抖阴福利导航

BP 8201 IT Security and Encryption

Statement of purpose

抖阴福利导航 provides many technology products and services to support the academic and administrative needs of the College. Individuals who use the College鈥檚 IT resources are expected to follow certain defined behaviors in order to minimize information security risk and protect the College and its constituents.

Protecting students, faculty, and staff from the risk of identity theft or unauthorized disclosure of personal information is the primary goal of adopting the best practices described in this policy.

The purpose of this policy is to ensure that data is protected from unauthorized access, either physically (e.g.: preventing the theft of a laptop or USB drive), by using access controls (e.g.: locking computers when unattended), or by using encryption (e.g.: encrypting outbound emails using Virtru).

Scope statement

All 抖阴福利导航 (抖阴福利导航) employees, students, and affiliates or other third parties that create, use, maintain, or handle 抖阴福利导航 IT resources are subject to this policy. This policy applies to use of all 抖阴福利导航 owned and managed IT resources, use of any computer or mobile device connected to a 抖阴福利导航 network, all controlled sensitive data stored or transmitted using 抖阴福利导航 IT resources and all users of such data.

Policy summary

Users of 抖阴福利导航 IT resources shall adhere to computer security and data encryption best practices.

Policy

  1. Users who manage or use IT resources shall protect them from unauthorized modification, disclosure, and destruction to the best of their ability.
  2. Users shall secure and lock, or log off, all unattended devices.
  3. Users shall not give others unauthorized access to resources that have been assigned to them.
  4. Users shall not leave mobile devices that contain controlled sensitive data unattended.
  5. Users shall report the loss of mobile devices, or any other media containing controlled sensitive data, immediately (or as soon as possible).
  6. Users shall use extreme caution when opening attachments in email or text messages (or other electronic files) received from unknown senders.
  7. Users shall only use encryption approved and provisioned by 抖阴福利导航 to store or transmit controlled sensitive data.
  8. When sending emails containing controlled sensitive data from a pcc.edu email address to a non-pcc.edu email address, faculty and staff shall use 抖阴福利导航 email encryption services.

Visit the Virtru page on Spaces for instructions on how to install and use Virtru, or contact the IT Service Desk at 971-722-4400 or servicedesk@pcc.edu.

Exemptions

None.

Exceptions

Exceptions to this policy must be pre-approved in writing by the Chief Information Officer (CIO) / Chief Information Security Officer (CISO).

Policy violation

  1. Violation of this policy may result in disciplinary action in accordance with 抖阴福利导航 People, Strategy, Equity and Culture (PSEC) and/or Student Conduct guidelines.
  2. 抖阴福利导航 reserves the right to report security violations or compromises to the appropriate authorities. This may include reporting violations of Federal, State, and local laws and regulations governing computer and network use, or required accreditation reporting.
  3. Anyone who violates this policy may be held liable for damages to 抖阴福利导航 assets, including but not limited to the loss of information, computer software and hardware, lost revenue due to disruption of normal business activities or system down time, and fines and judgments imposed as a direct result of the violation.
  4. 抖阴福利导航 reserves the right to deactivate any user鈥檚 access rights (whether or not the user is suspected of any violation of this policy) when necessary to preserve the integrity of IT resources.

Complaint procedures

Report non-security-related violations (such as receipt of inappropriate content, other People, Strategy, Equity and Culture (PSEC) policy violations, general college policy violations, or regulatory compliance violations) to a supervisor, PSEC, or EthicsPoint.

Report information security and general technical policy violations to the IT Service Desk at 971-722-4400 or servicedesk@pcc.edu, or contact the CIO or CISO.

Governing standards, policies, and guidelines

None.

Definitions

  • Affiliate
    Any person or entity that has been sponsored by a 抖阴福利导航 manager to receive controlled temporary access to 抖阴福利导航 services.

    • This is generally as a result of a contractual relationship with 抖阴福利导航. For example, an air conditioning vendor may require affiliate access to test the HVAC system. A consultant project manager may require affiliate access to access project plans on a 抖阴福利导航 system.
  • Chief Information Officer (CIO)
    Senior manager of the Information Technology (IT) Department and a member of Cabinet.

    • At 抖阴福利导航, the CIO is responsible for all technology, with the exception of:
      • Online Learning (Academic Affairs)
      • Some specialized technology that supports CTE or other engineering programs (e.g. software that supports machine labs, specialized dental technology, etc.)
      • Some technology that supports auxiliary services (e.g. Point of Sale systems in the cafeterias and bookstores)
  • Chief Information Security Officer (CISO)
    Senior manager responsible for information security compliance at 抖阴福利导航.
  • Encryption
    The process of converting data to an unrecognizable or 鈥渆ncrypted鈥 form.

    • Encryption is commonly used to protect sensitive information so that only authorized parties can view it.
  • IT Resource
    (At 抖阴福利导航) All Information Technology (IT) resources that are the property of 抖阴福利导航 and include, but are not limited to, all network-related systems; business applications; network and application accounts; administrative, academic and library computing facilities; college-wide data, video and voice networks; electronic mail; video and web conferencing systems; access to the Internet; voicemail, fax machines and photocopiers; classroom audio/video; computer equipment; software and operating systems; storage media; Intranet, VPN, and FTP.

    • IT Resources include resources administered by IT, as well as those administered by individual departments, college laboratories, and other college-based entities.
  • Network
    (In IT) The technology that carries messages between one computer and another.

    • A network is a primary component of technology infrastructure and consists of hardware (e.g. routers, switches) that control and direct traffic; transport technologies (e.g. cables, fibre, wireless radio waves) that transport messages from Point A to Point B; and standards (e.g. Internet Protocol, Ethernet) that facilitate a common understanding of the messages being sent and how they are to be processed.
    • End points (or nodes) on a network are the senders and receivers of the messages and are usually computers (e.g. servers, desktops, laptops) 鈥 but can also be technology such as machine controllers, audio/visual devices, etc.
    • The Internet of Things (IoT) largely replaces people interacting across a network with machines and other technology devices interacting across a network, often using artificial intelligence (AI).
  • USB 鈥淭humb鈥 Drive
    A portable data storage device that includes flash memory. Has a USB connector that plugs into the USB socket on a computer.
  • User
    Any person who makes any use of any 抖阴福利导航 IT resource from any location (whether authorized or not).

Responsible executive

Chief Information Officer

Responsible officer

Chief Information Officer (CIO), Chief Information Security Officer (CISO)

Responsible office

Information Technology Department

Last revision date

09-09-2024