Week 3
Draft an Acceptable Use Policy for a Growing Startup
Client Background
NebulaTech is a fast-growing software-as-a-service startup that recently secured Series B funding. They are currently scaling their workforce rapidly but lack formal cybersecurity governance or documentation.
Business Environment
The company operates in a highly dynamic, cloud-first environment where employees utilize a mix of corporate and personal devices. Informal communication channels like Slack are the primary method for IT and policy guidance. There is currently no official Acceptable Use Policy to govern hardware or cloud resource usage.
Security Incident
No breach; the engagement is a proactive policy drafting commission triggered by NebulaTech's Series B board requiring documented cybersecurity governance, including AI and cloud use, ahead of an enterprise customer security review.
Scope
The engagement is limited to a desktop review of internal communications and the subsequent drafting of the AUP. Technical network scanning or physical asset auditing is outside the scope of this project.
Objectives
- Identify policy gaps against NIST 800-53
- Define acceptable device usage standards
- Establish clear cloud resource boundaries
- Draft a professional Acceptable Use Policy
- Provide a findings summary for management
- Incorporate NIST CSF 2.0 terminology and explicit AI-safety and identity-centric guardrails (approved AI tools, data-classification-aware AI use, MFA/SSO) into the AUP.
Required Deliverables