Free Tool

Acceptable Use Policy Template
sixteen sections for scope, credentials, devices, BYOD, AI tool use, monitoring, prohibited acts, and enforcement

A free, copy-ready acceptable use policy (AUP) template. Sixteen structured sections covering policy charter and authority, scope and applicability across user populations, acknowledgement and onboarding mechanics, acceptable use principles and core obligations, account and credential and authentication rules, device and endpoint and BYOD rules, network and remote-access and travel rules, internet and web and social media rules, email and messaging and communication rules, data handling and classification and retention rules, AI and generative AI and machine-learning tool rules, software and application and shadow-IT rules, prohibited acts and security-relevant misconduct, monitoring and privacy and lawful basis, incident reporting and security concern escalation, and enforcement and sanctions and exceptions and document control. Aligned with ISO/IEC 27001 Annex A 5.10 and A 6.2 to A 6.4, SOC 2 CC1.4 and CC2.2, PCI DSS Requirement 12.3, HIPAA 164.308(a)(5), NIST CSF 2.0 GV.PO and PR.AT, NIST SP 800-53 PL-4 and AT-2, CIS Critical Security Controls Control 14, NIS2 Article 21(2)(g), DORA Article 13, and GDPR Article 32.

No credit card required. Free plan available forever.

Loading tool...

Carry the AUP evidence chain on one workspace rather than across folders

SecPortal pairs the signed AUP to the workspace document record so the sign-off chain, the annual reconfirmation, the amendment triggers, the framework mapping, and the security findings that touch AUP-relevant misuse all live on one workspace with named-actor activity log. Free plan available.

No credit card required. Free plan available forever.