Skip to content

Acceptable Usage Policy

Acceptable USAGE POLICY

Version history

Version Number Date Description Created By Approved By
0.1 17/Apr/2024 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Purpose

This policy is designed to establish best practices for the acceptable use of information and IT assets in alignment with the Information Security Policy of tecciance.

Scope

The scope of this policy applies to all users of Information and IT resources in tecciance. This procedure is applicable to all users with access to information and IT assets in tecciance.

Responsibilities

The primary responsibility for implementing this Policy lies with IST & Department Heads. The IS team shall execute this Procedure under the guidance of the Leadership Team and in coordination with Department Heads.

Policy

Under no circumstances is an employee of tecciance authorized to engage in any activity that violates local, state, national, and/or international law while using tecciance - owned resources. The following activities are prohibited. Employees may be exempted from these restrictions during their legitimate job responsibilities (e.g., systems administration staff may need to disable network access of a host disrupting production services). The lists below are not exhaustive but provide a framework for activities falling under unacceptable use.

System and Network Activities

The following activities are prohibited, without exceptions:

  • Engaging in any activity violating applicable local, state, national, and international laws and Information Security Policy of tecciance during employment.

  • Violating the rights of any person or company protected by copyright, trade secret, patent, or other intellectual property laws.

  • Unauthorized copying of copyrighted material, including digitization and distribution of copyrighted material without appropriate licensing.

  • Introducing malicious programs into the network or server. Revealing account passwords to unauthorized individuals.

  • Using company computing assets for procuring or transmitting material violating sexual harassment or hostile workplace laws.

  • Making fraudulent offers or statements.

  • Providing information about tecciance employees to external parties. Engaging in covert information gathering on company assets' business activities. Exporting software or technical information in violation of laws.

  • Leaving equipment unattended without proper protection. Accessing data without authorization.

  • Interfering with network communication or denying service to users. Attempting to evaluate environmental weaknesses without authority.

Email and Communications Activities

  • Sending unsolicited email messages (spam).

  • Harassing others via email, telephone, or paging.

  • Unauthorized use or forging of email header information. Creating or forwarding chain letters or email hoaxes.

  • Disclosing internal, confidential, or restricted information to third parties. Sending other company's confidential information to third parties.

  • Posting non-business-related messages to large Usenet newsgroups. Sending mails to clients without authorization from Business Head.

Enforcement

Any employee found violating this policy may face disciplinary actions as per the Disciplinary Action Policy.

Procedure

General

  • Users will be accountable for ethical use of the organization’s information and IT resources. Users will ensure actions do not compromise the company’s information security and comply with associated policies.

  • Users will use resources for company's business purposes only. Users will access only authorized resources.

  • Users will treat data as valuable assets and protect it. Users will comply with spot checks and audits.

  • Users are responsible for visitors, contractors, and clients they invite to company premises. Users encountering unauthorized individuals will challenge them or inform Incident Management Team & their immediate senior.

  • Users will not circulate inappropriate materials and will promptly remove such materials if received.

  • Users will not engage in activities thwarting access rights.

  • Users will comply with non-disclosure and confidentiality agreements.

  • Users will not access restricted areas without authorization and will use change control forms for requesting changes.

  • Non-adherence to the policy may result in disciplinary action.

Desktop Level

  • Users will not introduce harmful computer code.

  • Users will secure desktop data with passwords and comply with the Password Policy. Users will ensure antivirus updates are installed.

  • Users will check removable media for viruses.

  • Users will not leave confidential information unattended. Users will not use magnets near computer equipment.

  • Users will not keep liquids near computer equipment.

  • Users require written permission for removing or transporting computers. Users will not transport removable media between home and office.

Software License Guidelines

  • Users will ensure desktops have licensed software.

  • Users will not download unauthorized software.

  • Users will not use the company’s software for personal use.

  • Users will not install personal software on company computers.

  • Users will not propagate company's software outside the network.

Information Disclosure Guidelines

  • Users will not discuss or transfer company-related information without authorization.

  • Users encountering unsecured sensitive information will inform their superior.

  • Users will follow Data and Document Classification policy.

  • Users will not disclose company's data or documents outside the organization.

Definitions

  • tecciance: Company Legal Name

  • ISMS: Information Security Management System

  • CEO: Chief Executive Officer

  • Unacceptable Use: Activities deemed unacceptable under the Acceptable Use Policy or any other activity illegal under local, national, or international laws while using tecciance's resources.

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

Use of generative AI and coding assistants on organization or client information is permitted only on approved services, with a purpose, and within the user's classification entitlement.

Do not paste secrets, credentials, Restricted data, or unpublished client material into unapproved AI tools.

Output of AI tools is unverified until reviewed. Users remain accountable for what they commit, send, or publish.