Acceptable Computer & Internet Usage at Work
BinariumCourse Code: IT101 | Organization: Binarium Corp | Duration: Approximately 75 Minutes | Language: English
Every employee who uses a company device, company email, or the company network is subject to the Acceptable Use Policy (AUP) — whether they have read it or not. The AUP is a legal framework that defines how company technology assets may be used, what is prohibited, how the company monitors usage, and what the consequences of violations are. This course makes the AUP understandable, practical, and actionable for every employee regardless of their role or technical background. By the end, you will not only know the rules — you will understand why they exist and be able to apply them to the real situations you face at work.
What You Will Learn
This course is structured across six chapters covering the full scope of technology acceptable use, privacy, and workspace security:
- Chapter 1 — Why the AUP Matters: The legal and operational basis of the Acceptable Use Policy; what technology governance means for employees and organizations; the consequences of AUP violations (disciplinary, legal, reputational); Binarium Corp's obligations to clients, regulators, and partners; the cost of cybersecurity incidents driven by policy non-compliance.
- Chapter 2 — Acceptable vs. Prohibited Use: Acceptable use of company email, internet, and communication platforms (Microsoft Teams, SharePoint, voice systems); personal use limits and the "reasonable personal use" standard; prohibited content categories (adult/pornographic, gambling, piracy, hate speech, extremist content); prohibited activities including cryptocurrency mining on company hardware, accessing dark web resources, and using shadow AI tools (unauthorized ChatGPT, consumer AI) with company or client data.
- Chapter 3 — Software, Hardware, and Data: Prohibitions on unauthorized software installation and the risks of shadow IT; BYOD (Bring Your Own Device) restrictions and MDM enrollment requirements; USB drive and removable media controls; working with company data on personal devices — the three-tier data classification framework (Public, Internal/Confidential, Restricted/PII/Client Confidential) and permitted storage locations; obligations when leaving the company; software license types (per-seat, concurrent, site, SaaS, open source) and the legal consequences of license non-compliance; BSA and CAAST audit risk in Canada; open source copyleft obligations (GPL, LGPL, MIT).
- Chapter 4 — Privacy and Monitoring: What Binarium Corp monitors and how (email, web browsing, endpoints, network traffic, cloud apps, physical access); who reviews monitoring data and under what circumstances; the Canadian privacy law framework for workplace devices (PIPEDA, PIPA Alberta/BC, PHIPA Ontario); the landmark Supreme Court of Canada decision R. v. Cole (2012 SCC 53) and its practical implications for employee privacy expectations on employer-issued devices; company email as a business record subject to retention requirements; IIROC/MFDA 7-year retention rules; litigation holds and the prohibition on spoliation; email disclaimers — what they do and do not accomplish.
- Chapter 5 — Workspace Hygiene: The clean desk policy — definition, scope, and what must be cleared; physical document security and the risk of shoulder-surfing and visitor exposure; screen lock policy — Binarium Corp's 5-minute automatic lock requirement and the mandatory manual lock on departure; screen lock keyboard shortcuts (Win+L, Control+Command+Q); tailgating as a physical security attack and how to prevent it; visitor management — sign-in, badge issuance, escort requirements, tailgating prohibition, and the "friendly challenge"; remote visitor and screen-sharing confidentiality obligations; paper document disposal — DIN 66399 shredding standards (P-4 cross-cut minimum); real-world dumpster-diving incident in Ontario (2023); digital media disposal and certified data wipe requirements.
- Chapter 6 — AUP Acknowledgement & Final Assessment: Full text review of the ten AUP commitments employees make; course completion acknowledgement; 20-question final assessment; certificate issuance.
Learning Objectives
Upon completing this course, you will be able to:
- Identify the categories of prohibited content and prohibited activities under the Binarium Corp AUP, and explain the business and legal rationale for each prohibition
- Apply the three-tier data classification framework to determine where company data may be stored, how it may be accessed on personal devices, and what controls are required
- Distinguish between common software license types (per-seat, concurrent, site, SaaS, open source) and describe the specific employee behaviour that constitutes a license violation in each case
- Explain what company systems are monitored at Binarium Corp, describe the legal disclosure basis for that monitoring, and articulate the principles from R. v. Cole (2012 SCC 53) regarding employee privacy expectations on employer-issued devices
- Apply the clean desk, screen lock, visitor management, and document disposal requirements in day-to-day workplace situations — including during client visits, remote work sessions, and end-of-day routines
Who This Course Is For
This course is mandatory for all Binarium Corp employees regardless of role, department, or seniority. No technical background is required. The course is designed to be equally relevant for:
- Client-facing staff (account managers, consultants, project managers) who handle client data and contracts
- Administrative and operations staff who process documents, manage schedules, and coordinate communications
- Finance and accounting staff who work with financial records, invoices, and banking data
- IT and technical staff who have elevated system access and unique software installation responsibilities
- HR staff who handle employee personal information, payroll data, and HR records
- Executives and managers who set the tone for technology use and must model AUP compliance
- Remote and hybrid employees who regularly work with company data outside the office environment
The course is grounded in the Canadian legal context — referencing PIPEDA, the Criminal Code of Canada, Supreme Court of Canada jurisprudence (R. v. Cole), BSA and CAAST enforcement in Canada, and real Canadian workplace incidents — while covering principles that apply universally across industries.
Prerequisites
None. This course requires no prior technical knowledge, legal background, or IT training. All employees who can use a computer and access company systems are the intended audience.
Duration
Approximately 75 minutes of instructional content across six chapters, plus graded knowledge checks at the end of each chapter and a 20-question final assessment. Employees who need extra time to review specific sections may complete the course at their own pace — the system saves progress automatically.
Grading and Certificate
This course uses a weighted grading model:
- Knowledge Checks (30%): Five graded knowledge checks — one at the end of each of Chapters 1 through 5. Each check consists of 3–5 questions and allows 2 attempts. Correct answers are displayed after completion to reinforce learning.
- Final Assessment (70%): A 20-question final exam covering all six chapters. One attempt only. A wide range of question formats is used including multiple choice, true/false, and scenario-based questions. Answers are displayed after the due date.
- Passing Grade: 70%
Employees who achieve a passing grade will receive the Certificate in Acceptable Computer and Internet Usage (IT101), issued by Binarium Corp. The certificate is available for PDF download and LinkedIn sharing from the Training Portal upon course completion. Recertification is required annually — your Training Portal dashboard will notify you when recertification is due.
Recommended Next Courses
- CYB101 — Cybersecurity Fundamentals (CIA triad, malware, ransomware, social engineering, incident reporting)
- SEC102 — Phishing Awareness (phishing methodology, BEC, spear phishing, simulated phishing exercises)
- PRV101 — Data Privacy: PIPEDA and Quebec Law 25 (privacy obligations, subject access requests, breach notification)
- PWD101 — Passwords and MFA Best Practices (password hygiene, MFA types, password manager adoption)
Binarium Corp | Managed IT & Cybersecurity Services | Canada
Training Enquiries: training@binarium.ca | Helpdesk: 1-855-274-6899 | helpdesk@binarium.ca