Doc owner: TBD
Rationale: Acceptable Use Policy
Applies to
- Acceptable Use Policy
- Physical Security Policy — clean-desk/clear-screen and storage-device additions
- Network Security Policy — simultaneous-network addition
Design notes
This change closes the content gaps that a standard SOC 2 / ISO 27001 Acceptable Use Policy is expected to cover (per the Drata reference template), while keeping Allied's house style of a lean policy stack rather than one monolithic document.
Definitive copy lives here, not in Drata. Allied maintains the authoritative AUP in the org repo and publishes it at docs.a2i.network. The Drata policy object links to the published page rather than holding its own copy. Drata's Acceptable Use Policy monitoring test checks for existence, management approval, and accessibility — so the policy must additionally be assigned an owner and moved off status: draft, and acknowledgements must be kept current, for that test to pass. Content completeness alone does not clear it.
Coverage is distributed by domain, not duplicated. Many topics in the reference template already live in other Allied policies (encryption, firewalls, EDR/anti-malware, access revocation, vulnerability management). Rather than copy them into the AUP and risk drift, the AUP cross-references them and only states acceptable-use-specific requirements directly. New material was placed where it belongs:
- Clean desk / clear screen, printer handling, storage-device risk assessment → Physical Security Policy (it already held a TBD slot for clear-desk, and Allied has no controlled office, so these are behavioural rather than premises controls).
- Not bridging Allied connections to an untrusted network simultaneously → Network Security Policy. The reference template's VPN / Active Directory / application-proxy language was deliberately not copied, because Allied uses a Cloudflare ZTNA + WARP model with no corporate network or perimeter VPN; the control was re-expressed to fit that model.
- Prohibited-activities list, monitoring notice, security-awareness training, leaver obligations, breaches and sanctions → the AUP itself, as these are core acceptable-use statements.
Still open. Quantified personal-use limits and a position on generative-AI tool use remain TBD and are flagged in the policy.
Related decisions
Link DEC-* records when relevant.
Changelog
See Git history for this file and for the definitive pages.