0 ratings 0% found this document useful (0 votes) 12 views 5 pages Information Security Policy
The Information Systems Acceptable Use Policy v4.0 for Aditya Birla Group outlines the acceptable use of its information systems, emphasizing that they should only be used for company-related activities and prohibits personal gain. Users are responsible for protecting data, adhering to security guidelines, and may face disciplinary actions for violations, including termination. The policy also mandates that users agree to its terms and acknowledges that the company can monitor usage and amend the policy as needed.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here .
Available Formats
Download as PDF or read online on Scribd
Go to previous items Go to next items
Information System Acceptable Use Policy v4.0
Aditya Birla Group
Information Security Policy
Information Systems Acceptable Use Policy
Perec
Preteens
Document Title: Status:
Information Systems Acceptable Use Polic Release
Prepared By: Classification:
Rishi Jethva Confidential
Reviewed By: ‘Approved By:
Manoj Sarangi Dr. Santrupt Misra, Director HR
‘Atul Jayawant, Group ClO
Version
1.0 ‘All Employees of Aditya Birla Group
2. [20 ‘Adityadisha, All Employees of Aditya Birla Group
3 [30 ‘Adityadisha, All Employees of Aditya Birla Group
Cinioces
‘Adityadisha, All Employees of Aditya Birla Group
No._| Version | Date ‘Changes Mado ‘i
4 4.0 4* Oct 2007 Initial Version Created
a "Amended the policy to merge information Systems AUP
3 on de Deoee and Internet and Email AUP. Other wording changes.
aa lee ‘Amended the Policy to add confidential and Personal data
12" July 2010 protection clause
st Amended the Policy to add clause on legitimate use of
a 40 Age 2012 Social Media and Blog sites
Page 1 of 5Information System Acceptable Use Policy v4.0
Information Systems Acceptable Use Policy
This document outlines policies for acceptable use of Aditya Birla Group's Information Systems, For the
Purpose of this policy, "Aditya Birla Group” collectively refers to all legal entities within the Aditya Birla
Group. ‘Company’ or “Unit” refers individually to each of the legal entity within Aditya Birla Group. Aditya
Birla Group's Information Systems and facilities include any application, computer, server, electronic
Media, communication devices network, Information Technology services (including internet & email)
Provided / supported / procured / leased or used by Aditya Birla Group. Any service, or device (including
Personal computing devices such as smart phones, tablets etc.) owned / procured by the user and used
{or accessing Aditya Birla Group information must also adhere to this policy. The ‘user’ of the Information
‘System is any person (employees, trainees, contractor, and third party) who has been provided access to
Information Systems. The purpose of this policy is to ensure that all users use the Aditya Birla Group
‘computing facilites in an effective, efficient, ethical and lawful manner.
1. Aditya Birla Group Information Systems are to be used only for processing data and information
relating to Aditya Birla Group businesses. Any use of the Aditya Birla Group's Information
‘Systems/data for personal gain is prohibited.
2. Users are responsible for protecting any information in their possession including that stored on
their respective Aditya Birla Group workstations, laptops and personal computing devices.
‘3. Users shall not attempt to access any data or programs contained on Aditya Biria Group's systems
for which they do not have authorization or explicit consent of the data owner.
4. Users shall not purposely use Information Systems (including intemet and email) for any activity
with an intent of
‘+ discriminating, harassing, vilifying or victimizing others based on gender, race, religious,
beliefs, cisabilty, political conviction, sexual preferences, age or otherwise
‘© degrading the performance of systems
+ gaining access to a Aditya Birla Group system for which proper authorization has not
been given
+ depriving an authorized user access to a Aditya Birla Group's information system
+ attempting to gain more system access or privileges than allocated
‘+ circumventing Aditya Birla Group's Information Security measures
+ sharing information with a third party outside Aditya Birla Group, which will allow
circumvention of security systems by the third party
‘+ causing physical damage to facility or property
5. Users shall use only approved personal computing / hand held devices (e.g. iPad, tablets, Mobile
Phones, Blackberry etc.) for accessing / storing or exchanging company information like data/ e-
rmail/ SMS. These devices shall be used only in compliance to Mobile Computing Device Policy and
the users shall take due care to protect such devices and the data stored therein from loss, theft
and misuse.
Page 2 of 5Information System Acceptable Use Policy v4.0 Pal
6. Users will familiarize themselves with the contents of the Information Security User Handbook (and
any updates to these) and practice the same, Any doubls or queries should be raised with
respective Managers or CISO.
7. Users shall comply with security directives, guidelines, and polices at all times. Users shall not
circumvent or attempt to circumvent any logical or physical security control or guidelines issued by
‘Aditya Birla Group or the company. Additionally, users shall proactively participate in all security
and safety exercises / drills / trainings which may be conducted from time to time.
