A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?
The Acceptable Use Policy (AUP) defines how employees may use company assets, including computers and networks. It sets expectations for behavior and consequences for violations. In this scenario, the AUP is the document that outlines these rules, making it the correct choice.
Why this answer
The Acceptable Use Policy (AUP) is designed to outline the rules and guidelines for using company assets. It typically covers what is allowed and prohibited, and the consequences of violations. This aligns with the scenario's requirement to define acceptable use of computers, networks, and data.
Exam trap
The trap here is confusing the AUP with other policies like the NDA, which also govern behavior but focus on confidentiality rather than asset use.