acceptable use policy when
access any technology or information of Grand Incorporated. All as to remain vigilant to their
behavior as well as suspicious or risky behavior of others and are asked to report all violations or
concerns to a manger and to the Information Technology and Information Systems team. All
violations will be investigated, and an appropriate level of action will be taken to include
discipline and or training/retraining.
Scope
The acceptable use policy for Grand incorporated applies to any information, technology,
devices, and resources to conduct Business for Grand Incorporated. The includes any technology
used for such purpose whether owned or leased by the Grand Incorporated, an employee of
Grand Incorporated, a vendor, visitor, subsidiary, or any person conducting business on behalf of
Grand Incorporated. All individuals are required to adhere to the Acceptable Use Policy as well
as any federal, state, or local laws or regulations regarding the use of information or technology.
Policy Compliance
Guidelines for the acceptable use begin with the Ownership of information. Any Grand
Incorporated information on any electronic device remains the property of Grand Incorporated.
The user is responsible for securing that data and protecting the device in accordance with
4
Acceptable Use Policy
information security policies regardless of ownership of device. If the device is lost, stolen, or
breach has occurred it must be promptly reported to the information security team. All
information belonging to Grand Incorporated should only be accessed when necessary and
within the scope of assigned job duties. Any device containing Grand incorporated should only
be used for official company business and no personal use of internet, communication, etc.
Personal use of devices can lead to unintended consequences. Personal use of internet can put
information at risk, caution must be exercised when utilizing technology for personal needs. All
network traffic and information systems will be monitored and is subject to acceptable use
guidelines relating to Grand Incorporated business use. Uses that are unacceptable are, illegal
activities, violating the rights of others personal or professional, violating copyright laws, access
Grand Incorporated information for anything other than company business, activities that could
introduce malicious programs to Grand Incorporated’s network, revealing sensitive information
to others, accessing or transmitting content that is not appropriate for the workplace or that
violates HR policies or sexual harassment laws, promoting false information, conducting
competing business, circumventing network security, or social media unless part of job
responsibilities. This list is not exhaustive, and judgement should be exercised with use of
company assets.
Findings
Acceptable use policies are a major policy for every company in today’s world. When
email, webpages, databases, etc. are literally at our fingertips with mobile devices it is important
to set ground rule for who, what, where, when, and how data and systems are accessed to protect
information security. According to (Dyrli 2000) it is important to have a very detailed acceptable
5
Acceptable Use Policy
use policy so that there is very little question as to what is unacceptable and most importantly
update frequently and very clear about expectations while being readily accessible. Making sure
that users are aware of the policy is a large portion of the battle after establishing the policy.
There are many corners of the internet and if left on their own users can knowingly and
unknowingly put the company at risk. Social media, applications, malware, etc. are all major
concerns and areas where breaches can occur, information can unknowingly be shared, viruses
can be allowed into the network. Outlined in (Benton 2016) have an acceptable use policy is a
must and adhering to it is paramount. Many users have their own devices and have a way to
safeguard company information is key. Device management is essential whether that be the
user’s mobile device with company information, or a company issued computer. Having the
ability to control and monitor what is used is a great tool to keep information protected and to
monitor what company systems are being used for. Also noted by (Benton 2016) is that it is
important to have control but to ensure that systems are still usable so that not to discourage use
by users.
It is however important to realize that as stated earlier human error is a major issue when it
comes to security and training is an important aspect to any acceptable use policy. There are
always going to be varying levels of technological knowledge amongst users and without
training there can be gaps that are easy to exploit. (Sun 2021) demonstrates that one of the more
common cyber-attacks does not involve brute force so sophisticated coding, it is simply to find
the human vulnerability and exploit it. This concept is known as social engineering. It can be in
the form of a website or communication that preys on the natural curiosity of users or it could be
the manipulation of a person commit an act that would not normally do. Having an acceptable
6
Acceptable Use Policy
use policy that clearly outlines prohibited behaviors and uses particularly for the internet can
help to mitigate these concerns.
Related Standards
The Team
The acceptable use policy is implemented to ensure that users are aware of the boundaries
when it comes to computer systems. The company will train all employees on what is acceptable
and will also provide training to the department heads so that teams can be made aware of any
exceptions based on their job responsibilities. The information security and information
technology teams will be trained to respond to unacceptable behaviors as well as coaching
techniques and method to assist in the continued training of the company’s employees.
Internal Training
Training is the cornerstone of any successful policy. Without the knowledge and training
it would be unreasonable to expect someone to adhere to a policy like the acceptable use policy.
Unfortunately, it would be difficult to include every possible issue that may arise, and some level
of personal decision is to be expected. Training is the key to equipping employees to make
informed decisions relating their actions. The company will provide training for all employees
and will update the acceptable use document often to reflect every changing technological
landscape. When updated all users will be made aware of any changes to the acceptable use
policy. Expectations will be clearly explained, and team members will be made available to
answer any questions and provide guidance.
Definitions
7
Acceptable Use Policy
•
Data Breach: Situation where sensitive and private data have been tampered with or
accessed or stolen.
•
Cyber-attack: an attempt by hackers to damage or destroy a computer network or system.
•
Social Engineering: a strategy used that relies on human interaction and involves tricking
people into breaking standard security practices. Exploiting human vulnerability.
•
Electronic Device: a device that is used for audio, video, or text communication or any
other type of computer or computer-like instrument.
•
Social Media: websites and applications that enable users to create and share content or to
participate in social networking.
Terms
With the threat of cyber attacks growing daily the need to protect the information and
systems of the company is at the forefront of daily operations. The information security and
information technology teams play a pivotal role in setting ground rules for the users to protect
assets. It will be the goal of these teams to bring awareness to the users of Grand Incorporated so
that policies can be adhered to and safeguards be put into place. Working alongside department
heads boundaries will be set so that the ability to perform job responsibilities will not be
hindered yet will also work with human resources and legal departments to make sure that proper
steps are followed so that users can and will be held accountable for any behaviors that are not
appropriate.
Summary
With the ever-growing reliance on technology and the ability to gather, store, and access
information from many devices in many places it is vital for every company to have an
acceptable use policy. Without such a policy there is little ability to hold users accountable and
8
Acceptable Use Policy
expect a standard to be followed. There are many threats to companies today and the best way to
protect against financial, personal, and political impact is to safeguard information as best as you
can. Without a clear policy that states what a user can and cannot do and a framework for
deciding what the correct course of action should be in the event it is not clearly laid out, a
company can expect there to be problems. When users are left to make their own decisions often,
they will be wrong. Providing training, a clear policy, and making available help in the form of
guidance is a major step toward maintaining information security. Having an acceptable use
policy also helps to deter bad behavior by outlining the potential consequences of a violation.
There are many ways a user can get into hot water with devices today. Giving a clearly defined
operating procedure will help to mitigate issues and in the event of an issue could lessen the
impact as well as provide recourse for the company.
9
Acceptable Use Policy
References
Talesh, S. (2018). Data Breach, Privacy, and Cyber Insurance: How Insurance Companies Act as
“Compliance Managers” for Businesses. Law & Social Inquiry., 43(2), 417–440.
https://doi.org/10.1111/lsi.12303
Wikina, S. B., PhD. (2014). What Caused the Breach? An Examination of Use of Information
Technology and Health Data Breaches. Perspectives in Health Information
Management, , 1-5. http://ezproxy.liberty.edu/login?qurl=https%3A%2F
%2Fwww.proquest.com%2Fscholarly-journals%2Fwhat-caused-breach-examination-use-
information%2Fdocview%2F1690624031%2Fse-2%3Faccountid%3D12085
Sun, L. (2021). Social Engineering in Cybersecurity: Effect Mechanisms, Human Vulnerabilities
and Attack Methods. IEEE Access : Practical Innovations, Open Solutions., 9, 11895–
11910. https://doi.org/10.1109/ACCESS.2021.3051633
Benton, M. (2016). Business security in the mobility era: If you don't have an acceptable use
policy you need to create one and adhere to it. New Hampshire Business Review, 38(16),
58.
Dyrli, O. (2000). Is Your Acceptable Use Policy Acceptable? Curriculum Administrator., 36(8).
Security Policy Templates. Information Security Policy Templates | SANS Institute. (2014).
https://www.sans.org/information-security-policy/.
Students also viewed