Free policy template ISO 27001

Acceptable Use Policy

The rules for how staff use company devices, accounts, and data, the policy every employee actually signs.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Acceptable Use & Workstation Security

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy sets out how people are expected to use {{COMPANY_LEGAL_NAME}}'s systems responsibly and how endpoints must be configured to keep company data safe.

2. Scope

This policy applies to everyone who uses company systems and to every device that connects to company networks or handles company data.

3. Policy statements

3.1 Acceptable use

Company assets are provided for authorized business purposes. Limited personal use is fine as long as it creates no risk. Illegal, harassing, or copyright-infringing activity is never permitted.

3.2 Workstation configuration and updates

Endpoints must run full-disk encryption, a host firewall, and automatic operating-system patching. Screens lock automatically after ten minutes of inactivity and require a password or PIN to resume.

3.3 Email and messaging

Company data must not be forwarded to personal email accounts. Business conversations belong in approved, sanctioned messaging tools.

3.4 Removable media and printing

Sensitive documents are collected from printers immediately and shredded once no longer needed. Company data on removable media must be encrypted and securely destroyed when finished.

3.5 Personal devices and local storage

Personal devices used for work (BYOD) must meet endpoint requirements (PIN, encryption, and patching) and be registered with IT. Company data is stored only in approved, encrypted containers or applications, never loose on a personal device.

3.6 Compliance measurement

A quarterly workstation review confirms encryption, auto-lock settings, and patch status across the fleet.

3.7 Continual improvement

Rules are refreshed as new collaboration tools are adopted and as endpoint threats evolve.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and its procedures
Managers Enforce the policy within their teams
All personnel Comply; report issues promptly

5. Compliance and exceptions

Breaches lead to access suspension until remediation, with severe cases escalated to HR. A temporary deviation (for example, lab or test work) requires documented approval, a time limit, and, where relevant, compensating controls. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates