Division of Information Technology
PO Box 1510
Pembroke, NC 28372
Phone: 910.521.6260
Fax: 910.775.4337
Email: doit@uncp.edu
Location: D.F. Lowry Building, Room 110
Campus Map
Policies
DoIT 03 07 - Network Policy
Click here to download a MS Word file.
Effective date: April 25, 2008
Purpose
The University of North Carolina at Pembroke (hereinafter UNCP) provides computer access and capabilities through the Division of Information Technology and various college and department computer systems. UNCP relies heavily upon these systems to meet operational, financial, educational and informational needs. It is essential that these systems and machines be protected from misuse and unauthorized access. It is also essential that UNCP's computers, computer systems, and computer networks, as well as the data they store and process, be operated and maintained in a secure environment and in a responsible manner. This policy applies to all UNCP computer systems and refers to all hardware, data, software and communications networks associated with these computers. In particular, this policy covers computers ranging from multi-user timesharing systems to single user personal computers, whether free-standing or connected to the network. Computing resources are valuable, and their abuse can have a far-reaching negative impact. Computer abuse affects everyone who uses computing facilities. The same morality and ethical behavior that applies in the non-computing environment applies in the computing environment.
The UNCP computing and telecommunicating networks, computing equipment and computing resources are owned by UNCP and are provided primarily to support the academic and administrative functions of UNCP. Federal and state law, and University policies and procedures govern the use of this equipment and technologies. Additional rules and regulations may be adopted by various divisions/departments to meet specific administrative or academic needs. Any adopted requirements must be in compliance with applicable federal and state laws, and this policy.
Definition of Terms
Network Devices.
Network devices include any device that connects to the University internetworking infrastructure. Network devices may include desktop computers, laptop computers, internet protocol telephones, network storage devices, printers, network infrastructure devices such as routers, switches, and wireless access points. They may also include wireless devices such as laptop computers, PDAs, and some wireless telephones. These do not include devices that access UNCP service through an Internet Service Provider, such as home computers used to check email, Blackboard, etc.
Computer Systems.
Computer systems include any microcomputer (stand-alone or networked), workstation, mini-computer or mainframe computer used on this campus or, accessible by way of networks, at other locations.
Computer Networks.
Computer networks include any local or wide area communications systems connecting computer systems as defined above. The network backbone consists of the primary communications media which connect small networks and individual terminals, microcomputers, workstations, etc. to other devices. Local area networking media may consist of copper wire, fiber optic cable, thin or thick wire cable which is used to connect one terminal, microcomputer, workstation, etc. to another or to network interface equipment.
Administrative Privileges.
Administrative privileges are the highest level of permission that can be granted to a computer user. Levels of permissions are necessary in networked environments to ensure system security and prevent damage to computer hardware and software. A user with administrative privileges can perform tasks such as install and uninstall software and change a computer's configurations.
Policy
1. Network Security
2. Network Accounts
3. Physical Security
Access to physical spaces such as closets and rooms that contain functioning network infrastructure devices and server devices shall be limited to personnel authorized by the Associate Vice Chancellor for Information Resources and Chief Information Officer and, in cases involving an imminent threat of physical harm, the Director of Police and Public Safety. Access may be controlled through special access technologies such as card swipe, biometric, and other special devices.
4. Computer Security Incident Response.
The University will maintain an emergency response plan that includes the internetworking infrastructure and all network devices.
5. Compliance.
UNCP will maintain its network and network devices in compliance with all Federal, State, or Regulatory agency requirements. These guidelines are intended to satisfy requirements for important laws such as the Federal Educational Rights Protection Act (FERPA), the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act, and the Payment Card Industry (PCI). UNCP network policies and procedures are subject to audit by the NC Office of the State Auditor.
6. Monitoring the Network
UNCP expressly reserves the right to impose any restraints or monitor the content of communications, data, or other information on the UNCP technology infrastructure:
The University respects the privacy of users. It does not routinely inspect or monitor the contents of electronic information, nor is the University responsible for its contents. However, when there is reasonable suspicion, and with the approval of the Chancellor or his delegate, DoIT reserves the right:
Users have no Constitutional expectation of privacy in any information on the UNCP technology infrastructure. UNCP cannot guarantee the confidentiality or integrity of or any User's continuing access to any information or data stored or transmitted on UNCP's Network because of the possibility, despite UNCP's best efforts, of unauthorized access by third parties ("hackers"), failure of equipment ("system crashes"), or some other event. Users are reminded that UNCP may be required to disclose any information transmitted or stored on the UNCP technology infrastructure that is determined to be a public record and not otherwise exempt from disclosure under applicable law. While every effort is made to insure confidentiality and integrity, Users are still responsible for maintaining the secrecy of their personal access and authentication information (passwords, etc.) and transmitting information (email, files, etc.) to the proper address.
In the event that such monitoring or review is necessary or appropriate, the Division of Information Technology or the Chancellor's designee will be responsible for such monitoring, investigation and enforcement or for working in cooperation with the federal, state, or local law enforcement agency involved.
7. Exceptions and Waivers
Recognizing the rapid pace of change in available information technology and the resulting possibility of unforeseen and unintended consequences arising from this policy, the Chancellor is authorized to issue waivers and/or exceptions to this policy if such waivers and exceptions maintain the integrity of sensitive data, do not result in a violation of applicable law, and are documented in a memorandum or other writing signed by the Chancellor. Such waivers and exceptions should be reported to the Board of Trustees at its next regularly scheduled meeting.
Responding to security and abuse incidents
All users have the responsibility to report any discovered unauthorized access attempts or other improper usage of UNCP computers, networks, or other information processing equipment. If a security or abuse problem with any University computer or network facility is observed by or reported to a user, such user shall immediately report the same to the Division of Information Technology.
Range of disciplinary sanctions
Persons in violation of this policy are subject to a full range of sanctions, including, but not limited to, the loss of computer or network access privileges, disciplinary action, and dismissal from the University of North Carolina at Pembroke. Any sanctions against employees will be imposed through procedures consistent with any applicable state regulations. Some violations may constitute criminal or civil offenses, as defined by local, state, and federal laws and the University may prosecute any such violations to the full extent of the law.
UNCP may suspend computer or network access privileges immediately and without prior notice to the user if necessary to preserve the safety or integrity of UNCP's Network or to prevent or investigate violation of applicable federal, state or local law or UNCP policy. The user must be sent written or electronic notice of any such intentional suspension of access and the reasons for it, and notice of the time, date and location for a meeting at which continued suspension of access may be discussed with the Executive Director of DoIT or his designee, who must reconsider his or her suspension decision in light of the information received in the meeting. Following the meeting, the Executive Director of DoIT or his designee shall send a copy of his or her decision upon reconsideration to the user and advise the user that he or she may appeal the decision to the Associate Vice Chancellor for Information Resources and Chief Information Officer ("CIO”).
Updated: Monday, July 14, 2008
© The University of North Carolina at Pembroke
PO Box 1510 Pembroke, NC 28372-1510 • 800.949.UNCP (8627) • 910.521.6000