Free Acceptable Use Policy (AUP) Template
Free editable Word template to support SACS-210 TPC1.2 for Saudi suppliers and small organizations preparing for the General Requirements.
Template Overview
This free Acceptable Use Policy template is a practical sample from the SACS-210 Compliance Kit. It helps small Saudi organizations define clear user rules for secure and responsible use of IT resources while supporting implementation of TPC1.2.
- IT Resource Usage Guidelines: Clear rules for company devices, email, internet use, personal or unauthorized devices, data, and cloud services.
- User Security Responsibilities: Password and MFA responsibilities, data handling, removable media, security controls, and incident reporting.
- SACS-210 Alignment: Built around TPC1.2 and includes user-facing rules that support related General Requirements without replacing technical or operational controls.
- Practical Implementation: Customize, approve, communicate, train personnel, and operate the policy in your actual environment.
Editable AUP Policy Template
An unlocked Word policy with guidance, approval and version-control fields, ready to customize to your actual environment.
Implementation Guide
Phase 1: Customize Template
Replace the placeholders and adapt the policy to your organization's actual environment, including contacts, approved technologies, BYOD, remote work, and internal rules.
Phase 2: Management Approval
Have senior management review, approve, date, and formally endorse the customized policy before it is issued to personnel.
Phase 3: Communicate, Train & Acknowledge
Communicate the approved policy to in-scope personnel, conduct appropriate cybersecurity awareness or training, and use the organization's approved acknowledgment process.
Frequently Asked Questions
Does this template guarantee SACS-210 or legal compliance?
No. This is a customizable policy template designed to support SACS-210 TPC1.2. Your organization must adapt it to its actual environment and applicable legal, regulatory and contractual obligations, implement relevant technical and operational controls, train personnel, maintain evidence, and complete any required authorized assessment.
Can we edit the document, or is it locked?
The download is a fully editable Microsoft Word (.docx) file. Replace the placeholders, add your logo, update contacts, and adjust the internal rules so the policy reflects your actual environment and approved practices.
What does SACS-210 TPC1.2 require?
SACS-210 TPC1.2 requires the Third Party to develop, approve and communicate an Acceptable Use Policy. For audit readiness, the policy should be customized to the actual environment, communicated to in-scope personnel, supported by appropriate awareness or training, and followed through the organization's approved acknowledgment process.
Does the free download include an employee acknowledgment form?
No. The free resource includes the AUP policy template. A separate AUP Acknowledgment Form is included in the full SACS-210 Compliance Kit and can be used as part of the organization's acknowledgment process.
Does the template cover "Bring Your Own Device" (BYOD)?
Yes. The template includes practical rules for approved personal devices and prohibits unauthorized or unmanaged devices from storing, processing or accessing company or proponent data unless formally approved. It does not assume that a small organization already operates an MDM platform.