Internet & Email Acceptable Use
Stay within corporate internet and email policies.
What Is Internet & Email Acceptable Use?
An Acceptable Use Policy defines what you can do with corporate email, internet access and company devices, and it only becomes real when you have to apply it. You will make a series of judgement calls: forwarding a work document to personal email, visiting a particular site on the corporate network, a colleague asking you to send sensitive data through an unapproved app, and a suspicious link inside a plausible business email. Each decision maps back to a specific provision, so you learn the rule and the reason together.
What You'll Learn in Internet & Email Acceptable Use
- Apply your organization's Acceptable Use Policy to common email scenarios including forwarding, personal use, and handling attachments from unknown senders
- Evaluate whether specific internet activities on the corporate network comply with AUP restrictions on personal browsing, streaming, and cloud storage
- Refuse requests to transmit sensitive data through unapproved communication channels like personal email, consumer messaging apps, or unvetted file-sharing services
- Recognize the escalating consequences of AUP violations, from informal warnings through formal disciplinary action and potential termination
- Distinguish between acceptable and prohibited use of corporate devices for personal activities based on your specific AUP provisions
Internet & Email Acceptable Use — Training Steps
-
Late Night at Northgate Financial
It's 7 PM on a Wednesday — you're working late to finish the Q3 Client Portfolio Analysis, due first thing tomorrow morning. The office is mostly empty.
-
A Helpful Tip
Alice's phone buzzes. It's a message from Jake Torres — a friend and former colleague who now works at a hedge fund.
-
Visiting CryptoPulse
Alice opens CryptoPulse in her work browser. The site looks professional — market charts, analysis tools, portfolio tracking. It doesn't look like a shady crypto site at all. But Northgate's acceptable use policy explicitly prohibits cryptocurrency platforms on company networks, regardless of how professional they appear.
-
The Free Toolkit
A banner on the site offers a 'Free Market Insight Toolkit.' Alice thinks it could help with her analysis. She clicks download without thinking twice.
-
The Download Warning
The company's endpoint protection flags the download. A warning pops up — but Alice is in a rush and dismisses it. 'It's just a false positive,' she thinks. 'Jake uses this tool every day.'
-
The Shortcut Home
It's getting late. Alice decides to email the Q3 report draft to her personal email to finish at home. She sends the confidential Q3_Client_Portfolio_Analysis.xlsx to alice.morgan.personal@gmail.com. 'It's faster than the secure file transfer,' she tells herself. The report contains confidential client portfolio values, investment strategies, and personal financial details.
-
A Productive Evening
Alice finishes the report at home and comes in the next morning feeling accomplished. The Q3 analysis is done, the deadline is met. Everything seems fine.
-
IT Security at Your Desk
Alice arrives at work to find an email from IT Security already waiting. Her stomach drops.
-
The DLP Dashboard
Alice clicks the link in the email and logs in to the Compliance Portal to review the DLP alerts.
-
What the System Caught
The DLP Alert Dashboard reveals three separate violations from last night. Every shortcut Alice took was logged and flagged.
Security Framework Coverage
CIS Controls
- CIS 14.1 Establish and Maintain a Security Awareness Program
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind