A signed acceptable use policy must explain the cybersecurity rules personnel must follow while working, provide cybersecurity awareness when they join and throughout employment, and obtain documented acknowledgment that they understand and will comply. Under ECC – 2:2024 practice 1-9-4, employee acceptable use policy cybersecurity requirements are not satisfied by a signature alone: the business must maintain approved requirements, communicate them to employees and relevant external personnel, build them into HR processes, and keep evidence that awareness and acknowledgments occurred.
What does ECC – 2:2024 control 1-9-4 officially require?
The formal requirement for practice 1-9-4 states: “The personnel cybersecurity requirements during employment must include at least the following.”
For a small or medium-sized business, that sentence has three important parts:
- “Personnel” means more than permanent employees. Include temporary staff, contractors, consultants, interns, outsourced support teams, and other external parties who can access business systems, data, premises, or company-issued devices.
- “During employment” means requirements start before or at onboarding and continue while the person has access. A policy signed once and never mentioned again is unlikely to demonstrate ongoing compliance.
- “Must include at least the following” means the organization needs both awareness and enforceable compliance with its cybersecurity policies and procedures.
ECC divides this into two related objectives.
| ECC objective | Plain-English meaning | What you should be able to show |
|---|---|---|
| 1-9-4-1: Cybersecurity awareness during onboarding and employment | Teach personnel the security rules before they begin work and reinforce those rules regularly through approved channels. | An approved policy or procedure, onboarding content, awareness emails or workshop material, and an awareness plan or schedule. |
| 1-9-4-2: Implementation of and compliance with cybersecurity requirements | Tell personnel what policies apply to them, require them to follow those policies, and obtain documented acknowledgment. | An approved policy or procedure, HR process evidence, and signed or electronically accepted policy acknowledgments. |
The signed acceptable use policy is usually one part of this evidence set. It should not try to replace every security policy. Instead, it should clearly direct personnel to the policies that govern passwords, remote access, data handling, incident reporting, devices, email, collaboration tools, and disciplinary consequences.
What should employee acceptable use policy cybersecurity requirements cover?
Your acceptable use policy should use plain language and describe what people may do, must do, and must not do when using company systems or handling company information. For a remote or hybrid workforce, it should specifically cover the places where work now happens: home networks, personal devices, cloud applications, mobile phones, shared collaboration spaces, and public locations.
- Permitted business use: Define which devices, applications, accounts, networks, and data repositories personnel may use for work. State whether reasonable personal use is allowed and prohibit activity that is unlawful, abusive, or likely to harm the business.
- Account and password protection: Require unique accounts, prohibit password sharing, require multi-factor authentication where provided, and prohibit approval of unexpected MFA prompts.
- Remote and hybrid work: Require use of approved remote-access tools, screen locking, secure Wi-Fi, and reasonable protection from household members or visitors viewing confidential information. Explain whether public Wi-Fi is prohibited or must be used only with the company VPN.
- Approved software and cloud services: Prohibit installing unapproved software, browser extensions, AI tools, file-sharing services, or personal email forwarding for business information without authorization.
- Data handling: Explain how to classify, store, share, print, download, and dispose of sensitive information. Personnel should know that customer data, payroll records, financial information, and credentials must not be copied into personal storage or messaging applications.
- Email, messaging, and phishing: Require users to check unusual requests, report suspected phishing, and avoid opening suspicious attachments or links. Include a simple reporting route, such as the IT support address or designated security contact.
- Incident reporting: Require prompt reporting of lost devices, suspected account compromise, accidental data disclosure, malware alerts, and unauthorized access. Make clear that fast reporting is expected even when the person made a mistake.
- Monitoring and consequences: State that company systems may be monitored or logged as permitted by applicable law and that breaches may lead to access restriction, disciplinary action, contract action, or legal escalation.
Keep the policy readable. A six-page policy that employees can understand and acknowledge is more useful than a 30-page document that nobody reads. If separate policies exist, the acknowledgment should name them or link to their current approved versions so there is no ambiguity about what the person accepted.
Who does control 1-9-4 apply to, and when is it triggered?
Control 1-9-4 applies whenever a person receives or retains access to organizational information, systems, facilities, or technology resources. For an SMB owner, the practical rule is simple: if someone can log in, view data, handle a company device, access a shared drive, process customer information, or administer a business platform, they should be covered.
The requirement is triggered at several points in the personnel lifecycle:
- Before work begins: Include the acceptable use policy and basic security awareness in the onboarding workflow before granting access to email, cloud storage, finance systems, or customer platforms.
- When access changes: Reconfirm relevant requirements when someone moves into a role with greater access, such as an accounts clerk becoming a finance manager or an employee receiving administrator privileges.
- During employment or engagement: Provide recurring awareness messages, workshops, or short training. The frequency should reflect your risk, but annual training plus periodic phishing and remote-work reminders is a practical baseline.
- When policies materially change: Obtain a new acknowledgment when you introduce major changes, such as mandatory MFA, a new bring-your-own-device rule, or a prohibition on unapproved generative AI tools.
- For external personnel: Require contractors and managed service providers to acknowledge applicable security conditions before access is enabled, even if they are not processed through your normal employee HR workflow.
For example, CedarPay, a 75-person fintech company, hires remote customer-support agents who use Microsoft 365, Zendesk, Salesforce, and a browser-based payment operations portal. Its HR coordinator sends the acceptable use policy and a 20-minute security module through BambooHR before the manager requests accounts. The agent electronically acknowledges the policy, completes the module, and cannot receive the payment-portal role until the HR record shows both items as complete.
That workflow is stronger than emailing a PDF after the employee starts. It links the employee acceptable-use requirements to access provisioning and leaves evidence that can be reviewed later.
What does compliant practice look like to an assessor?
An assessor generally looks for a working process, not merely a policy template. The following are concrete examples that would usually demonstrate meaningful implementation of ECC practice 1-9-4 when supported by dated records.
- Approved policy with management ownership: The owner or delegated executive approves an “Acceptable Use and Personnel Cybersecurity Requirements Policy,” version 1.2, with an effective date, review date, and scope covering employees, contractors, and temporary workers. The document references the organization’s password, remote-work, incident-reporting, and data-classification procedures.
- Onboarding gate before system access: A new hire checklist in BambooHR or Microsoft Lists requires completion of security awareness and electronic policy acknowledgment before the IT administrator creates Microsoft 365, VPN, or accounting-system accounts. The checklist records the person’s name, completion date, policy version, and approver.
- Ongoing awareness evidence: Every quarter, the business sends a short awareness message from its approved company email account. Topics include phishing reporting, safe use of public Wi-Fi, MFA fatigue attacks, and protecting customer data during remote work. Retain the email, distribution list, and workshop slides or recording.
- Contractor acknowledgment tied to access: A managed IT provider supporting Microsoft Intune and firewall administration signs an external-party acknowledgment before receiving privileged accounts. The acknowledgment covers approved remote access, MFA, prohibition on shared administrator accounts, incident escalation, and data confidentiality.
- Annual re-acknowledgment with follow-up: Harbor Bank, a 140-person regional bank using Microsoft 365, Temenos core banking, and Citrix remote access, distributes the updated policy through KnowBe4 each January. The HR manager receives a completion report, follows up with non-completers, and temporarily disables non-essential remote access for personnel who remain overdue after the stated deadline.
Notice that each example produces evidence: an approved document, a signed acknowledgment, training material, a completion report, or a system workflow record. Those records are what turn employee acceptable use policy cybersecurity requirements from a statement of intent into a defensible compliance practice.
FAQ
Does an acceptable use policy need to be signed by every employee?
Yes, where ECC 1-9-4 applies, obtain documented acknowledgment from employees and other relevant personnel who must follow the policy. An electronic acknowledgment is generally acceptable if it identifies the individual, date, and policy version and can be retained for review.
Is cybersecurity awareness training required only when an employee starts?
No. ECC 1-9-4-1 requires awareness during onboarding and during employment. Use onboarding training plus recurring communications, workshops, short modules, or targeted reminders to show ongoing awareness.
Do contractors need to sign the acceptable use policy?
Contractors need to acknowledge applicable cybersecurity requirements when they access your systems, data, or facilities. You may use a contractor-specific acknowledgment rather than the employee form, but it should cover the same relevant rules and be retained with the contract or access records.
What evidence should we keep for a signed acceptable use policy?
Keep the approved policy version, approval record, signed or electronic acknowledgments, onboarding checklist records, awareness emails or training content, attendance or completion reports, and evidence of follow-up for overdue acknowledgments.
Start by adding a clear security acknowledgment and a short onboarding awareness module to your remote-work hiring process, then keep the resulting records in one place your business can easily review.