LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Acceptable Use Policy

Public security and assurance reference

POL-13: Acceptable Use Policy

Purpose

This policy defines the acceptable use of LNC Nexus systems, applications, and data. It ensures that resources are used responsibly and legally to protect legal-medical knowledge and analysis services.

Scope

This policy applies to all employees, contractors, consultants, temporary staff, and third-party vendors who use LNC Nexus hosted, private, or self-managed deployments.

Policy Statements

Users shall use LNC Nexus resources only for authorized business purposes. Prohibited activities include unauthorized access, data theft, and malware distribution. In self-managed deployments, customers are responsible for enforcing acceptable use; LNC Nexus provides the framework but not the enforcement. Regulated data handling requires additional restrictions. No resource shall be used for personal gain without explicit authorization.

Roles and Responsibilities

The Security Team defines acceptable use standards and monitors compliance. Users follow acceptable use procedures and report violations. Department heads ensure compliance in their areas. System administrators enforce technical controls.

Evidence and Review

Usage logs, violation reports, and audit records serve as evidence of compliance. The Security Team conducts periodic reviews of acceptable use practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Access may be suspended immediately upon detection of a violation.

POL-1 (Access Control Policy), POL-2 (Authentication and Password Policy), POL-8 (Information Security Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft