The Information Technology Services (ITS) team is encouraging faculty, staff and students to review Brock’s information technology (IT) policies, which help protect the University’s IT assets and sensitive data.
Key IT policies that users should be aware of include the IT Acceptable Use Policy, End User Logical Access Policy and IT End User Communications and Encryption Policy.
The IT Acceptable Use Policy applies to faculty, staff and students when using Brock IT systems or services and when accessing, sharing or modifying Brock data. Key takeaways include that:
- Security must be prioritized at all times.
- Limited personal use of Brock IT resources is permitted if it doesn’t compromise performance or operations, incur any cost, damage the University’s reputation or involve activities inconsistent with its mission.
- Users are responsible for all activities conducted within their user account.
The End User Logical Access Policy applies to users when accessing systems that require authorization. Some of the main points of the policy include that:
- Brock’s technology and data must be protected against unauthorized access.
- Access to Brock systems is restricted to authorized users or processes.
- Access to Brock systems is based on the principle of least privilege, which means the least amount of access is granted to complete required tasks.
The IT End User Communications and Encryption Policy applies to faculty, staff and students when they are transmitting or transferring sensitive Brock data. Key elements of the policy include that:
- Sensitive data must be transmitted using secure methods such as encryption.
- Social media systems must never be used to transmit or post sensitive data without prior consent from the owner of the data or those responsible for the data.
- Data owners must understand who should have access to the data and if encryption is required.
- Data owners must engage with ITS to ensure proper encryption.
- Credit card data must never be stored in any system.
For more details about these key IT policies and other policies, visit brocku.ca/policies