BCE Acceptable Use Policy

Last updated: August 6, 2025

Purpose

This policy outlines the standards and practices required for all AWS accounts created, managed, or operated by BizCloud Experts (BCE). It ensures full alignment with the AWS Acceptable Use Policy and upholds the security, compliance, and integrity of BCE-managed environments.


Scope

This policy applies to:

  • All AWS accounts provisioned or managed by BCE

  • All BCE internal AWS environments

  • All client AWS environments under BCE operational management


Key Requirements

Acceptable Use Compliance

No AWS account managed by BCE may be used for:

  • Illegal, harmful, or fraudulent activities

  • Violation of intellectual property or privacy rights

  • Promotion of violence, terrorism, or exploitation

  • Child sexual exploitation or abuse content

  • Security breaches or denial-of-service attacks

  • Sending spam, malware, or deceptive content


Least Privilege Enforcement

All permissions must follow the principle of least privilege, granting only the minimum access required for each role

Multi-Factor Authentication (MFA)

MFA is mandatory for all:

  • Root users

  • IAM users with administrative privileges


Reporting Violations

If you become aware of any violation of this Policy, please report it immediately to our security team at security@bizcloudexperts.com.


Responsibilities

BCE Cloud Operations Team:

  • Configure and manage AWS Organizations, Service Control Policies, and IAM roles

  • Enable and monitor CloudTrail, AWS Config, and GuardDuty across all managed accounts

  • Identify and remediate AUP violations immediately

Security & Compliance Team

  • Review security alerts and audit reports monthly

  • Update internal security policies in response to AWS AUP changes


Incident Handling

If BCE is notified by AWS regarding a potential AUP violation:

  • BCE will follow its Incident Management Plan

  • All remediation actions will be logged and reported to relevant stakeholders

  • Clients will be notified immediately if impacted


Review Policy

This document will be reviewed:

  • Within 30 days of any AWS AUP change

  • Annually, even if no changes are reported


Approval

This policy has been reviewed and approved by BCE Leadership. All BCE clients and internal teams are expected to comply as a condition of BCE-managed AWS services.