Skip to content
Legal

Acceptable Use Policy

Expected conduct for systems, networks, and support services managed or provided by North Shield.

This policy sets out expected behaviour when using systems, networks, devices, or support services that we manage or provide. It exists to protect the availability, integrity, and confidentiality of those systems.

Where a client has its own acceptable use policy, that policy applies to its staff. This document describes our baseline expectations and applies alongside any client policy and the engagement agreement.

Expected conduct

  • Use managed systems for legitimate business purposes
  • Protect credentials and do not share accounts
  • Use multi-factor authentication where it is available
  • Report suspected security issues promptly
  • Follow change and approval processes for configuration changes
  • Keep managed devices enrolled, updated, and encrypted where supported

Prohibited activity

  • Attempting to access accounts, data, or systems without authorization
  • Bypassing or disabling security controls such as endpoint protection, encryption, or MFA
  • Installing unauthorized software or connecting unmanaged devices to protected networks
  • Sharing credentials or using another person's account
  • Deliberately introducing malicious code
  • Using managed systems for unlawful activity or harassment
  • Scanning, probing, or testing systems without written authorization
  • Removing or copying data outside approved channels

Monitoring

Managed systems generate operational and security logs. These are used to maintain availability and security, investigate incidents, and support the service. Monitoring is proportionate to that purpose and is carried out in line with the engagement agreement and applicable law.

Enforcement

Where activity places systems or data at material risk, we may take proportionate protective action, such as isolating a device or suspending an account, and will notify the client contact as soon as practical. Employment consequences are a matter for the client organization.

Reporting concerns

Requests and questions can be submitted through the contact page on this website.

Please note

This document is published for transparency and describes current practice. It is general information, not legal advice, and it does not replace the written agreement covering a specific engagement.