Acceptable Use & Secure Browsing
Your technology is a business asset. Learn the policies and practices that keep your devices, email, cloud services, and AI tools secure without slowing your team down.
What You Will Learn
Your organization’s technology is a business asset. This module covers the policies and practices that keep your devices, email, cloud services, and AI tools secure without slowing your team down.
- Acceptable use policies: what you can and cannot do with work devices
- Secure browsing: how to recognize dangerous websites and avoid malware
- Cloud and SaaS security: the risks of unsanctioned cloud services
- Generative AI tools: how to use ChatGPT and similar tools safely at work
- Personal device policies: BYOD risks and rules
Acceptable Use: The Basics
An acceptable use policy (AUP) defines what employees can and cannot do with organization-owned devices, email, and internet access. It is not about surveillance. It is about setting clear expectations so everyone knows the boundaries:
- Work devices are for work. Personal use should be minimal and never involve sensitive data.
- Do not install software without IT approval. Even free tools can introduce malware.
- Do not share login credentials. Every user should have their own account.
- Do not disable security tools. Antivirus, firewalls, and MFA exist to protect you.
- Lock your screen when you step away, even for a minute.
- Report lost or stolen devices immediately. Do not wait to see if it turns up.
Quick Check
You step away from your desk for a quick meeting. What should you do with your computer?
Secure Browsing
The web is where most of your team works and where most malware infections happen. Here is how to browse safely:
Look for HTTPS
Before entering any information on a website, check that the URL starts with https:// (the s means secure). The padlock icon confirms the connection is encrypted. Never enter passwords or sensitive data on a site that only shows http://.
Watch for Fake Websites
Attackers create look-alike websites that mimic legitimate ones. Check the URL carefully for misspellings or extra characters. When in doubt, do not type the URL from an email. Type it manually or use a bookmark you trust.
Avoid Downloading Files from Unknown Sources
Free software, pirated content, and attachments from unknown emails are common malware delivery methods. Only download software from official sources or through IT-approved channels.
Quick Check
You want to use ChatGPT to help summarize a document containing patient names and treatment details. What should you do?
Generative AI Tools: ChatGPT, Copilot, and Others
AI tools are increasingly common in the workplace for drafting emails, summarizing documents, and generating reports. But they create a new data exposure risk:
AI Tool Safety Rules
- Never paste PHI, client data, financial data, or credentials into public AI tools like ChatGPT. You are sending that data to a third-party company.
- Treat AI tools like any other cloud service. They need IT approval before use with work data.
- Use enterprise versions when available. Microsoft Copilot for M365 and Google Gemini for Workspace have data protection agreements.
- Do not trust AI output blindly. AI can generate incorrect information. Verify facts before using AI-generated content.
- Do not use AI to generate or store passwords because the data may be retained by the AI provider.
Cloud Services and SaaS Risks
Cloud services like Google Drive, Dropbox, Slack, and Trello are powerful tools. But when staff sign up for them without IT approval, they create shadow IT. The risks include data exposure, account takeover, compliance violations, and data loss when staff leave.
If your team needs a cloud tool, they should request it through IT. STM can help vet and deploy approved alternatives that are secure and easy to use.
How This Looks in Your Industry
Healthcare Practices
Staff may use personal phones to access patient portals. Without a BYOD policy, those devices may not have encryption, MFA, or remote wipe capability, creating a HIPAA risk if the phone is lost.
Legal Firms
Attorneys may use personal cloud storage to work on case documents from home. This can waive attorney-client privilege if the data is exposed. Approved document management with encryption is essential.
Nonprofits
Volunteers and part-time staff often use personal devices. A simple BYOD policy requiring screen locks, encryption, and no storage of sensitive data on personal devices protects your organization.
Daycares and Schools
Staff may use personal phones to take photos of children for parent communication apps. COPPA and state child privacy laws require careful handling of student data, including photos.
Key Takeaways
- Work devices are for work. Do not install software, disable security tools, or share logins.
- Always check for HTTPS before entering any information on a website.
- Never paste PHI, client data, financial data, or credentials into public AI tools like ChatGPT.
- Request cloud tools through IT. Shadow IT creates data exposure and compliance risks.
- Lock your screen every time you step away, and report lost devices immediately.
Module Quiz
Select an answer for each question to reveal the correct response and explanation.
1. You want to use ChatGPT to help summarize a document containing patient names and treatment details. What should you do?
2. You step away from your desk for a quick meeting. What should you do with your computer?
3. A colleague recommends a free online tool for converting documents. How should you evaluate whether to use it?
4. Before entering your password on a website, what should you check?
5. Why should staff request new cloud tools through IT instead of signing up on their own?
Module 06 of 10 – Cybersecurity Essentials Training
