Appendix I

The City University of New York

Policy on Acceptable Use of Computer Resources

Introduction

CUNY’s computer resources are dedicated to the support of the universitys mission of education, research and public service. In furtherance of this mission, CUNY respects, upholds and endeavors to safeguard the principles of academic freedom, freedom of expression and freedom of inquiry.

CUNY recognizes that there is a concern among the university community that because information created, used, transmitted or stored in electronic form is by its nature susceptible to disclosure, invasion, loss, and similar risks, electronic communications and transactions will be particularly vulnerable to infringements of academic freedom. CUNY’s commitment to the principles of academic freedom and freedom of expression includes electronic information. Therefore, whenever possible, CUNY will resolve doubts about the need to access CUNY computer resources in favor of a user's privacy interest.

However, the use of CUNY computer resources, including for electronic transactions and communications, like the use of other university-provided resources and activities, is subject to the requirements of legal and ethical behavior. This policy is intended to support the free exchange of ideas among members of the CUNY community and between the CUNY community and other communities, while recognizing the responsibilities and limitations associated with such exchange.

Applicability

This policy applies to all users of CUNY computer resources, whether affiliated with CUNY or not, and whether accessing those resources on a CUNY campus or remotely.

This policy supersedes the CUNY policy titled “CUNY Computer User Responsibilities” and any college policies that are inconsistent with this policy.

Definitions

“CUNY Computer resources” refers to all computer and information technology hardware, software, data, access and other resources owned, operated, or contracted by CUNY. This includes, but is not limited to, personal computers, handheld devices, workstations, mainframes, minicomputers, servers, network facilities, databases, memory, and associated peripherals and software, and the applications they support, such as e-mail and access to the internet.

“E-mail” includes point-to-point messages, postings to newsgroups and listservs, and other electronic messages involving computers and computer networks.

Rules for Use of CUNY Computer Resources

1. Authorization. Users may not access a CUNY computer resource without authorization or use it for purposes beyond the scope of authorization. This includes attempting to circumvent CUNY computer resource system protection facilities by hacking, cracking or similar activities, accessing or using another person’s computer account, and allowing another person to access or use the user’s account. This provision shall not prevent a user from authorizing a colleague or clerical assistant to access information under the user’s account on the user’s behalf while away from a CUNY campus or because of a disability. CUNY computer resources may not be used to gain unauthorized access to another computer system within or outside of CUNY. Users are responsible for all actions performed from their computer account that they permitted or failed to prevent by taking ordinary security precautions.

2. Purpose. Use of CUNY computer resources is limited to activities relating to the performance by CUNY employees of their duties and responsibilities. For example, use of CUNY computer resources for private commercial or not-for-profit business purposes, for private advertising of products or services, or for any activity meant solely to foster personal gain, is prohibited. Similarly, use of CUNY computer resources for partisan political activity is also prohibited.

3. Compliance with Law. CUNY computer resources may not be used for any purpose or in any manner that violates CUNY rules, regulations or policies, or federal, state or local law. Users who engage in electronic communications with persons in other states or countries or on other systems or networks may also be subject to the laws of those other states and countries, and the rules and policies of those other systems and networks. Users are responsible for ascertaining, understanding, and complying with the laws, rules, policies, contracts, and licenses applicable to their particular use.

4. Licenses and Intellectual Property. Users of CUNY computer resources may use only legally obtained, licensed data or software and must comply with applicable licenses or other contracts, as well as copyright, trademark and other intellectual property laws.

5. False Identity and Harassment. Users of CUNY computer resources may not employ a false identity, mask the identity of an account or computer, or use computer resources to engage in abuse of others, such as sending harassing, obscene, threatening, abusive, deceptive, or anonymous messages within or outside CUNY.

6. Confidentiality. Users of CUNY computer resources may not invade the privacy of others by, among other things, viewing, copying, modifying or destroying data or programs belonging to or containing personal or confidential information about others, without explicit permission to do so. CUNY employees must take precautions to protect the confidentiality of personal or confidential information encountered in the performance of their duties or otherwise.

