IT Acceptable Use Policy

Principles

  • Our Information Systems are fundamental to our business and process the vast majority of our important data. This data is extremely valuable and is constantly threatened by Cyber Attacks.
  • We are committed to protecting our data and information and complying to any legal, regulatory or contractual requirements.
  • We always act in an ethical manner when using Information Systems, which includes public platforms and social media.
  • We follow the rules and processes that apply to our Information Systems and do not attempt to bypass any controls.

We

  • do not connect personal devices to Rolls-Royce internal networks or use them to process/store sensitive or controlled information without written authorisation;
  • do not store personal data on Rolls-Royce’s systems unless that data is required as part of our role;
  • do not use company identities, including branding or official representations, in any non-Rolls-Royce communications or on external social media platforms unless authorised to do so;
  • only use those Information Systems and applications which we have been authorised to use as part of our role;
  • do not change or attempt to change the configuration of any Company device issued to us or Information System or application to which we have access unless authorised to do so;
  • use AI tools in accordance with the Rolls-Royce Group AI Policy;
  • limit the use of any removable media only to those that are authorised to use and with a critical business need;
  • are responsible for the data on our Information Systems and ensure that it is classified and handled in accordance with the rules and regulations that apply, particularly when travelling with IT equipment;
  • help protect the Company by:
    • complying with the password standard and never divulging our password to others – unless required to do so by law;
    • ensuring devices are locked when not in use;
    • ensuring access rights are role-based and subject to regular reviews;
    • accepting any software updates in a timely fashion;
    • being extremely careful about clicking on links or attachments in emails from unknown or unexpected senders;
    • looking after any IT device (including not leaving items unattended in our own vehicle or other vehicles at any time) and reporting any losses; and
    • not browsing, posting or otherwise interacting with websites that are likely to be deemed unacceptable even if they are not blocked;
  • monitor the Information Systems to the extent permitted or as required by law and as necessary and justifiable for business purposes;
  • report policy breaches, security incidents and suspicious emails to the cyber security contacts listed; and
  • read the introduction to our Code and Group Policies to understand who they apply to and the consequences for breaching them.

Leaders

  • make sure that IT equipment (laptops, removeable drives, phones, etc) is returned when a team member leaves; and
  • ensure that their teams have access only to the systems and data they need to do their job.

Select Tabs

Our Code

Take a look back at our Code principles related to this policy:

Additional Guidance

Some of these are internal links and only available if accessing from a Rolls-Royce GAD network asset. 


Contacts
Some of these are internal links and only available if accessing from a Rolls-Royce GAD network asset. 

Take a look back at our Code principles related to this policy:

Our Code

Did you know our Code is available as an app.

Download on the app store – link to website (opens in a new window)

Did you know our Code is available as an app.

Download on the app store – link to website (opens in a new window)