BCE Acceptable Use Policy
Last updated: August 6, 2025
Purpose
This policy outlines the standards and practices required for all AWS accounts created, managed, or operated by BizCloud Experts (BCE). It ensures full alignment with the AWS Acceptable Use Policy and upholds the security, compliance, and integrity of BCE-managed environments.
Scope
This policy applies to:
All AWS accounts provisioned or managed by BCE
All BCE internal AWS environments
All client AWS environments under BCE operational management
Key Requirements
Acceptable Use Compliance
No AWS account managed by BCE may be used for:
Illegal, harmful, or fraudulent activities
Violation of intellectual property or privacy rights
Promotion of violence, terrorism, or exploitation
Child sexual exploitation or abuse content
Security breaches or denial-of-service attacks
Sending spam, malware, or deceptive content
Least Privilege Enforcement
All permissions must follow the principle of least privilege, granting only the minimum access required for each role
Multi-Factor Authentication (MFA)
MFA is mandatory for all:
Root users
IAM users with administrative privileges
Reporting Violations
If you become aware of any violation of this Policy, please report it immediately to our security team at security@bizcloudexperts.com.
Responsibilities
BCE Cloud Operations Team:
Configure and manage AWS Organizations, Service Control Policies, and IAM roles
Enable and monitor CloudTrail, AWS Config, and GuardDuty across all managed accounts
Identify and remediate AUP violations immediately
Security & Compliance Team
Review security alerts and audit reports monthly
Update internal security policies in response to AWS AUP changes
Incident Handling
If BCE is notified by AWS regarding a potential AUP violation:
BCE will follow its Incident Management Plan
All remediation actions will be logged and reported to relevant stakeholders
Clients will be notified immediately if impacted
Review Policy
This document will be reviewed:
Within 30 days of any AWS AUP change
Annually, even if no changes are reported
Approval
This policy has been reviewed and approved by BCE Leadership. All BCE clients and internal teams are expected to comply as a condition of BCE-managed AWS services.