7. Integrity of Computer Resources. Users may not install, use or develop programs intended to infiltrate or damage a computer resource, or which could reasonably be expected to cause, directly or indirectly, excessive strain on any computing facility. This includes, but is not limited to, programs known as computer viruses, Trojan horses, and worms. Users should consult with the IT director at their college before installing any programs that they are not sure are safe.

8. Disruptive Activities. CUNY computer resources must not be used in a manner that could reasonably be expected to cause or does cause, directly or indirectly, unwarranted or unsolicited interference with the activity of other users. This provision explicitly prohibits chain letters, virus hoaxes or other intentional e-mail transmissions that disrupt normal e-mail service. Also prohibited are spamming, junk mail or other unsolicited mail that is not related to CUNY business and is sent without a reasonable expectation that the recipient would welcome receiving it, as well as the inclusion on e-mail lists of individuals who have not requested membership on the lists, other than the inclusion of members of the CUNY community on lists related to CUNY business. CUNY has the right to require users of CUNY computer resources to limit or refrain from other specific uses if, in the opinion of the IT director at the user’s college, such use interferes with efficient operations of the system, subject to appeal to the President or, in the case of central office staff, to the Chancellor.

9. CUNY Names and Trademarks. CUNY names, trademarks and logos belong to the university and are protected by law. Users of CUNY computer resources may not state or imply that they speak on behalf of CUNY or use a CUNY name, trademark or logo without authorization to do so. Affiliation with CUNY does not, by itself, imply authorization to speak on behalf of CUNY.

10. Security. CUNY employs various measures to protect the security of its computer resources and of users’ accounts. However, CUNY cannot guarantee such security. Users are responsible for engaging in safe computing practices such as guarding and not sharing their passwords, changing passwords regularly, logging out of systems at the end of use, and protecting private information, as well as for following CUNY’s Information Security policies and procedures. Users must report incidents of Information Security policy non-compliance or other security incidents to CUNY’s Chief Information Officer and Chief Information Security Officer, and the IT director at the affected user’s college.

11. Filtering. CUNY reserves the right to install spam, virus and spyware filters and similar devices if necessary in the judgment of CUNY’s Office of Information Technology or a college IT director to protect the security and integrity of CUNY computer resources. Notwithstanding the foregoing, CUNY will not install filters that restrict access to e-mail, instant messaging, chat rooms or websites based solely on content.

12. Confidential Research Information. Principal investigators and others who use CUNY computer resources to store or transmit research information that is required by law or regulation to be held confidential or for which a promise of confidentiality has been given, are responsible for taking steps to protect confidential research information from unauthorized access or modification. In general, this means storing the information on a computer that provides strong access controls (passwords) and encrypting files, documents, and messages for protection against inadvertent or unauthorized disclosure while in storage or in transit over data networks. Robust encryption is strongly recommended for information stored electronically on all computers, especially portable devices such as notebook computers, Personal Digital Assistants (PDAs), and portable data storage (e.g., memory sticks) that are vulnerable to theft or loss, as well as for information transmitted over public networks. Software and protocols used should be reviewed and approved by CUNYs Office of Information Technology.

13. CUNY Access to Computer Resources.

14. Enforcement. Violation of this policy may result in suspension or termination of an individuals right of access to CUNY computer resources, disciplinary action by appropriate CUNY authorities, referral to law enforcement authorities for criminal prosecution, or other legal action, including action to recover civil damages and penalties.

15. Additional Rules. Additional rules, policies, guidelines and/or restrictions may be in effect for specific computers, systems, or networks, or at specific computer facilities at the discretion of the directors of those facilities. Any such rules which potentially limit the privacy or confidentiality of electronic communications or information contained in or delivered by or over CUNY computer resources will be subject to the substantive and procedural safeguards provided by this policy.

16. Disclaimer. CUNY shall not be responsible for any damages, costs or other liabilities of any nature whatsoever with regard to the use of CUNY computer resources. This includes, but is not limited to, damages caused by unauthorized access to CUNY computer resources, data loss, or other damages resulting from delays, non-deliveries, or service interruptions, whether or not resulting from circumstances under the CUNYs control.

Last Updated: