Acceptable Use Policy
Defines appropriate employee use of business systems and information.
Sep 06, 2026$39
Foundational plans, workbooks, policies, and response tools for organizations with roughly 1–50 employees and no dedicated security team.
Defines appropriate employee use of business systems and information.
Controls account creation, privileged access, reviews, changes, and termination.
Provides recurring monthly, quarterly, and annual cybersecurity tasks.
Records hardware, software, SaaS, users, vendors, data, backups, and business processes.
Documents backup coverage, retention, testing, recovery methods, and responsibilities.
Defines how the business operates when critical technology is unavailable.
Focuses on invoice fraud, wire fraud, payroll diversion, and executive impersonation.
Response procedures for Microsoft 365, Google Workspace, CRM, accounting, cloud storage, and SaaS compromise.
Establishes system criticality, dependencies, RTO/RPO, restore order, and recovery responsibilities.
Defines roles, escalation, containment, recovery, evidence, communication, and post-incident activities.
Organizes evidence for underwriting, renewal, and cyber insurance applications.
Tracks identified security gaps and corrective actions.
Identifies cybersecurity weaknesses and prioritizes corrective actions.
Ensures access is removed and company information recovered during employee departure.
Establishes security requirements when employees join the company.
Provides awareness handouts, reminders, and basic training material.
Tracks incident events, decisions, evidence, affected systems, communications, and actions.
Establishes the organization’s overall cybersecurity rules.
Guides response to missing laptops, phones, tablets, and portable media.
Defines password, MFA, password-manager, and account-recovery requirements.
Guides response to compromised mailboxes, credentials, or malicious email.
Gives employees a standard method for reporting suspicious email and messages.
Step-by-step ransomware containment, backup validation, communication, and recovery.
Identifies and manages confidential, financial, employee, customer, and regulated information.
Establishes fundamental cybersecurity policies and procedures.
Flagship package combining incident response, inventories, recovery, logging, and response checklists.
Establishes vendor cybersecurity review and monitoring procedures.
Guides response when a critical supplier or technology provider experiences a cyber incident.
Helps evaluate third-party cybersecurity practices.
Response procedures for website, hosting, DNS, registrar, and ecommerce compromise.