Scope
Defines covered users, systems, and environments; clarifies applicability to on‑ and off‑installation devices.
A well‑defined Fort Bliss Acceptable Use Policy reduces cyber risk, clarifies user responsibilities, and supports accountability, audits, and incident response. It helps align everyday user behavior with federal standards, installation directives, and legal requirements while protecting mission data and personnel privacy.
The policy applies to multiple user groups across the installation to ensure consistent use and oversight of Fort Bliss IT assets.
Responsible for implementing and enforcing the AUP, configuring technical controls, reviewing incidents, and coordinating periodic training and audits. Signs off on policy versions and approves user attestation workflows for their assigned organizational units.
Manages contractor access requests, ensures contractors complete required training and attestations, and verifies that subcontractor agreements include appropriate security and handling clauses before granting system privileges.
Defines covered users, systems, and environments; clarifies applicability to on‑ and off‑installation devices.
Permitted activities, approved tools, and authorized resource purposes tailored to mission needs.
Explicitly lists disallowed behaviors such as credential sharing, unauthorized scanning, and data exfiltration.
Authentication, MFA, remote access rules, least privilege, and privileged account management requirements.
Notification of system monitoring, expectations of limited privacy, and retention of logs and recordings.
Disciplinary measures, reporting escalation, and contract remedies for violations.
| Field | Configuration |
|---|---|
| Authentication Method | DoD CAC or approved MFA |
| Retain Audit Trail | Yes — IP, timestamp, and actions |
| Document Formats | PDF/A or secure HTML |
| Access Control | Role-based, least privilege |
Use a platform that preserves audit trails, supports DoD authentication, and secures stored records.
Date when the current AUP version is released to users
Users must acknowledge within 30 days of publication
Policy reviewed and reauthorized at least yearly
Role-based training due within 45 days of assignment
Report suspected compromises immediately per installation guidance
Stakeholders draft policy text and collect legal and operational input.
Command leadership and legal counsel approve the final policy version.
Policy published and users complete mandatory acknowledgments.
Periodic audit and updates based on incidents or regulatory changes.
| Criteria | Fort Bliss AUP | Generic IT Security Policy |
|---|---|---|
| Primary Focus | user behavior | technical controls |
| Enforcement | personnel actions | system controls |
| Audience | all users | it staff and administrators |
| Typical Contents | acceptable use rules | configuration and hardening |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
When rolling out operational acknowledgments we needed a simple interface for staff
Property teams required mobile signing for on-site forms
Coordinates deployment and verifies technical controls, ensures systems support required authentication and logging, and validates exported audit trails for retention and review by command leadership and auditors.
Ensures users complete required training and attestations, maps user roles to access levels, and maintains records to support investigations, background checks, and compliance reporting.