Acceptable Use Policy
Purpose
Section titled “Purpose”This policy defines the rules for acceptable use of Cadence OneFive’s information assets, systems, and resources. It aims to protect the organization and its personnel from security risks arising from inappropriate use while supporting a productive, collaborative remote work environment.
This policy applies to all Cadence OneFive personnel, including employees, contractors, and temporary staff. It covers all information assets, systems, networks, communication platforms, and data owned or managed by the organization, regardless of how or where they are accessed.
Policy Statement
Section titled “Policy Statement”Cadence OneFive provides information systems and resources to support its mission. All personnel are expected to use these resources responsibly, professionally, and in accordance with this policy and applicable laws.
General Use
Section titled “General Use”- Organization systems and resources are provided primarily for business purposes and must be used in a professional manner.
- Personnel must not use organization resources for illegal activity, personal financial gain, or any purpose that could harm the organization’s reputation or operations.
- Personnel are responsible for the security of their accounts and must not share credentials or allow unauthorized individuals to access organization systems.
- Personnel must comply with all applicable laws, regulations, and contractual obligations when using organization resources.
System and Network Use
Section titled “System and Network Use”- Personnel must not attempt to gain unauthorized access to any system, network, or data beyond their authorized access level.
- Personnel must not circumvent, disable, or interfere with security controls, including firewalls, antivirus software, access controls, or monitoring tools.
- Personnel must not install unapproved software on organization-managed systems. Software requests should be submitted to the IT Team for review.
- Personnel must not use organization systems to probe, scan, or test the security of external networks or systems without explicit authorization.
Communication Systems
Section titled “Communication Systems”- Organization communication platforms (email, Discord, and other collaboration tools) must be used professionally and respectfully.
- Personnel must not use communication systems to transmit harassing, discriminatory, threatening, or otherwise inappropriate content.
- Personnel should be mindful that communications on organization platforms may be subject to monitoring and retention in accordance with legal and policy requirements.
Data Handling
Section titled “Data Handling”- All organization data must be handled in accordance with the Data Classification Policy and the Data Security Policy.
- Personnel must not share, transfer, or disclose organization data to unauthorized parties, whether internal or external.
- Organization data must only be stored on approved systems and services. Personnel must not store company data on personal cloud storage, unapproved SaaS tools, or removable media without authorization.
- When data is no longer needed, it must be disposed of in accordance with the Data Disposal Policy.
Internet and Cloud Services
Section titled “Internet and Cloud Services”- Personnel must not intentionally access malicious, illegal, or inappropriate websites using organization systems or while connected to organization networks.
- Only organization-approved SaaS tools and cloud services may be used to process or store company data. Personnel should consult the vendor census before adopting new tools.
- Personnel must not upload organization data to unauthorized external services, including AI tools, file-sharing platforms, or social media, without approval.
Personal Use
Section titled “Personal Use”- Limited personal use of organization systems is permitted provided it does not interfere with work responsibilities, consume excessive resources, or violate any provision of this policy.
- Personal use must not involve illegal activity, offensive content, or any activity that could expose the organization to security risks or reputational harm.
- The organization assumes no responsibility for personal data stored on organization systems.
Monitoring
Section titled “Monitoring”- Cadence OneFive reserves the right to monitor, log, and audit all use of organization systems and resources for security, compliance, and operational purposes.
- Monitoring activities are conducted in accordance with applicable laws and the organization’s commitment to transparency and respect for personnel.
Enforcement
Section titled “Enforcement”- Violations of this policy may result in disciplinary action, up to and including termination of employment or contract, as determined through the organization’s established processes.
- Suspected violations should be reported to the IT Team or Head of Platform.
Related
Section titled “Related”Policy Review
Section titled “Policy Review”This policy will be reviewed annually by the IT Team in collaboration with relevant stakeholders, and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