8. Users shall not download and / or install any unauthorized software.
9. Users shall not make unauthorized copies of copyrighted software, except as permitted by law or by
the owner of the copyright. Wherein copyright owner refers to the person or entity which possesses
the exclusive right to make copies, license, and otherwise exploit a literary, business, musical, or
artistic work, whether printed, audio, video, etc.
10. At all times, users are responsible for the content that they store or transmit using Aditya Birla
Group information Systems and mobile computing devices. Copyrighted materials belonging to the
entities other than Aditya Birla Group may not, subject to the allowable exemptions, be transmitted
by employees on Aditya Birla Group e-mail! Internev/intranet system. All users obtaining access to
other companies’ or individuals’ materials must respect all copyrights and may not copy, retrieve,
modify or forward copyrighted materials, except with permission of the copyright owner, or as may
be permitted under the appropriate law. Each employee shall observe all terms and conditions of
the license agreement, under which the license to use any copyrighted work has been obtained,
11. Use of E-mail or communication facilities not provided or authorized by Aditya Birla Group is
prohibited for any official communication. Users shall not use any unauthorized e-mail services,
instant messengers or communication facilities for transmission, storage or retrieval of any official
information.
42. Any messages or information sent by a user to another individual outside Aditya Birla Group via an
electronic network are statements that reflect on Aditya Birla Group. Therefore, all such
‘communication should be done keeping Aditya Birla Group's security and image in mind.
48. Users shall treat personal data of employees, customers and business partners fairly and lawfully
Users entrusted with the task shall be responsible for collecting personal data only for specific,
lawful, explicit and legitimate purposes. Further users shall process this data consistent with those
purposes.
44, Users shall not, without the prior consent of the company, divulge company’s confidential
information whether electronic, oral, or written to any third party or for any purpose other than the
exclusive benefit of the company and Aditya Birla Group.
46. Aditya Birla Group routinely monitors usage pattems for its e-mailinternet communications’ other IT
services rendered. All messages created, stored, sent, of retrieved over the Aditya Birla Group's e-
mailinterevinformation Systems are the property of Aditya Birla Group and should not be
Considered private information. Aditya Birla Group Management reserves the right to access and
‘monitor all electronic messages and soft or hard copy files of the user at all imes
16. Users will be held personally liable for any defamatory, obscene, offensive, political, proprietary,
copyrighted or libellous content they may posV propagate / transmit / store using internet / personal
‘computing devices / email / social media or blog sites. Third parties may pursue legal action against
individuals, personally, for their content uploaded on social media platforms.
Page 3 of 5Information System Acceptable Use Policy v4.0
17, In case users become aware of weaknesses in security of Aditya Birla Group's Information System
oF of any incidents of possible misuse or violation of this policy, the user shall report the same to
hherihis Manager or Chief Information Security Officer (CISO).
Aditya Birla Group may take any breach of this policy as a sign of misconduct by the user and the user
may be subject to the following
@) Verbal or written warning
) Counseling Withdrawal af access and system privileges in part or whole
©) Any combination of above
Serious or repeated breach of this policy can be construed as gross misconduct and disciplinary actions
‘may include:
a) Dismissal
b) Loss of benefits
c) Legal proceedings in accordance with State and Federal Laws
3) Any Combination of the above
Page 4 of 6tnformation System Acceptable Use Policy v4.0,
User Agreement
Information Systems Acceptable Use Agreement
have received a copy of Aditya Birla Group's Information Systems Acceptable Use Policy. | have read
the aforementioned document, understood the same and agree to abide by policies that are set forth
\erein.
\ recognize and understand that Aditya Birla Group's Information Systems are to be used for conducting
the Aditya Birla Group business only. | am aware that Aditya Birla Group may access and review any
‘materials stored on my workstation, handheld devices, USB or any other storage devices etc., oF
information sent or received by me through the Aditya Birla Group network, e-mail or Internet connection.
|lunderstand that this Acceptable Use Policy applies to me, and | am aware that violations of this policy
may subject me to disciplinary acton, up to and incuding termination from employment and or any legal
tion,
| indemnify Aditya Birla Group, its Officers, and other employees of any damage, harm, and liability
arising out of breach of this policy by me or due to any negligence on my par.
Furthermore, | understand that this policy and document can be amended at any time by Aditya Birla
Group. | further acknowledge that any changes in future to this policy may be communicated to me
through physical or electronic means.
Re Saves
User Signature Ee
RAkIB 2ZrHooR Wand
User Name & Employee Code Unit
Jammu
Location
Manager Signature"
05-01-2025
Date
Manager Name & Employee Code
*Manager Signature is required only when the access to the Information System is given to the vendor
personnel or Non Aditya Birla Group employee.
Page 5 of §