CompTIA Security+ (SY0-701)Security Program Management and OversightEasy

An organization publishes a document that all employees must sign before receiving network access. The document defines permitted and prohibited uses of company systems, including personal use of email and prohibitions on installing unauthorized software. Which document is this?

  1. AMemorandum of understanding
  2. BAcceptable use policy
  3. CService level agreement
  4. DBusiness impact analysis
Show answer & explanation

Correct answer: B. Acceptable use policy

An acceptable use policy (AUP) defines the rules employees must follow when using company systems and network resources, including permitted and prohibited activities. It is typically signed as a condition of receiving access.

Why the other options are wrong

  • A. An MOU documents mutual intent between two organizations, not internal employee rules.
  • C. An SLA defines performance expectations between a provider and customer, not employee conduct.
  • D. A BIA identifies critical business processes and recovery priorities, not usage rules.

Acceptable Use Policy (AUP)

A policy that defines permitted and prohibited uses of an organization's IT systems and resources by employees or users.

  • Typically signed as a condition of network access
  • Covers personal use, prohibited software, and data handling
  • Violation can result in disciplinary action or termination

Memory trick: AUP = 'Allowed Uses, Please' — the rulebook for using company gear.

More Security Program Management and Oversight questions