IQAC: IT Security Policy for College Staff (Teaching and Non-Teaching) And Students
Purpose
The purpose of this policy is to set terms and conditions, as well as standards and guidelines, for the acceptable uses of the IT services and assets provide to the college staff, contractors and visiting faculty. DES expects college staff, contractors and visiting faculty to become familiar with individual and institutional responsibilities to protect its electronic information.Scope
This policy applies to all the users In the College, including temporary users, visitors with temporary access to services and partners with limited or unlimited access time to services.IT Assets
- Employees should handle all the IT assets of DES properly and in a secure manner. This applies to desktops, laptops, printers and other equipment, applications and software, to anyone using those assets.
- Active desktop and laptops must be secured if left unattended.
- Access to assets is forbidden for un-authorized personnel. Granting access to the assets involved in the provision of a service must be done through the approved Service Request Management and Access Management processes.
- Users shall maintain the assets assigned to them in a responsible manner and not cause any damage to them.
- The IT Technical Teams are responsible for maintaining and upgrading configurations. None other users are authorized to change or upgrade the configuration ofthe IT assets. That includes modifying hardware or installing software.
- Special care must be taken for protecting laptops and other portable assets from being stolen. Employees must be aware of extreme temperatures, magnetic fields and use of such devices in wet laboratories should be avoided.
- Whenever possible, encryption technologies should be implemented in portable assets. 8. Assets (Laptops, desktops) storing sensitive Information such as examination question papers must be password protected and it would be the responsibility of Teacher-InCharges and Heads of the Department/Post Graduate programme Coordinators. The device also in turn should be password protected and should be left unattended.
- Henceforth, email addresses issued by the organization shall be used for all official communication within the College and outside College for educational and research purposes only. (Use fergusson.edu and despune.org email IDs only).
- All the assigned email addresses, mailbox storage and transfer links must be used only for business purposes in the interest of the College and DES.
- Use of the College and DES resources for unauthorized advertising, external business, spam, political campaigns, and other uses unrelated to the College and DES business is strictly forbidden.
- In no way may the email resources be used to reveal confidential or sensitive information from the outside College and DES. In unavoidable circumstances, confidential data information has to be encrypted or password protected before being sent.
- Using the email resources of the College and DES for disseminating messages regarded as offensive, racist, obscene or in any way contrary to the law and ethics is absolutely discouraged.
- Outbound messages from all users should have appropriate signatures at the foot of the message.
- Scanning technologies for virus and malware must be In place in client PCs and servers to ensure the maximum protection in the ingoing and outgoing email.
ERP system
- ERP system can be accessed from mobile and PC. Employees will not share login Id or password with anyone.
- The email Id and the contact details provided as input to the ERP system have to be up to date.
- Teachers should avoid using the ERP system from any cyber café. In case of unavoidable circumstances, after ERP system is accessed from any cyber café, cache and local copies of any documents should be cleared.
CCTV
- The College campus is monitored by CCTV for stakeholder security. None shall tamper it in any way.
Policy
This IT Security Policy covers the following:
- IT Assets
- Password Control
- Internet and Wi-fi
- Antivirus
- Inventory
- ERP System
- CCTV
- Data Backup
Password control
- All laptops and desktops must be protected with a strong password-based access control system.
- Every user (teacher) must have a separate, private identity for accessing IT network services.
- Each identity must have a strong, private, alphanumeric password to be able to access any service. They should be as least 8 characters long.
- Password should be changed after every 90 days.
- Sharing of passwords is forbidden. They should not be revealed or exposed to public sight.
- Writing down passwords on notepads or on sticky notes and storing it in personal mobile devices is forbidden.
- Whenever a password is deemed compromised, it must be changed immediately.
- Devices which are used in the laboratory should be password protected and for Access points in the laboratories, teachers should login through the firewall, if internet is being used and should log out, once the use is over. This is specifically for using multiple devices in laboratories for teaching.
Internet and Wi-fi
- Access to pornographic sites, hacking sites, and other risky sites is strictly forbidden and will be dealt as per existing IT laws.
- Internet access is mainly for business purpose.
- All internet traffic is guarded by firewall. The employees in no way shall tamper the firewall. Every teacher will be provided with single login and this should be protected again with a strong password of 8 characters.
- Attacks like denial of service, spam, phishing, fraud, hacking, distribution of questionable material, infraction of copyrights and others are strictly forbidden.
- Use of social sites in the college campus by using college internet is strictly prohibited. Social media platforms created only for promotion ofcollege activities will be allowed to access through college internet.
- Copyright Infringement-Any download using the service that will infringe a copyright of a material, audio, video or document is totally prohibited and will be subject to disciplinary action depending on the number of offenses
Data Backup
Data Backup is the responsibility of each user and back up has to be taken on College/DES approved shared locations. If backup is taken on pen drive or hard disc, it should be encrypted.
Antivirus
All windows computers and devices with access to the College and DES network must have an antivirus client installed, with real-time protection, Devices which store important college information and data will be protected by the antivirus for which there is separate budgetary provision.
Inventory
- All items of equipment to be brought under control shall be identified by a serial number affixed to each item.
- Equipment control records shall be maintained for each item of equipment identified by a serial number and an appropriate stock registration number and should be duly entered in the College Asset Register.
- Periodic physical inventories, at least once annually, shall be taken of all items of equipment placed under serial number control.