Loading...
HomeMy WebLinkAboutResolution 7619RESOLUTION 7619 CITY OF MOUNDS VIEW COUNTY OF RAMSEY STATE OF MINNESOTA APPROVING THE COMPUTER TECHOLOGY USE AND ACCESS POLICIES WHEREAS, the City's current Computer Use Policy, dated July 20, 2000, is very outdated and does not address present day technologies; and WHEREAS, the purpose of having computer and technology policies is to assist in protecting the quality and integrity of the City's computer systems and to provide employees with standards of behavior when using the computer, email and the internet; and WHEREAS, the Metro-INET group developed a series of computer, password, Internet and email use policies; and WHEREAS, since the City is part of the Metro-INET group, Metro-INET is requesting that all agencies that utilize this shared network adopt the same policies. NOW, THEREFORE BE IT RESOLVED that the Mounds View City Council approves the attached Computer Technology Use and Access Policies in accordance with Metro-INET's policies. Adopted this 24th day of May, 2010. ~ , or ATTEST: d ~~ ~ James Ericson, City Administrator (seal) ~r Computer Technology Use and Access Policies Computer Use Policy Purpose To set provisions for securing desktop and notebook computers, related computer media and peripheral equipment. Backaround Most of City business is conducted with the use of desktop or notebook computers dedicated to a single user's activity. It is essential to protect City information assets created, gathered, shared or stored with desktop and notebook computers, related computer media (e.g. diskettes, CDROMs, Personal Digital Assistants (PDAs), flash drives, etc.) and peripheral equipment such as fax machines, printers and copiers. Scope of the Policv This policy applies to all individuals granted access to the City network and information systems including but not limited to full and part-time employees, temporary workers, volunteers, contractors, and those employed by others to perform City work. This policy includes all computers (e.g., desktops and notebooks), stand alones as well as those connected to the City network. The same physical and technical security measures shall be implemented for mobile and remote computers. Policy 1. General a. The City will ensure reasonable physical safeguards to maintain desktop and notebook computers and peripheral equipment in such a way to avoid inadvertent disclosure of City information. b. The City IT Department shall be responsible for secure installations, configurations, distribution, management and removal from service, of City desktop and notebook computers. c. The City may withdraw permission for any or all business or personal uses of its network or information systems at any time. 2. Securing Desktop and Notebook Computers a. When leaving a desktop or notebook computer unattended, users shall apply the "Lock Workstation" feature (ctrl/alt/delete, enter) where systems allow. b. Unattended desktop and notebook computers shall be secured from viewing by password protected screen savers which should be set to automatically activate after a period of non-use. The period of non-use shall be for no more than fifteen (15) minutes c. Desktop computer users shall store confidential and sensitive information on a networked drive (shared directory on the City network) and not the user's hard drive. d. Desktop and notebook computers and monitors shall be turned off at the end of each workday unless instructed otherwise by the IT Department to perform routine maintenance. e. Desktop and notebook computer users shall not disable or atter security safeguards, such as virus detection software, installed on City desktop or notebook computers. f. Additional security requirements may be required for computers containing data governed by other applicable State and Federal laws including law enforcement data and data associated with the Health Insurance Portability and Accountability Act (HIPPA). 3. Physical Security Measures Physical security measures shall be used to secure notebooks, computer media, and other forms of information storage media containing confidential or sensitive information. a. Mobile notebook computers actively connected to the network or information systems must not be left unattended. b. Notebook computers left in a vehicle shall not be visible except in police, utility department, code enforcement or fire emergency vehicles where the device is mounted to the vehicle console. If possible, the notebook should be stored in a locked trunk. (Weather conditions should be considered when leaving electronic equipment in a vehicle for long periods of time.) Unattended vehicles shall be locked at all times. c. Mobile notebook computers, computer media and any other forms of removable storage (e.g. diskettes, CD ROMs, zip disks, PDAs, flash drives) should be stored in a secure location, attached to the workstation by a locking cable or stored in a locked cabinet when not in use. d. Other information storage media containing confidential data such as paper, files, tapes, etc. shall be stored in a secure location or locked cabinet when not in use. 4. Peripheral Equipment Peripheral equipment (e.g, printers, faxes, copiers) that store, produce and/or transfer confidential or sensitive information shall be protected from inadvertent or unauthorized access. a. Fax and telex machines that store or transmit confidential or sensitive information shall be placed in secure locations and monitored. b. All documents containing confidential or sensitive information shall be cleared from printers and copiers immediately. 5. Unauthorized Software a. Individual users shall not install or download software applications and/or executable files to any City desktop or notebook computer without prior authorization from the IT Department. b. The IT shall make available to users, a list of authorized and accepted software and applications approved by the City. 6. Viruses a. Desktop and notebook computer users shall not write, compile, copy, knowingly propagate, execute, or attempt to introduce any computer code designed to self- replicate, damage, or otherwise hinder the performance of any computer system (e.g. virus, bacteria, worm, Trojan horse, or the like). b. Suspected viruses should be reported immediately to the IT Department. c. Viruses shall not be deleted without expert assistance unless instructed by the IT Department. 