-
Initiating Authority
- The Chief Information Officer and Chief Information Security Officer serve as the
initiating authorities for this policy.
-
Purpose
- The University recognizes that the provision of computing and information technology
resources is necessary in carrying out its educational mission. The purpose of this
policy is to set forth the requirements for acceptable use of University Information
Technology Resources.
-
Policy
-
Use of University Technology Resources
- The University provides University Technology Resources for use by currently enrolled
students, currently employed faculty and staff, and certain other designated affiliated
individuals. Other Users may be allowed limited use to certain types of University
Technology Resources (i.e., library computers and University guest internet); provided
that University Technology Resources are used for academic or other purposes deemed
to further the mission of the University.
- University Technology Resources shall only be used or accessed as authorized by the
University. A User’s authorized access level is determined by their current relationship
with the University and will be adjusted promptly when that relationship changes in
accordance with ITS and Information Security policies. A User’s access to University
Technology Resources shall be revoked promptly upon separation of employment, extended
inactivity, or loss of active affiliation with the University, unless otherwise permitted
under ITS and Information Security policies.
- The University does not guarantee uninterrupted use of or access to University Technology
Resources. Access to University Technology Resources may intermittently be unavailable
due to power failures, system testing, maintenance, and other special circumstances
as determined necessary by Information Technology Services or the Information Security
Department.
- Users assigned accounts on the University’s Industry and Defense Programs (IDP) enclave
(@idp.wichita.edu) are subject to additional acceptable-use requirements described
in the WSU-IDP Acceptable Use Addendum, which Employees may locate through IDP SharePoint.
-
Requirements for Use
- Governing Law and Policies. Users of University Technology Resources must comply with all federal, state and
local laws and regulations, and all University, Kansas Board of Regents (KBOR), and
State of Kansas policies and procedures related to such use, including the requirements
and prohibitions of this policy.
- Assignment and Consent. Users shall be responsible for all activities that occur while using University Technology
Resources assigned to them and shall follow all University policies that govern the
resources and/or data maintained in them. Continuing to use University Technology
Resources indicates User awareness of this policy and consent to the University’s
terms and conditions of use.
- Use of Personal Accounts and Systems for Work Communications. Users shall use University Technology Resources for work-related communications.
Personal email or unapproved third-party services (for example, personal email or
chat services) may not be used for work-related communications unless explicitly authorized
by ITS.
- Personal Use of University Technology Resources. Users may be allowed incidental personal use of University Information Technology
Resources, including email, Internet, and assigned electronic devices; provided that
such use does not interfere with University operations, violate University or the
Kansas Board of Regents policies, generate incremental identifiable costs to the University,
and/or negatively impact the User’s job performance.
- Resource Integrity and Security. Users shall use University Technology Resources in a manner that maintains the integrity
of such resources, and where appropriate, the privacy, confidentiality, and/or security
of electronic information.
- Non-ITS Services. All University ITS and Information Security policies and procedures shall be followed
in the use and operation of University Technology Resources, including when such resources
or services are administered or provided by departments or organizations outside of
the University’s ITS department.
- Data Storage. Users shall follow all University requirements for storage of WSU Private, Restricted,
or Proprietary information/data (as defined or classified in Policy 19.18 / Third Party Data Transfers and Policy 19.20 / Data Sensitivity Classification), including credit card numbers, social security numbers, driver’s license or state
ID numbers, as determined by Information Security, Privacy, Registrar’s Office, or
other University designated data owner or custodian.
- Workspace Data Protection. Users shall maintain workspaces to ensure the protection of any information/data
that is defined or classified under Policy 19.18 / Third Party Data Transfers and Policy 19.20 / Data Sensitivity Classification as WSU Private, Restricted, or Proprietary, or any information deemed necessary to
protect by department Leadership. This includes not leaving such information/data
unattended or visible to others on desks, workspaces, or common areas, and securely
storing or disposing of such information/data when not in active use.
- Copyright Compliance. Users shall obtain permission to use or copy material that is owned by another in
accordance with Policy 3.36 / Copyright, including but not limited to, music, movies, software, documents, images, or multimedia
objects.
- Training. Users shall be required to complete all security and/or compliance training as assigned
by the University. Failure to complete training requirements may result in the loss
of the privilege of access to, and use of, University Technology Resources.
- Return Resources. Users shall return all University Technology Resources to ITS or the appropriate
designee when the User no longer has an authorized reason or need for access and use,
including job change or separation of employment, or as directed by ITS or Information
Security. When separating from employment with the University, all University provided
Information Technology Resources must be returned.
-
Prohibited Uses
- Sharing Access Privileges. Users shall not give out, loan, share, or otherwise allow anyone else to use the
access privileges for University Technology Resources that have been granted to them.
This includes, but is not limited to, sharing of passwords/authenticators or allowing
individuals to use University Technology Resources that they have not been granted
access to by Information Technology Services or the Information Security Department.
- Remote Access. Users shall not use remote access methods that have not been approved by University
ITS when accessing networks or systems owned or managed by the University.
- Security Safeguards. Users shall not attempt to circumvent security safeguards and/or login procedures
on any computer system, or otherwise attempt to gain unauthorized access to or degrade
security controls.
- Electronic Information. Users shall not intentionally seek, browse, provide, or modify information in electronic
files, or obtain copies of electronic files without authorization.
- Restricted Information. Users shall not remove or copy any WSU Private, Restricted, or Proprietary information/data
(as defined or classified in Policy 19.18 / Third Party Data Transfers and Policy 19.20 / Data Sensitivity Classification) from University Technology Resources with the intent to transfer or store it on
non-University owned or leased computing and information technology resources.
- Research. Users shall not utilize any University Technology Resources to compromise the integrity
of research or participate in any activities of misconduct in research as described
in Policy 9.13 / Misconduct in Research.
- Malware and Malicious Software. Users shall not in any way interfere with or intentionally develop or use programs
that compromise, or harm the performance, functionality, or integrity of University
Technology Resources. This includes removal of system safeguards or controls.
- Unauthorized Login. Users shall not represent themselves as someone else, by logging into and using another
individual’s University account.
- Degrading Performance and Productivity. Users shall not perform operations that degrade network performance for other Users.
Users shall not send spam or engage in other activities that infringe on the productivity
of other Users.
- Cloud-Based Software. Users shall not accept terms and conditions for any cloud-based software or application
which will house or transfer information defined or classified under Policy 19.18 / Third Party Data Transfers and Policy 19.20 / Data Sensitivity Classification as WSU Private, Restricted, or Proprietary data without review and approval from
the Data Management Committee or Subcommittee.
- Personal Information. Users shall not transfer or store any sensitive personal information/data about themselves
or others that is not related to their role or relationship with the University on
University Technology Resources. This includes, but is not limited to, information
about themselves or others, involving personal finances, taxes, health matters, or
other data that could subject the University to legal, financial, and/or compliance
risk should it become compromised.
- External Activities. Users shall not use University Technology Resources in external activities for commercial
purposes, personal financial gain, or solicitations. This prohibition includes cryptocurrency
mining. Additional information regarding conflicts, consulting, and outside employment
can be found in Policy 3.04 / Commitment of Time, Conflict of Interest, Consulting, and Other Employment.
- Misuse. Users shall not use University Technology Resources to send, upload, download, post,
transmit or store fraudulent, harassing, sexually explicit or pornographic materials
(unless reasonably related to a faculty member's research), child pornography (as
defined by state or federal law), profane, libelous, threatening, intimidating or
other unlawful messages. Exceptions to this may include use of University Technology
Resources by the University Police Department or Office of General Counsel for official
business.
-
Privacy, Monitoring, and Disclosure
- Users shall have no expectation of privacy in information stored or communicated using
University Technology Resources, including email.
- Communications and information stored or transferred using University Technology Resources
may be subject to disclosure through legal proceedings and/or may also be subject
to access and disclosure pursuant to the Kansas Open Records Act.
- Authorized University information technology and security personnel may have access
to User electronic files, email, and other data as necessary during repair or maintenance
activities, strictly adhering to their designated tasks and not for personal use.
- The University may monitor User data, including but not limited to, electronic files
and email, for legal, policy, compliance, and business purposes. Monitoring may include,
but is not limited to, circumstances in which:
- Information that the User has given permission to access or has voluntarily given
access to, such as posts to publicly accessible websites or systems and/or posts to
publicly accessible network services;
- Monitoring that is reasonably necessary to protect the integrity, security, or functionality
of the University's computing resources or to protect the University from liability;
- There is reason to believe the User has violated or is violating, this policy, other
University policies, or applicable legal or regulatory requirements;
- An account appears to be engaged in unusual activity detected during review of general
system activities, usage patterns, or as indicated by detective security mechanisms;
- Maintenance of the University’s computing resources are required, including, but not
limited to, backup and caching of data and communications, logging of activity, review
of patterns of User activity, scanning of systems and networks for anomalies and vulnerabilities;
or
- It is otherwise required or permitted by law, policy, or other legal authority.
