Acceptable Use Policy for Information, Information Assets, and Information Processing Facilities
Acceptable Use Policy for Information, Information Assets, and Information Processing Facilities
Simplebooklet Marketing Inc. | Approved December 1, 2024
1. Purpose
This policy defines the acceptable use of information, information assets, and information processing facilities to protect the confidentiality, integrity, and availability of Simplebooklet Marketing Inc.'s resources. It ensures that employees and contractors use these resources responsibly and in compliance with organizational and legal requirements.
2. Scope
This policy applies to all employees, contractors, and third-party users who access or use Simplebooklet Marketing Inc.'s information, information assets, and information processing facilities. These include but are not limited to:
- Computers, servers, and networks
- Software applications and databases
- Mobile devices and storage media
- Emails, messaging platforms, and internet resources
3. Policy Statement
3.1 General Use
- Information assets must be used solely for authorized business purposes.
- Users must adhere to all relevant laws, regulations, and company policies when accessing or using these resources.
- Personal use of company resources should be minimal and not interfere with business operations.
3.2 Security Requirements
- Users must protect their login credentials and must not share them with others.
- Devices used to access company resources must have up-to-date security software, including antivirus and firewalls.
- Information classified as confidential or sensitive must be encrypted during transmission and storage.
3.3 Prohibited Activities
Users must not:
- Access, modify, or disclose information without proper authorization.
- Install unauthorized software or connect unauthorized devices to company networks.
- Use information assets to engage in illegal activities, harassment, or other inappropriate behavior.
- Intentionally introduce malware, viruses, or other harmful programs into company systems.
3.4 Internet and Email Usage
- Internet access must be used for business-related activities.
- Users must not visit websites containing illegal, offensive, or inappropriate content.
- Emails should not be used to transmit confidential information without encryption.
3.5 Mobile and Remote Access
- Remote access to company resources must be authorized and occur through secure channels (e.g., VPN).
- Mobile devices must be password-protected and configured to comply with company security standards.
- Lost or stolen devices must be reported immediately to the IT department.
4. Responsibilities
4.1 Employees and Contractors
- Adhere to this policy and report any violations or security incidents.
- Maintain the confidentiality of company information.
4.2 IT Department
- Monitor compliance with this policy.
- Provide training and support on acceptable use practices.
- Investigate and address reported violations.
4.3 Managers
- Ensure team members understand and follow this policy.
- Report policy violations to the appropriate departments.
5. Violations and Consequences
Violations of this policy may result in disciplinary actions, including but not limited to:
- Revocation of access rights
- Termination of employment or contract
- Legal action in cases of unlawful activities
6. Monitoring and Review
- The IT department will monitor system usage to ensure compliance.
- This policy will be reviewed annually or when significant changes occur in technology or legal requirements.
7. Acknowledgment
All users must acknowledge and agree to this policy in writing or through an electronic acknowledgment system.
Approved by: Ken Kwasnicki
Date: December 1, 2024
Updated on: 08/09/2026
Thank you!
