Acceptable Use Policy
This Acceptable UsePolicy ("AUP") is incorporated into the Master Services Agreement("MSA") between Corsair USA, LLC ("Corsair") and Client. The purpose of this AUP is to establish acceptable use standards for systems, networks, cloud services,software, and cybersecurity services managed by Corsair.
1. GENERAL PRINCIPLES
Client agrees that all systems, accounts, networks, applications, and services managed by Corsair shall be used:
• For legitimate business purposes;
• In compliance with applicable laws;
• In accordance with vendor licensing agreements;
• In a manner that does not create unreasonable cybersecurity risk.
2. PROHIBITED ACTIVITIES
Client and its users shall not use managed systems or services for:
Illegal Activities
• Violate local, state, federal, or international laws;
• Engage in fraud or financial crimes;
• Distribute illegal materials;
• Violate intellectual property rights.
Security Violations
• Attempt unauthorized access;
• Circumvent security controls;
• Share credentials;
• Disable security software;
• Tamper with monitoring systems;
• Install unauthorized remote access software.
Malicious Activities
• Introduce malware;
• Distribute ransomware;
• Perform denial-of-service attacks;
• Conduct penetration testing without written authorization;
• Interfere with network operations.
Unauthorized Software
• Install unlicensed software;
• Install unsupported operating systems;
• Install cryptocurrency mining software;
• Install peer-to-peer file sharing applications;
• Install software known to create security risks.
3. PASSWORD REQUIREMENTS
Users shall:
• Maintain unique passwords;
• Avoid password sharing;
• Use passwords of at least twelve (12) characters;
• Use multi-factor authentication where available;
• Immediately report suspected compromise.
Passwords shall not be:
• Shared via email;
• Written in unsecured locations;
• Reused across multiple systems.
4. MULTI-FACTORAUTHENTICATION
Client agrees toimplement and maintain multi-factor authentication for:
• Microsoft 365 accounts;
• Administrative accounts;
• VPN access;
• Remote access systems;
• Cloud administrative accounts;
• Financial applications where supported.
Failure to implementmulti-factor authentication may limit Corsair's liability for account compromise.
5. EMAIL SECURITY
Users shall not:
• Open suspicious attachments;
• Click unknown hyperlinks;
• Share credentials via email;
• Bypass email security controls.
Suspected phishing messages shall be reported immediately.
6. ENDPOINT SECURITY
Client agrees that usersshall not:
• Disable antivirus protection;
• Disable endpoint detection software;
• Disable operating system updates;
• Jailbreak or root devices;
• Remove management agents;
• Circumvent security policies.
7. REMOTE ACCESS
Remote access shall:
• Utilize approved methods;
• Require multi-factor authentication;
• Be restricted to authorized users;
• Be monitored and logged.
Unauthorized remote access software is prohibited.
8. DATA HANDLING
Client shall:
• Properly classify sensitive information;
• Protect confidential information;
• Restrict access based on business need;
• Comply with applicable regulatory requirements.
Client remains solely responsible for:
• Data ownership;
• Data classification;
• Data retention requirements;
• Regulatory compliance.
9. BRING YOUR OWN DEVICE(BYOD)
If permitted by Client policy:
• Devices must be supported and patched;
• Devices must use encryption;
• Devices must use password protection;
• Devices may be subject to security controls;
• Devices may be remotely wiped when necessary.
10. MONITORING
Client acknowledges that Corsair may monitor:
• Network activity;
• Endpoint activity;
• Authentication events;
• Security logs;
• Administrative activities;
• Threat intelligence indicators.
Monitoring is performed solely for operational and security purposes.
11. SECURITY INCIDENTREPORTING
Users shall immediatelyreport:
• Suspicious emails;
• Lost devices;
• Credential compromise;
• Malware infections;
• Unauthorized access;
• Security incidents.
Failure to reportincidents promptly may increase damages and liability.
12. VIOLATIONS
Violations of this AUPmay result in:
• Account suspension;
• Removal of system access;
• Additional security requirements;
• Service suspension;
• Termination of services.
Corsair reserves the right to take emergency action to protect Client systems and services.
13. CLIENTACKNOWLEDGEMENT
Client acknowledges thatcompliance with this AUP is a material requirement of the Master Services Agreement and that violations may increase cybersecurity risk and limit Corsair's liability.
