Forgotten password?

End user cyber security policy (premium)

This cyber security policy is designed to regulate the use of company IT systems by employees and/or contractors.

This policy is intended for organisations that have a complex system user environment. It may be adapted to create a restrictive policy or a permissive policy, or one which mixes and matches restrictive and permissive provisions.

To increase the chances of the policy being read, understood and followed, it is relatively short, focusing upon the key issues. These key issues include the formulation of passwords, the circumvention of security software, keeping software up to date, reporting security breaches, use of personal devices for work purposes, use of work devices for personal purposes, portable storage media and public Wi-Fi networks.

In addition, the policy includes sections covering the training of personnel and the monitoring of IT systems.

This policy was created and is maintained by Emma Osborn of OCSRC ( in collaboration with Docular.

Ask about this document

End user cyber security policy (premium) contents

  1. Introduction: employee and contractor contribution to security; concerns of company; the need for employees/contractors to be vigilant; providing information on how to keep
    the company
    secure; implementation of the policy; contact for queries ; the policy is part of the contract.
  2. Cyber security requirements: rules about passwords; circumventing security measures; antivirus requirements; reporting of security breaches; no accessing work systems with personal devices; provisions for accessing
    systems using own devices; taking IT equipment off company premises; exchanging data; no use of
    equipment outside network; no personal use of
    equipment; use of
    devices for personal reasons; use of public cloud services; removing data from
    premises; installing software onto
    computer or phone; administrator accounts; accessing inappropriate content; use
     VPN away from office; use
    VPN with public Wi-Fi; use of equipment in public Wi-Fi networks; use of removable storage.
  3. Training: cyber security training for employees handling personal data; cyber security awareness training for personnel; random testing of employee cyber security awareness.
  4. Monitoring: monitoring of IT systems; personal data logged by the system; keeping of system logs.
  5. Handling mistakes: handling mistakes in a timely manner; solving the problem; when to report a mistake; details of the mistake to give the security team; mistakes on own device while connected to company's systems; failing to report system misuse.
  6. Consequences of system misuse: actions considered to be misuse of IT systems; consequences of IT system misuse.
  7. Declaration: required permissions; signature; signature line: first.
End user cyber security policy (premium) document editor previewEnd user cyber security policy (premium) document editor preview
This is a shortened preview of the editor interface; once you create your instance you'll be able to edit the full document in our online editor.
End user cyber security policy (premium) document previewEnd user cyber security policy (premium) document preview
This is a shortened preview of the DOCX output; once you create your instance you'll be able to download the full document in PDF, HTML, RTF and/or DOCX (Microsoft Word) format.