(1) This Policy outlines the standards of behaviour required for accessing the University’s IT Resources. (2) This Policy applies to all users of Macquarie University IT resources and connected systems. This includes: (3) Macquarie University (the University) is committed to maintaining a secure technology environment and as such, has established behavioural requirements for accessing the University’s IT Resources. Establishing these requirements aims to decrease the likelihood that IT Resources are misused. (4) All Users should provide confirmation that they have read and understood this Policy prior to commencement of work/study at the University. (5) Users provisioned with access to IT Resources should be aware of their responsibilities regarding appropriate care and protection. (6) Unauthorised individuals must not be given physical or logical access to IT Resources or Information. (7) The owner of a User account is solely responsible for all actions performed using their account. (8) IT Resources may be used for acceptable limited and reasonable personal use. Such personal use must be lawful, not negatively impact the University or violate this Policy. See the Acceptable Use of IT Resources - Misuse Schedule for examples of unacceptable use. (9) Users should consider the implications of storing and transmitting personal information not required by the University within IT Resources (e.g., personal events, security clearances, passports, files containing personal information, etc). The University is not responsible for protecting such Information. (10) Fixed IT Resources (e.g., monitors, routers) must not be taken off-site without prior written authorisation by the IT Service Desk or an authorised manager. (11) Information created, sent, received, or processed for the University’s business purposes that is not subject to the intellectual property rights of Users, is owned by the University. (12) Users have a responsibility to maintain vigilance and report any suspicious cyber security events occurring against the University, in accordance with this Policy and the Data Breach Policy. This includes: (13) University related cyber security events should be reported immediately to the IT Service Desk team or the IT Cyber Security team (cyber@mq.edu.au). Details of cyber security events should remain confidential and not be divulged or discussed with unauthorised individuals. (14) The University is not responsible for managing cyber security breaches for the personal emails, accounts or devices of Users. However, Users are encouraged to report incidents where there is a potential impact to University IT Resources. (15) IT Resources must: (16) Untrusted removable storage media (e.g., USB drives and external hard drives) should not be connected to IT Resources. (17) IT Resources should only be charged using trusted charging devices (e.g., charger, cables, power adapter). Public charging stations or USB ports (e.g. airports, restaurants, conference rooms) should not be used. (18) On the last day of employment or termination of a contract, staff and affiliates must return all University IT Resources and any associated accessories (e.g., keyboards, chargers, travel cases). (19) Students must return IT Resources when they are no longer required for study purposes. (20) Information should be generated, stored, processed and transmitted in accordance with the: (21) Personal email or cloud storage accounts should not be used to store, process or transmit University owned Information. (22) Information classified as Confidential or above (refer to the Information Classification and Handling Procedure) should be securely stored when not in use or when left unattended. (23) Information that is no longer required should be securely disposed of in accordance with the Records and Information Management Policy and approved retention schedules, using appropriate disposal methods for the information type, including secure digital deletion, system-based disposal, or media sanitation. (24) Whiteboards and other Information display sources should be cleaned of any Information classified Confidential or above, after use. (25) Home Wi-Fi should be password protected with the latest supported Wi-Fi security protocols, if used to connect to University IT Resources. (26) Staff must comply with travel requirements detailed in the Travel Policy. (27) Staff must complete cyber security awareness training as required by the University. (28) The University monitors all its IT Resources in accordance with the University’s Workplace Surveillance Policy. Breaches of this Policy constitute misuse of the University’s IT Resources. (29) The University may access, review, monitor, or disclose the contents of all messages created, sent or received using IT Resources. This may be performed for monitoring compliance with this Policy, terms and conditions of employment/engagement, and statutory obligations. (30) Users should assume that personal information transmitted by or stored on University IT Resources will be accessed by the University to the extent permitted by law. Any personal information managed by the University will be handled in accordance with the Privacy Policy and the Workplace Surveillance Policy. (31) The University may refer serious matters or repeated breaches to the Chief Information and Digital Officer, Chief People Officer, the Head of the relevant organisational unit, or the appropriate external authorities, which may result in disciplinary, civil and/or criminal proceedings. (32) The University has a statutory obligation to report unlawful activities, serious wrongdoing and corrupt conduct to appropriate authorities and will cooperate fully with the relevant authorities. (33) Users must not use IT Resources for, or in support of, illegal, obscene, or other inappropriate activities, in accordance with the Acceptable Use of IT Resources - Misuse Schedule. (34) Any exemption to this Policy must be sought from the Chief Information Security Officer (CISO). (35) Breaches of this Policy by staff and students will be managed in accordance with the applicable provisions of the Student Code of Conduct, Student Conduct Rule, Student Conduct Procedure, Staff Code of Conduct and other relevant policy instruments. (36) The University permits staff to access University Information and applications via their personal mobile devices. (37) To maintain the security of University Information, personal mobile devices used to access University Information and applications must: (38) If the above cannot be met personal mobile devices must not be used and either use of corporate laptop or corporate device is required in place. (39) The University is not responsible for any loss of personal data, delays, non-deliveries, service interruptions, technical difficulties, or malicious activity to a personal mobile device. (40) The University permits staff to access internet, email, social media and Artificial Intelligence (AI) for the following reasons: (41) Staff should: (42) University approved AI tools should be used in accordance with the Responsible and Ethical Use of Artificial Intelligence Policy. (43) University data must not be uploaded to non-university managed AI tools. (44) Social media should be used in accordance with the Social Media Policy. (45) Nil. (46) The following definitions apply for the purpose of this Policy: Acceptable Use of IT Resources Policy
Section 1 - Purpose
Scope
Background
Section 2 - Policy
Incident Notification
Protection of Physical IT Resources
Protection of Information
Remote Working and Travel
Cyber Security Training
Monitoring and Privacy
Prohibited Conduct
Compliance and Exemptions
Section 3 - Procedures
Use of Personal Mobile Devices
Internet, Email, Social Media and Artificial Intelligence (AI) Usage
Section 4 - Guidelines
Section 5 - Definitions
View Document
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.
Those listed above will be known as Users for the purpose of this Policy.