An acceptable use policy governing how staff and contractors use the organisation's systems, devices and data: permitted and prohibited use, BYOD, monitoring notice and enforcement. Supports ISO 27001 acceptable-use control and SOC 2 access expectations.