An acceptable use policy (AUP; also sometimes acceptable usage policy) is a set of rules applied by network and website owners which restrict the ways in which the network or site may be used. AUP documents are written for corporations, businesses, universities, schools, and website owners often to reduce the potential for legal action that may be taken by a user, and often with little prospect of enforcement.
Acceptable use policies are also integral to the framework of information security policies; it is often common practice to ask new members of an organization to sign an AUP before they are given access to its information systems. For this reason, an AUP must be concise and clear, while at the same time covering the most important points about what users are, and are not, allowed to do with the IT systems of an organization. It should refer users to the more comprehensive security policy where relevant. It should also, and very notably, define what sanctions will be applied if a user breaks the AUP. Compliance with this policy should, as usual, be measured by regular audits.
In some cases, AUP documents are named Internet and E-mail policy, Internet AUP, or Network AUP and also Acceptable IT Use Policy These documents, even though named differently, largely provide policy statements as to what behaviour is acceptable from users of the local network/Internet connected via the local network.
The most important part of an AUP document is the code of conduct governing the behaviour of a user whilst connected to the network/Internet. The code of conduct may include some description of what may be called netiquette which includes such items of conduct as using appropriate/polite language while online, avoiding illegal activities, ensuring that activities the user may embark on should not disturb or disrupt any other user on the system, and caution not to reveal personal information that could be the cause of identity theft.
Most AUP statements outline consequences of violating the policy. Such violations are met with consequences depending on the relationship of the user with the organization. Common actions that schools and universities take is to withdraw the service to the violator and sometimes if the activities are illegal the organization may involve appropriate authorities, such as the local police. Employers will at times withdraw the service from employees, although a more common action is to terminate employment when violations may be hurting the employer in some way, or may compromise security. Earthlink, an American Internet service provider has a very clear policy relating to violations of its policy. The company identifies six levels of response to violations:
Central to most AUP documents is the section detailing unacceptable uses of the network, as displayed in the University of Chicago AUP Unacceptable behaviours may include creation and transmission of offensive, obscene, or indecent document or images, creation and transmission of material which is designed to cause annoyance, inconvenience or anxiety, creation of defamatory material, creation and transmission that infringes copyright of another person, transmission of unsolicited commercial or advertising material and deliberate unauthorised access to other services accessible using the connection to the network/Internet. Then there is the type of activity that uses the network to waste time, as indicated in SurfControl's advice on writing AUPs, of technical staff to troubleshoot a problem for which the user is the cause, corrupting or destroying other user's data, violating the privacy of others online, using the network in such a way that it denies the service to others, continuing to use software or other system for which the user has already been warned about using, and any other misuse of the network such as introduction of viruses.
Disclaimers are often added in order to absolve an organisation from responsibility under specific circumstances. For example, in the case of Anglia Ruskin University a disclaimer is added absolving the University for errors or omissions or for any consequences arising from the use of information contained on the University website. While disclaimers may be added to any AUP, disclaimers are most often found on AUP documents relating to the use of a website while those offering a service fail to add such clauses. PsychologyUK, a magazine forum site, includes the type of disclaimer that can be used in an AUP for a website or online service of some type.
Particularly when an AUP is written for a college or school setting, AUPs remind students (or when in the case of a company, employees) that connection to the Internet, or use of a website, is a privilege, as demonstrated in the Loughborough University's Janet Service AUP and not a right. Through emphasising this "privilege" aspect, Northern Illinois University then make the connection that any abuse of that privilege can result in legal action from the University.
In a handbook for writing AUP documents, the Virginia Department of Education indicate that there are three other areas needing to be addressed in an AUP:
Through a cursory reading of AUP statements found by a Google Search the variation of AUP documents including each of these items is highly variable. However, those statements in a school or university setting are more likely to include a statement to address at least the "personal safety" issue.
6.1 If any provision of this AUP or part thereof shall be void for whatever reason, the offending words shall be deemed deleted and the remaining provisions shall continue in full force and effect.
6.2 The Company reserves the right to add, delete or modify any provision of this Policy at any time without notice, effective upon posting of the modified Policy at http://www.taglab.com/contact/acceptableusepolicy.html
6.3 This Policy shall be governed by the laws of England and the parties submit to the exclusive jurisdiction of the Courts of England and Wales.
And of course with the ever widening of the number of jurisdictions covered by the Internet, the AUP document needs to indicate the jurisdiction , meaning the laws that are applicable and govern the use of an AUP. Even if a company is only located in one jurisdiction and the AUP applies to only its employees naming the jurisdiction saves difficulties of interpretation should legal action be required to enforce its statements.