University Policy 8000
Last Revision Date
Vice President and Chief Financial Officer, (208) 426-1200
Office of Information Technology, (208) 426-4357
Scope and Audience
This policy applies to all users of University information technology resources.
- Family Educational Rights and Privacy Act 34 CFR Part 99
- Electronic Communications Privacy Act of 1986 (ECPA)
- Idaho Code §67-5745C(3)
- Idaho Code Chapter 1, Title 74 (Idaho Public Record Act)
- Executive Order 2005-22
- Idaho Technology Authority (ITA)
- Idaho State Board of Education (SBOE)
- University Statement of Shared Values
- University Policy 1140 (Copyright Fair Use)
- University Policy 1060 (Non-Discrimination and Anti-Harassment)
- University Policy 1065 (Sexual Harassment)
- University Policy 2020 (Student Code of Conduct)
- University Policy 6120 (Payment Card Acceptance Policy)
- University Policy 7070 (Employee Political Activities)
1. Policy Purpose
To maximize the value of University Information Technology (IT) resources, permit maximum freedom to use consistent with state and federal law, policies of the Idaho Technology Authority (ITA), and Idaho State Board of Education (SBOE).
2. Policy Statement
University IT resources are provided to support the University and its academic, research, and service missions, the University’s business and administrative functions, and its student and campus life activities. Use of University IT resources must comply with state and federal laws and regulations, executive orders and policies of the Idaho Technology Authority (ITA), the Idaho State Board of Education, and University policies.
3.1 Information Technology (IT) Resources
An array of products and services that collect, transform, transmit, present, and otherwise make data into usable, meaningful and accessible information. IT Resources include but are not limited to: desktop, laptop, and tablet PC’s; handheld devices including but not limited to, cell phones; e-mail, voicemail, servers, central computers, and networks; cloud storage systems; network access systems including wireless systems; portable hard drives and databases; computer software; printers and projectors; telephone equipment and switches including local and long-distance services; camcorders, TVs, VCR’s, and FAX machines; satellite equipment and any other current or future IT resource adopted by the University as new technologies are developed to add to this array.
4. Responsibilities and Procedures
4.1 Personal Use Limited
The primary purpose of University IT Resources is to conduct official University business. University employees may, however, use the Internet and electronic mail on occasion for individual purposes on their personal time. See the Governor’s Executive Order No. 2005-22. See also University Policy 7070 (Employee Political Activities).
4.2 Academic Freedom and Associated Responsibilities
a. The First Amendment rights of academic freedom and freedom of expression, including the responsibilities associated with those rights, apply to the use of University IT Resources.
b. These rights and responsibilities are guided by this policy, the University’s Statement of Shared Values, University Policy 1060 (Non-Discrimination and Anti-Harassment, University Policy 2020 (Student Code of Conduct, other applicable University policies, the policies of the Idaho State Board of Education and Idaho Technology Authority (ITA), Executive Orders, and other state and federal laws and regulations.
4.3 Limited Privacy Expectations
Boise State University, as a public institution of higher education, is subject to the public records laws of the State of Idaho. While some information may be exempt from disclosure, information or records stored on University IT Resources are generally presumed to be open for review and inspection and are subject to public disclosure requests and examination by University officials in order to determine if exemptions apply to prohibit disclosure. As such, the University will examine and disclose information or records stored on University IT Resources as required by law. In addition, the University may have a business necessity or reason to access and examine information, records, files, communications, and accounts of its employees or students, including but not limited to the investigation of substantiated complaints or other reliable evidence of misuse or violation of law or policy. Therefore, users of University IT Resources should have a limited expectation of privacy in the use of such resources.
4.4 Prohibited Actions
a. University IT resources shall not be used for:
(i.) Commercial or personal profit-making purposes or for personal benefit where such use incurs a cost to the University and is not academic or work related.
(ii.) Accessing or attempting to access another person’s directory, files, or mail, whether protected or not, without permission of the owner. Attempts to access unauthorized IT resources via the computer network, to decrypt materials, or to obtain privileges to which the user is not entitled are prohibited.
(iii.) Visiting, viewing or distributing Internet sites or materials that contain obscenity, as defined under applicable federal and state law; and publishing, displaying, transmitting, retrieving or storing such obscene material.
(iv.) Intentional access to or dissemination of pornography by University employees, temporary staff, contractors or vendors, unless such use is specific to work-related functions and has been approved by the respective manager or such use is specifically related to an academic discipline or grant/research project. This applies to any electronic communication distributed or sent within the University network or to other networks while using the University network.
(v.) Intentionally or negligently interfering with the proper operation of any system or its use by others.
(vi.) Creating or distributing defamatory material or true threats, as defined under applicable law or other illegal activity, including but not limited to stalking as defined under applicable law.
(vii.) Downloading, disseminating, storing, using, or printing materials in violation of copyright laws including articles, music, videos, games, and software. See Use of Copyrighted Works Policy (#1130) for more details.
(viii.) Causing congestion, overload or disruption of networks or systems, including the distribution of chain letters.
(ix.) Creating or knowingly disseminating unwanted and unsolicited emails or materials (spam) in such a large volume that it tends to disrupt the proper functioning of University IT Resources or individuals’ ability to use such resources.
b. Users of University IT resources shall not:
(i.) Remove, transfer, disable or dispose of computer software licensed to the University. Contact OITfor details. Share University user credentials and passwords with other persons. Each user must have an individual account, passwords must be protected, and the user must not leave a machine logged on when not present unless the machine has been electronically locked and in a secure area, such as a private office.
(ii.) Consume unreasonable amounts of resources. The University may impose restrictions or limits on use of such resources.
(iii.) Falsify e-mail or newsgroup postings.
(iv.) Try to circumvent login or security procedures.
4.5 Policy Non-Compliance
a. Report suspected violations of this policy to the appropriate supervisor, department head, Dean, Vice President, or to OIT.
b. Use of these resources is a privilege, not a right, and abuse may result in the immediate removal of privileges pending final resolution.
c. Violation of any portion of this policy may result in disciplinary action. Whether a violation has occurred and what the appropriate disciplinary action is will be determined by the appropriate supervisor, department head, Dean, or Vice President. Incidents will be evaluated on a case by case basis and may result in the following sanctions up to:
(i.) Restricted access or loss of access to the University network or University IT Resources; and/or
(ii.) Suspension or expulsion, in the case of students; and/or
(iii.) Exclusion or dismissal from employment, in the case of faculty and staff; and/or
(iv.) Exclusion from campus, in the case of the public; and/or
(v.) Civil and/or criminal liability.
June 2004; January 2016