IT Do's and Don'ts Policy
IT Do's and Don'ts Policy
1. Purpose
This policy provides guidelines for the appropriate use of the company’s Information Technology
(IT) resources to ensure security, privacy, and operational efficiency.
IT Do's
● Safeguard confidential and proprietary information. Only share such data with authorized
personnel, and ensure it is stored securely.
● Use strong passwords for accessing company systems and change them regularly.
● Encrypt sensitive data when sending or storing it on external drives or cloud storage.
● Respect the privacy of others by not accessing or sharing personal data without proper
authorization.
● Ensure that email communication and document sharing respect confidentiality
agreements and legal requirements.
● Always comply with laws, including copyright, data protection, and intellectual property
rights, when using company technology resources.
● Ensure compliance with relevant industry regulations, such as GDPR, when handling
client and customer data.
● Lock your computer screen when leaving it unattended, even for a short period.
● Keep your devices physically secure, especially when working remotely or travelling.
● Use company-approved software and hardware only.
IT Don'ts
● Refrain from using company IT resources for personal business, financial transactions,
or illegal activities.
● Avoid using company devices for activities unrelated to work, such as personal
shopping, gambling, or social media browsing during work hours.
● Do not ignore or bypass security warnings, such as firewall alerts, antivirus notifications,
or system update reminders.
● Do not disable security features or firewalls unless instructed by the IT department for
troubleshooting purposes.
● Do not store personal or sensitive data on local devices unless explicitly authorized by
the IT department.
● Avoid leaving sensitive documents unattended in public spaces or on shared drives
without proper access controls.
Enforcement
Failure to adhere to this IT Do's and Don'ts policy may result in disciplinary action, including
termination, as per the company’s internal procedures and relevant legal obligations.