Bowling Green state university provides information technology resources to support the academic, administrative, educational, research and service missions of its appropriately affiliated members within the margins of institutional priorities and financial capabilities. The information technology resources provide for the university, a conduit for free and open forum for the expression of ideas mindful of the university core values. In order to protect the confidentiality, integrity, and availability of information technology resources for intended purposes, the following policy has been developed.
The scope of this policy is to encompass all information technology devices owned by the university, any device connected to the university network, and all university data on these devices.
Ability to access information technology resources does not, by itself, imply authorization to do so. Prior to accessing a resource, users are responsible for ascertaining and properly obtaining necessary authorization. Accounts, passwords, and other authentication mechanisms, may not, under any circumstances, be shared with, or used by, persons other than those to whom they have been assigned by the university.
BGSU employs various technologies and procedures in the interest of protecting the confidentiality, availability, and integrity of information technology. Some examples of these technologies and procedures, include, but are not limited to, physical methods, firewalls, anti-virus software, encryption, and passwords. Circumvention or attempted circumvention of a security system creates a threat to the university and is not permitted.
All members of the BGSU community share the information technology resources provided by BGSU. Those causing disruption to the use of information technology resources for other community members will be in violation of this policy. Some examples include, but are not limited to, configuration of devices that disrupt network services, launching denial of service attacks, and disturbing public access resources.
In an effort to protect the confidentiality, availability, and integrity of information technology resources, BGSU officials will investigate any discovered unauthorized network reconnaissance, vulnerability scanning, or service enumerations. While it is recognized that there are some valid purposes for this activity, BGSU officials are unable to determine intent and must react in a manner that will best protect information technology resources by assuming that the source of scans are malicious. Additionally, many vulnerability scanning tools utilize techniques that may be disruptive if not properly used. Please contact the ITS information security office for authorization to conduct vulnerability or service assessments using BGSU information technology resources.
This responsibility includes practicing safe computing at all times when deploying or using BGSU information technology resources. Users are to care for the integrity of technology based information sources they are authorized to access and to ensure that information is shared only with other appropriately authorized users.
Examples of this include, but are not limited to, forging email or using any Internet service not affiliated with the university that can prevent accountability for its usage.
Information technology services (ITS) has implemented wireless local area network (LAN) services on the BGSU main campus and the Firelands campus. While this service allows mobility and easier access to the BGSU network, it means that the air space on campus now serves as a medium for network connectivity. The use of open air space poses a number of potentially difficult situations for both users and network administrators. Users who may need to make use of wireless equipment for special purposes such as research or other unique applications must contact ITS to coordinate this use of wireless air space.
Effective July 1, 2024, access to the BGSU network will transition to a "wireless-first" approach. As of this transition date, all technology equipment purchases must support wireless networking (Wi-Fi). Exceptions to this policy include devices which require "Power over Ethernet" (PoE), security cameras, door access systems, IP phones, certain building automation equipment and life safety devices. Additional exceptions to this policy may be evaluated on an individual case basis and must be submitted as an ITS (information technology services) ticket. To further support this wireless-first initiative, future building construction or renovations will have one network wired port per office or single occupancy space.
BGSU respects the privacy of all information technology users. The university does not routinely monitor the content of material but does reserve the right to access and review all aspects of its information technology infrastructure to investigate performance or system problems, search for harmful programs, or upon reasonable cause, to determine if a user is violating a university policyor state or federal law. BGSU monitors, keeps, and audits detailed records of information technology usage; traces may be recorded routinely for trouble shooting, performance monitoring, security purposes, auditing, recovery from system failure, etc.; or in response to a complaint, in order to protect the university's and others' equipment, software, and data from unauthorized use or tampering. Extraordinary record keeping, traces and special techniques may be used in response to technical problems or complaints, or for violation of law, university policy or regulations, but only on approval by university administrators specifically authorized to give such approval. In addition to the privacy of individuals being respected under normal circumstances, the privacy of those involved in a complaint will be respected and the university will limit special record keeping in order to do so, where practicable. Information will be released in accordance with law. Users should be aware that while the university implements various security controls to protect information technology resources, protection of data from unauthorized individuals cannot be guaranteed.
Individuals or entities in violation of the BGSU information technology policy will be referred to the appropriate disciplinary authority for review. Access privileges may be suspended without prior notice if it is determined that a policy violation is causing a current or imminent threat to the confidentiality, integrity, or availability of information technology resources.
A violation of this policy may result in disciplinary action, up to and including termination of employment.
This policy is authorized by the office of the chief information officer (CIO) and has been approved by the appropriate university committee(s). This policy may be supplemented with additional published guidelines by campus units that are authorized to operate/control their own information technology resources provided such guidelines are consistent with and supplemental to this policy and do not alter its intent.
Ohio Admin. Code 3341-6-07
Promulgated Under: 111.15
Statutory Authority: 3341
Rule Amplifies: 3341
Prior Effective Dates: 03/17/2015, 03/31/2016, 12/22/2017