- The University, in its discretion, or as required by law, judicial order, or regulatory
order, may disclose the results of any general or individual monitoring, including
the contents and records of individual communications, to authorized University personnel
and/or external parties as approved by the University, and may use those results in
University disciplinary proceedings.
-
Academic Freedom and Free Expression
- The University supports the rights of academic freedom and free expression of ideas
in the educational environment, and nothing in this policy is intended to contravene
such rights. This policy shall not be construed in a manner that would result in a
conflict with the First Amendment to the U.S. Constitution or any other relevant federal
or state laws or regulations concerning freedom of speech or expression. This policy
incorporates by reference the principles set forth in the KBOR Statement on Free Expression, and shall be construed in a manner consistent therewith, along with KBOR’s policy
on the Use of Campus Grounds and Facilities.
-
Compliance and Reporting
- Violations of this policy may lead to access restrictions, content removal, disciplinary
action, legal action, or other risk mitigating measures. For violations that constitute
a criminal offense, the University will carry any responsibility to report such violations
to the appropriate authorities.
- Any device, account or service determined by the University to lack required security
controls, software, or that otherwise poses a threat to University Technology Resources
may be immediately disconnected or disabled by the University from a University network
without notice.
- Any known or suspected unauthorized access, inability to access, loss/destruction,
or misuse/abuse of University Technology Resources shall be reported to the Information
Security Department via email at askinfosec@wichita.edu, or by phone at 316-978-4SEC (4732).
- Any known or suspected violations of this policy may be reported to:
-
Requests for Policy Deviations
- The University recognizes that there may be academic or research pursuits that require
deviations from the policies, standards, and procedures that apply to University Technology
Resources. Such deviations must go through the University’s formal risk-based approval
process, which requires sufficient justification and documented approval by the respective
divisional Vice President, or their designee, after consultation with the Chief Information
Officer and Chief Information Security Officer, including notification of the associated
risks. Requests for deviations may be submitted by email to Information Security at
askinfosec@wichita.edu.
-
Definitions
- For the purpose of this policy only, the following definitions shall apply:
- ITS: The University’s Information Technology Services department.
- Users: Any individual, organization, or company who uses and/or accesses University Information
Technology Resources.
- University: Wichita State University.
- University Information Technology Resources: All University owned, leased, or managed electronic or hardcopy data; information
assets; computing hardware and/or electronic equipment, including but not limited
to, general use computing devices, kiosk stations, instrument controllers, and mobile
devices; software, networks and systems, Internet access, data and modems provided
by or otherwise made available through WSU and located on campus sites or approved
remote sites which are used for the electronic transmission of information in telecommunications,
wireless transmissions, and for other business, educational, or research purposes.
-
Applicable Laws and Additional Resources
- KITEC Information Technology Policy 1200 Acceptable Internet Use
- KITEC Information Technology Policy 7230 Enterprise Security Policy
- KITEC Information Technology Standards & Guidelines 7230A IT Security Standards
- Kansas Board of Regents Policy Manual
- Kansas Board of Regents Statement on Free Expression
- WSU Policy 3.04 / Commitment of Time, Conflict of Interest, Consulting, and Other
Employment
- WSU Policy 3.05 / Social Media Use
- WSU Policy 3.17 / Political and Lobbying Activities by Employees
- WSU Policy 3.36 / Copyright
- WSU Policy 9.13 / Misconduct in Research
- WSU Policy 13.14 / Security of Payment Card Data
- WSU Policy 19.03 / Internet Statement
- WSU Policy 19.04 / University Web Sites
- WSU Policy 19.05 / University Information Technology Resources and Email
- WSU Policy 19.10 / Retirement of Computing and Technology Resources
- WSU Policy 19.13 / Utilization of University Network
- WSU Policy 19.18 / Third Party Data Transfers
- WSU Policy 19.19 / Prohibited Use of Tiktok and Other Bytedance Covered Applications
and Services
- WSU Policy 19.20 / Data Sensitivity Classification
- WSU Policy 20.01 / Kansas Open Records Act
- WSU Policy 20.17 / Protected Health Information
- WSU Policy 20.18 / Privacy of Financial Information
-
Revision Dates
- June 1, 2007
- November 18, 2008
- December 9, 2015
- June 17, 2016
- August 17, 2026