Introduction
Access to computers, services and networks owned by Purdue University is a privilege
governed by certain regulations and restrictions. These include rules defined by the
University and the schools as well as all applicable federal, state and local laws ([1],[2],
[3],[4]).
The Center pledges to provide their authorized users the best computer and network
access possible and protect those resources as much as possible from unauthorized use
and access. Without this protection, these resources could be victims of internal and
external attacks that deny authorized access or result in the loss, dissemination, or
compromise of data.
People who use the center must agree to abide by the regulations set forth in this
Acceptable Use Policy. This means that the user agrees to behave responsibly according
to the standards established by Purdue University and this document while using
University systems and network resources.
Right to Use
All authorized users have the right to use computer and network resources within the
guidelines set forth in this policy.
Right to Privacy
No user will be subject to unauthorized scanning or monitoring except as defined by this
policy ([6]). Any request for access to logs or personal data must be mandated by the
proper authority. Only individuals who are specifically authorized shall perform
monitoring, and only the minimum amount of data necessary shall be collected. Data
collected through monitoring shall be made accessible only to authorized individuals who
are responsible for maintaining its confidentiality. Content monitoring of network
activity will not occur except as specifically defined below.
Allowance for Reasonable Monitoring([6])
The system administrator reserves the right to monitor the usage of all network resources
to ensure compliance with this policy, University policy, and federal, state and local laws.
All users agree to this monitoring implicitly through use of the network resources. This
includes:Logging and monitoring server usage and network traffic
* Accessing user data in the normal course of performing administration duties
* Monitoring resource usage to maintain functionality and efficiency
* Scanning, monitoring, and testing the network for security problems
Acceptable Uses
Users can use network and computer resources for University business that promotes the
goals of the Envision Center. Network and computer resources are to be used in ways that
do not unreasonably interfere with other users. Private use that does not interfere with the
use of the resources for University business or violate laws or policies is also allowed.
All usage of computer systems at Purdue University must fall within the policy
guidelines established by the University ([1],[2],[3],[4]). Understanding and following
these policies are the responsibility of each user.
Respect for Laws
Purdue users are expected to comply with copyright and intellectual property laws ([5]).
Users will not use unlicensed copyrighted material, make illegal copies of copyrighted
material, store such material on University systems, or transmit such materials over
University networks. Users will also not allow others to illegally use University licensed
software.
Respect for Other Users' Rights
Users will not use resources for non-University activities in ways that interfere with users
performing University business.
For University business, users will not unreasonably use computer and network resources
that interfere with other users' access to those resources. These resources include, but are
not limited to, perceptualization equipment, computing resources, network services,
bandwidth, and staff time.
Users will not conduct unauthorized scanning of computer network connected devices
and systems ([6]). This scanning includes but is not limited to unauthorized electronic
means to eavesdrop, collect, or disclose information about others.
Protection of Computer Resources
Users will operate equipment properly according to the specific purpose of each piece of
equipment. It is a user's responsibility to learn how to properly operate the equipment.
Access to equipment will be limited based on the knowledge level demonstrated by the
user.
Users will not attempt or assist in attempts to gain unauthorized access to passwords,
control information, services, computing resources, network resources, or computing
facilities ([7]).
Users will not access any data without permission from the owner of the data. This
includes data that are not covered by federal, state or local laws ([3],[4]).
Users will not operate their computers in ways that risk the security of the network or
other computer resources. This includes removing or preventing the installation of
security measures, software or patches.
Protection of Other Users
Users will not use computer and network resources in ways that jeopardize, harass,
intimidate, threaten, or otherwise harm other users, computers, or network resources
including local users and users external to the University ([8]).
Notification of Proper Authorities
Users who become aware of any violation of this policy should notify the proper
authorities. These authorities could include the Envision Center staff, university officials
or the police.
Consequences
Violations of this policy will be reported to the Envision Center's director and other
appropriate authorities. Non-compliance with this policy may also result in the loss of
access to computer resources. The network administrators reserve the right to remove the
network access and accounts of any user or computer that poses an immediate threat to
other users. Said access will be denied until the immediate threat is remedied. The
decision to permanently remove network or computer resource access and accounts will
be left up to the director of the Envision Center.
References
[1] Purdue IT Resource Acceptable Use Policy
http://www.purdue.edu/oop/policies/pages/information_technology/v_4_1.html
[2] Purdue Use of Electronic Mail Policy
http://www.purdue.edu/oop/policies/pages/information_technology/v_3_1.html
[3] HIPAA Policies and Procedures
http://www.itap.purdue.edu/security/policies/HIPPAPolicy.pdf
[4] FERPA Policies and Procedures
http://www.purdue.edu/oop/policies/pages/records/c_51.html
[5] Copyright Law
http://www.copyright.gov/title17/circ92.pdf
[6] Federal Wiretapping Law
http://www.eff.org/Privacy/Surveillance/200001_us_fed_wiretap_laws.html
[7] Indiana Computer Tampering Law
http://www.ai.org/legislative/ic/code/title35/ar43/ch1.html#IC35-43-1-4
[8] Indiana Intimidation and Harassment Law
http://www.in.gov/legislative/ic/code/title35/ar45/ch2.html
|