All posts

Acceptable use policy for company devices: template and examples

· 7 min read

Quick answer

An acceptable use policy (AUP) sets the rules for using company technology: permitted and prohibited use, security duties, personal use, monitoring, reporting loss or theft, and returning devices. It works best when each employee acknowledges it at the moment a device is issued.

An acceptable use policy (AUP) is the set of rules employees agree to when they use company technology. It explains what is allowed, what is prohibited, what the employee must do to keep devices and data secure, and what happens when the rules are broken.

Many AUPs focus on networks, email, and internet use. This guide focuses on the part that is easiest to neglect: the physical devices a company issues, such as laptops, phones, tablets, and accessories. Those are the items that go missing, get lent to family members, or never come back when someone leaves.

This is a practical starting point, not legal advice. Employment, privacy, and monitoring rules vary by country and state, so have HR and legal counsel review the policy before you adopt it.

What an acceptable use policy should cover

A device-focused AUP usually includes:

  • Scope. Which devices, systems, and people the policy applies to, including contractors.
  • Ownership. Company devices and the data on them belong to the company.
  • Acceptable use. Business use, and the limits of reasonable personal use.
  • Prohibited use. Illegal activity, installing unapproved software, disabling security controls, or letting others use the device.
  • Security duties. Screen locks, updates, encryption, and approved networks.
  • Remote and personal devices. Rules for working away from the office and for any personally owned devices used for work.
  • Monitoring. What the company may monitor, stated clearly.
  • Loss, theft, and damage. How quickly to report, and to whom.
  • Return of equipment. When and how devices must be returned.
  • Consequences. What happens when the policy is broken.
  • Acknowledgment. A signature or recorded acceptance.

For remote work and personally owned devices, NIST's SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and BYOD Security covers securing both organization-issued and personal client devices and gives advice on creating related security policies. For a broader IT acceptable use policy that covers email, internet, and system use in depth, the SANS Institute publishes a free acceptable use standard template in PDF and Word formats.

Acceptable use policy template for company devices

Copy the template below and replace the bracketed text. Remove any clause that does not match how your organization actually works; a policy nobody follows is worse than a short one people do.

[COMPANY NAME] COMPANY DEVICE ACCEPTABLE USE POLICY

1. Purpose and scope
This policy applies to all laptops, desktops, phones, tablets, and accessories
issued by [Company Name] ("company devices"), and to everyone who receives one,
including employees and contractors.

2. Ownership
Company devices and all data stored on them remain the property of
[Company Name]. Devices are issued for business use and may be reassigned
or recalled at any time.

3. Acceptable use
Company devices are provided for [Company Name] business. Limited personal use
is permitted if it does not interfere with work, break the law, or breach
this policy.

4. Prohibited use
You must not:
- use a company device for illegal activity or to harass others;
- install software that has not been approved by [IT contact];
- disable, bypass, or remove security software, encryption, or device management;
- allow family members or other people to use the device;
- store company data on personal devices or accounts unless approved.

5. Security
You must keep the device locked when unattended, install updates when
prompted, use only approved networks or the company VPN, and keep the device
physically secure, including in vehicles and when traveling.

6. Monitoring
[Company Name] may monitor company devices and accounts for security,
compliance, and support purposes, as permitted by law. [Describe what is
monitored.]

7. Loss, theft, and damage
Report a lost, stolen, or damaged device to [IT contact] within [24 hours].
Report theft to the police where appropriate and provide the report number.

8. Return of equipment
Return all company devices and accessories [on your last day / within X days
of a request]. Devices must be returned with passwords removed and in the
condition issued, allowing for normal wear.

9. Consequences
Breaking this policy may lead to loss of access, disciplinary action, or
recovery of costs where permitted by law.

10. Acknowledgment
I have read and agree to this policy.

Name: ____________________  Signature: ____________________  Date: ________
Devices issued (asset tag / serial): _____________________________________

Example clauses for common situations

Personal use. "Occasional personal use, such as checking personal email during a break, is acceptable. Streaming, gaming, and personal business activity are not."

Travel. "Do not leave company devices unattended in vehicles, checked luggage, or public places. Carry them as hand luggage when flying."

Remote work. "When working outside the office, connect through [the company VPN] and do not use public computers to access company systems."

Departing employees. "Before your last day, return every company device listed on your acknowledgment, together with chargers and accessories. Unreturned equipment will be handled under [the return procedure]."

Make the policy part of device handoffs

A policy signed once during onboarding and then filed away rarely changes behavior. The most reliable moment to collect an acknowledgment is when a device physically changes hands:

  1. At issue. Record which devices the person received, by asset tag or serial number, and collect the acknowledgment at the same time.
  2. At replacement or upgrade. Record the returned device and the new one, so the list of what the person holds stays accurate.
  3. At departure. Use the recorded list to recover every device. The employee offboarding equipment checklist sets out the return steps, and automating the equipment side of offboarding explains why an accurate people list comes first.
  4. At review. Revisit the policy at least annually and after any significant loss or security incident.

The acknowledgment is only useful if you can match it to specific devices. "Received a laptop" is weak evidence; "received laptop tag AC-000184, serial 9K2X71F, on March 3" is strong.

How AssetCenter fits

AssetCenter records which person holds each device, keeps every earlier assignment in the device's history, and lets you attach files such as a signed acknowledgment to the record. When someone leaves, their person record lists everything currently assigned to them, which turns the return clause into a checklist rather than an investigation.

The AssetCenter IT inventory page covers the wider device record. AssetCenter does not enforce the policy on the device itself; security controls, encryption, and device management stay with your MDM and security tools. For how those systems relate, see what IT asset management covers.

Frequently asked questions

What is the purpose of an acceptable use policy?

To set clear rules for using company technology, protect company data and devices, and give the organization a documented basis for enforcing those rules.

Is an acceptable use policy legally required?

Not generally, although some regulations and contracts expect documented security policies. Monitoring and disciplinary clauses must follow local employment and privacy law, which is why legal review matters.

Should the AUP cover personal devices?

If employees use personal phones or computers for work, yes, either in the AUP or in a separate BYOD policy. NIST SP 800-46 covers the security considerations for personally owned devices used for remote access.

How often should an acceptable use policy be updated?

At least once a year, and whenever devices, systems, or working patterns change, such as a move to remote work.

Next step: collect acknowledgments at the next handoff

Adapt the template with HR and legal review, then start collecting acknowledgments whenever a device is issued or replaced, recording the asset tag or serial number on each one. Within a single refresh cycle, every employee's acknowledgment will match the devices they actually hold.

Jeremy Francis, Founder & CEO, AssetCenter

By Jeremy Francis

Founder & CEO, AssetCenter

Keep reading