PL-4 Rules of Behavior
Description
The university defines scope, behavior, practices and compliance pertaining to use of information resources.
Applicability
- This Control applies to all information resource owners, custodians, and users.
Implementation
-
1University Standard Administrative Procedure 29.01.03.M0.02, Acceptable Use, describes individual responsibilities and expected behavior regarding information resource usage.
-
2It is the responsibility of the unit head or designee to obtain an acknowledgment from all individuals indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information resources.
-
3It is the responsibility of the Chief Information Security Officer to incorporate content regarding rules of behavior into the Annual Security Awareness Training required of all university employees (See Control AT-2).
- 3.1The content in the Annual Security Awareness Training shall be reviewed and updated as appropriate.
-
4University employees are prohibited from:
- 4.1Unauthorized representation of the university on social media, social networking sites, and external sites/application;
- 4.2Unauthorized posting of university information on public websites; and
- 4.3Use of university-provided username in conjunction with password for creating an account on external sites/applications.