
Acceptable Use Policy: A Guide for Australian Business
An acceptable use policy sets out what staff may and may not do with your business technology: devices, email, internet access, accounts and data. For an Australian employer it needs to cover permitted use, prohibited use, personal use, monitoring, bring-your-own-device, data handling and what happens when someone breaches it. The part most policies get wrong is monitoring, because a policy that does not clearly tell staff they are monitored is difficult to rely on later.
An acceptable use policy is also the document most often downloaded, signed once and never looked at again. Below is what it should contain, what makes it enforceable in an Australian workplace, and the clauses worth leaving out.
What is an acceptable use policy?
An acceptable use policy, often shortened to AUP, is a short document that defines the boundaries of acceptable behaviour when using an organisation’s information technology. It covers company devices, networks, email, cloud accounts, internet access and the data those systems hold, and it applies to employees, contractors and anyone else you give access to.
It is a behavioural control rather than a technical one, which is what makes it unusual in a security programme. Most controls work whether or not anyone understands them. An acceptable use policy only works if people have read it, understood it and believe it will be applied, which is why distribution and acknowledgement matter as much as the drafting.
Its job is narrower than people assume. An acceptable use policy is not a security strategy, an incident response plan or a privacy policy. It is the document that tells a person what they personally may do, so that you can reasonably expect them to follow it and reasonably act when they do not. Everything else belongs in other documents.
It is also the policy most compliance frameworks expect to see first. If you are working toward Essential Eight maturity or a certification, an acceptable use policy is usually among the earliest documents an assessor asks for, alongside your wider information security policy set.
What should an acceptable use policy cover?
A workable acceptable use policy for an Australian business covers eight areas. Anything beyond these tends to repeat content that belongs in another policy.

Personal use is the section worth thinking hardest about. A blanket ban on personal use is unenforceable in practice, because people check a bank balance at lunch and everybody knows it. A policy that permits reasonable personal use, defines what unreasonable looks like, and makes clear that personal use carries no expectation of privacy on company systems, is far more defensible than one everybody quietly ignores.
How do you make an acceptable use policy enforceable in Australia?
A policy you cannot rely on is decoration. Four things separate an acceptable use policy that supports a disciplinary process from one that collapses under scrutiny.
- Evidence that the person received it. A signed acknowledgement, or a verifiable training record showing acceptance with a date. Verbal briefings and shared drive uploads are not evidence anyone read anything.
- Clear notice of monitoring. If you monitor email, internet use, devices or systems, say so explicitly, say what is monitored, and say why. Monitoring laws differ by state and territory, so check your obligations in the jurisdictions where your staff actually work.
- Consequences stated plainly. The policy should say that breaches may lead to disciplinary action up to and including termination, and connect to your existing disciplinary process rather than inventing a parallel one.
- Consistent application. The most common reason an acceptable use policy fails is not its wording. It is that the business enforced it against one person and not another for the same conduct.
Monitoring deserves particular care because it interacts with privacy obligations. Where your systems handle personal information, your handling of it sits under the Privacy Act and the Australian Privacy Principles, and staff monitoring data collected through your systems is not exempt from thinking. Say what you collect, keep it proportionate to a genuine business purpose, and do not collect more because the tooling makes it easy. Australian Privacy Principles compliance covers the wider obligations.
What should you leave out of an acceptable use policy?
Most acceptable use policies are too long, and the length comes from material that belongs elsewhere or that the business cannot actually enforce.

The technical standards point is the one that causes the most trouble over time. A policy that specifies a sixteen-character password or names a particular antivirus product is out of date the moment you change either, and every stale clause is something an auditor or an opposing lawyer can hold up. Put the principle in the acceptable use policy and the specifics in a standard you can revise without reissuing a document everyone has signed.
Length is not a measure of quality here. A three-page acceptable use policy that staff have read beats a twenty-page one filed unopened, and the longer document carries more clauses you have committed to and may not be meeting. If a section exists because a template included it rather than because your business needed a position on it, remove it.
How does an acceptable use policy handle personal devices?
If staff use their own phones or laptops for work, your acceptable use policy needs to say so and set conditions, or you need a separate bring-your-own-device policy that it references. The awkward part is that you are asking for a degree of control over property you do not own.
| Decision | What to state in the policy | Why it matters |
|---|---|---|
| Is personal device use permitted at all | Yes, no, or only for specific services such as email | An unstated position defaults to whatever staff assume |
| Minimum security conditions | Screen lock, current operating system, device encryption, no shared family accounts | These are the conditions that make the arrangement acceptable |
| Management software | Whether you require a management profile, and what it can and cannot see | Staff reasonably want to know what their employer can view |
| Remote wipe | Whether you can wipe company data, and whether that could affect personal data | This is the clause most likely to cause a dispute later |
| What happens at offboarding | What is removed, by whom, and when | Company data on a former employee’s phone is a live exposure |
Be straight with staff about remote wipe in particular. A policy that quietly reserves a right to erase a personal phone, discovered at the moment it is exercised, creates a problem that no amount of correct drafting fixes afterwards.
Common questions about acceptable use policies
What should an acceptable use policy contain?
Scope and who it applies to, permitted use of company systems, prohibited use, the position on personal use, a clear monitoring statement, password and account rules at the principle level, data handling and classification basics, bring-your-own-device conditions, reporting obligations for suspected incidents, and the consequences of a breach. For most Australian SMBs that fits comfortably in three to five pages.
Why is an acceptable use policy important?
It does three jobs. It tells staff where the line is, which prevents a meaningful share of incidents caused by people who simply did not know. It gives the business a defensible basis for acting when someone crosses that line. And it is a control that compliance frameworks, insurers and enterprise customers expect to see, so its absence shows up in questionnaires and assessments.
How often should an acceptable use policy be reviewed?
Annually, plus whenever something changes that the policy describes. New collaboration tools, a shift to hybrid work, adopting generative AI tools or a change in monitoring all warrant an out-of-cycle review. Record the review date on the document. An acceptable use policy that still prohibits personal cloud storage while the business runs on a cloud platform is actively unhelpful.
Should an acceptable use policy cover AI tools?
Yes, and this is the most common gap in Australian acceptable use policies right now. State which AI tools are approved, what categories of information must never be pasted into them such as customer data, personal information, credentials or unreleased material, and who to ask before adopting a new tool. A short, clear position beats both silence and a blanket ban nobody observes.
Is an acceptable use policy a legal requirement in Australia?
No Australian law requires an acceptable use policy by name. It becomes effectively necessary through other routes: security frameworks and certifications expect one, cyber insurers ask about staff policies, enterprise customers request it during supplier reviews, and employment matters go considerably better for an employer who can show that the expectation was documented and acknowledged. Cyber insurance requirements in Australia covers what insurers tend to ask.
Writing one that people actually follow
Write it for the person who has to follow it, not for an auditor. Plain sentences, no defined-term glossary, and examples where a rule could be read two ways. If a new starter cannot read it in ten minutes and come away knowing what they may and may not do, it will not change anyone’s behaviour however complete it is.
Then pair it with the only two things that make any policy work: acknowledgement you can evidence, and a short refresher each year. Security training for employees is where the policy stops being a file and starts being something people have actually read.
Siege Cyber helps Australian businesses write policy sets that match how they really operate and stand up in an assessment. If you want a second set of eyes on yours, see our cyber security advisory services or get in touch.