Acceptable Use Policy
An acceptable use policy is a set of rules that tells people how they are allowed to use an organization's computers, networks, internet, and other technology resources. It spells out what behavior is appropriate and what is not, helping employees understand their responsibilities. Think of it as digital guardrails that protect both the organization and its users.
An Acceptable Use Policy (AUP) is a governance document that defines the practices, rules, and conditions users must comply with when accessing an organization's networks, devices, systems, internet access, or other information resources. It establishes the boundaries between approved and prohibited use, typically addressing areas such as authorized access, prohibited activities, data handling expectations, and user accountability. In practice, an AUP is one component of a broader security policy framework and generally requires acknowledgment by users to be enforceable; its effectiveness depends on clear scope, consistent enforcement, and integration with related policies rather than the document alone. Note that an AUP defines expected user conduct and does not by itself provide technical enforcement controls, which must be implemented separately.
Why it matters
An acceptable use policy establishes the baseline expectations for how people interact with an organization's technology resources, and that clarity matters because much of an organization's risk exposure originates from routine user behavior rather than sophisticated external attacks. Without a documented and acknowledged AUP, an organization has no consistent reference point for what constitutes appropriate versus prohibited use, which weakens its ability to hold users accountable, enforce disciplinary action, or demonstrate that expectations were communicated. In many engagements, a security leader will treat the AUP as foundational because it connects individual conduct to broader governance and risk objectives.
An AUP also plays a role in the human dimension of security governance, which is often more about business risk and behavior than pure technology. As the FBI's published policy notes, the intent is generally not to impose restrictions contrary to a culture of openness and trust, but to set reasonable boundaries that protect both the organization and its users. A well-scoped policy balances usability with protection, and its value depends heavily on organizational maturity, clear scope, and consistent enforcement rather than the existence of the document itself.
It is important to recognize what an AUP does not do. The policy defines expected user conduct but does not by itself provide technical enforcement; controls such as access restrictions, monitoring, or filtering must be implemented separately. A common expert correction is that an AUP is only one component of a broader security policy framework, and treating it as a standalone safeguard, or assuming it prevents misuse on its own, overstates what a governance document can accomplish.
Who it's relevant to
Inside AUP
Common questions
Answers to the questions practitioners most commonly ask about AUP.