Acceptable Use and Policies - Guidance
Guidelines for Incidental Personal Use
- Does not interfere with the person's work performance
- Is of nominal cost or value
- Does not create the appearance of impropriety
- Is not for a political or personal commercial purpose
- Is reasonable in time, duration, and frequency
- Makes minimal use of hardware, software and network resources
Always Prohibited Activities for Personal or Professional Use
- Locally installed Software, or AI tools, that give access to your system, passwords, or data are not allowed to be run on NDSU owned computers without permission by IT
- Use for harassment or similar inappropriate behavior
- Use for accessing or distributing sexually explicit, offensive or erotic material
- Violation of copyright laws
- Use for probing or hacking
- Use of non-business streaming technologies that consume significant amounts of bandwidth
- Use of pirated software or data
- Knowingly distributing viruses or bypassing established security
- Using University provided email to send or receive confidential information such as social security numbers or tax returns.
- Using University provided storage services to store confidential information that is not required as a part of your job duties, such as your own social security number or your own tax returns
Summary of Procedural Guidelines
- Bandwidth and network monitoring
- Complaint by a supervisor, other employee or person
- Inadvertent discovery during routine service or maintenance
- Legal copyright complaint (includes copyrighted materials such as music, movies, software, etc.)
- Creation or distribution of SPAM or other network abuse
- Law enforcement query or subpoena; open records request
The NDSU Chief IT Security Officer will be notified if they are not already aware of the problem. The appropriate Dean(s) or Director(s) will be notified as soon as possible so that there can be an initial decision or meeting established with the Appropriate Use Review Committee* (AURC) to assess the situation and agree on an appropriate course of action. The alleged violator will not be notified until this discussion has taken place and a decision when to notify the alleged violator has been made. A course of action is determined that can include monitoring and/or seizure and examination of equipment and related IT items (for example: computers, communication devices, hardware, software, media).
Occasionally, emergency action might be necessary so that the NDSU Chief IT Security Officer may not be able to contact all the above officials before an action is taken. If criminal violations are suspected, appropriate law enforcement will be notified. Outcomes of the investigation could include the following determinations: no violation, violation of law or policy, and/or possible criminal violations. Sanctions, if a violation is found, could include, but are not limited to: verbal caution; letter of warning; loss of computer and/or network access; referral to the Employee Assistance Program; referral for training and education; letter of reprimand; suspension with or without pay; and termination of employment. Any criminal process is separate but can also be considered when deciding on appropriate sanctions. The employee may use the normal employment appeals processes for any sanctions imposed.
*Members of the AURC include the NDSU Chief Compliance Officer, the North Dakota Assistant Attorney General, the NDSU Vice President of Information Technology, and the Chief Information Security Officer or their designees.
Some Policies and Laws that Apply to NDSU
- NDSU Policy 158 - Acceptable use of Electronic Communications Devices
- NDSU Policy 158.1 - E-mail as an Official Communication Method for Employees
- NDSU Policy 710 - Computer and Electronic Communications Facilities
- NDSU Code of Student Conduct
- ND State Board of Higher Education Policy 1202.1 - Acceptable Use of Information Technology Resources
- North Dakota Century Code
- NDCC § 12.1-20-05.1: Luring Minors by Computer
- NDCC § 12.1-06.1-08: Computer Fraud - Computer Crime
- NDCC § 12.1-27.1-01. Obscenity - Definitions -Dissemination - Classification of offenses
- NDCC § 12.1-27.2-04.1. Possession of certain materials prohibited
- US Law
- 18 USC § 1462: Importation or Transportation of Obscene Matters
- 18 USC § 2252: Certain Activities Relating to Material Involving the Sexual Exploitation of Minors
- 18 USC 2422(b): Coercion and Enticement
- Family Educational Rights and Privacy Act (FERPA)
- Gramm-Leach-Bliley Act (GLBA)
- Cybersecurity Maturity Model Certification (CMMC)