7. Monitoring of desktop and notebook computers. a. The City reserves the right to monitor individual user desktop and notebook computers at random or for cause. 8. Technical Security Desktop and notebook computers shall be configured to reduce the risk of inadvertent or unauthorized access to City information and systems. a. All City desktop and notebook computers shall be configured according to City desktop and notebook configuration standards. b. Without exception, a user's standard login account cannot be a member of the local machine administrator's group on the user's assigned desktop or notebook computer. c. User identification (name) and authentication (password) shall be required to access the operating system of all desktop and notebook computers whenever turned on or booted. d. Local hard drives shall not be accessible when a desktop or notebook computer is booted from mobile media, e.g., a diskette or compact disk. e. City standard virus detection software shall be installed on all desktop and notebook computers, mobile, and remote devices and shall be configured to check files when read and routinely scan the system for viruses. f. Desktop and notebook computers shall be configured to log all significant computer security relevant events. (e.g., password guessing, unauthorized access attempts or modifications to applications or systems software.) 4 9. Policy exceptions a. The IT Department Network policy exceptions regarding requests shall be submitted Manager. Manager shall be authorized to approve or deny elements of any security policy. Policy exception electronically or in hard copy form to the Network Failure to Complv Violations of this policy will be treated like other allegations of wrongdoing at the City. Allegations of misconduct will be adjudicated according to established procedures. Sanctions for inappropriate use of any City desktop computer, notebook computer or related computing device, software, or services may include, but are not limited to, one or more of the following: 1. Temporary or permanent revocation of use of computing equipment and network access; 2. Termination of employment; and/or 3. Legal action according to applicable laws and contractual agreements. Acceatance: Computer Use Policv I hereby acknowledge that I have read and understand the Computer Use Policy of the City. I agree to abide by these policies and ensure that persons working under my supervision abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary action according to applicable law or departmental policy. I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents harmless for any loss, damage, expense or liability resulting from any claim, action or demand arising out of or related to the user's use of the City owned computer resources and the network, including reasonable attorney fees. Such claims shall include, without limitation, those based on trademark or service mark infringement, trade name infringement, copyright infringement, unfair competition, defamation, unlawful discrimination or harassment, and invasion of privacy. Name Signature Date Password Policy Purpose To set a standard for creating, protecting, and changing passwords such that they are strong, secure, and protected. Backqround Passwords are a critical part of information and network security. Passwords serve to protect user accounts, but a password, if compromised, could put the entire network at risk of unauthorized access and loss of electronic data. As a result, all employees are required to take appropriate steps to ensure that they create strong, secure passwords and keep them safeguarded at all times. Scope of the Policv This policy applies to all employees, volunteers or contractors of the City who have or are responsible for a computer account, or any form of access that supports or requires a password, on any system that resides at any City facility, has access to the City network, or stores any non-public City information. Policv General 1. Passwords must be changed every 120 days. 2. Old passwords cannot be re-used for a period of 12 months. 3. Users will be notified by system prompts two weeks in advance of password expiration date. At this time, users will be prompted to select a new password. 4. All passwords must conform to strong password guidelines outlined below. Password Construction Guidelines Passwords are used to access any number of City information systems, including the network, database applications, email, and the Internet. Poorly designed passwords are easily cracked, and put the entire system at risk. Therefore, strong passwords are necessary to protect the integrity of the network and data. Try to create a password that is also easy to remember. 1. Passwords should not be based on well-known or easily accessible personal information. 2. Passwords must contain at least 8 characters. A strong password will contain a series of numbers, letters and special characters and would contain the following: • At least 1(one) uppercase letters (e.g. N) and 1(one) lowercase letters (e.g. t). • At least 1(one) numerical characters (e.g. 5). • At least 1(one) special characters (e.g. $). 3. Passwords must not be based on a users' personal information or that of his or her friends, family members, or pets. Personal information includes logon I.D., name, birthday, address, phone number, social security number, or any permutations thereof. 4. Passwords must not be words that can be found in a standard dictionary (English or foreign) or are publicly known slang or jargon. 5. Passwords must not be based on publicly known fictional characters from books, films, and so on. 6. Passwords must not be based on the company's name or geographic location. Password Protection Guidelines 1. Passwords should be treated as confidential information. No employee is to give, tell, or hint at their password to another person, including IT staff, administrators, superiors, other co-workers, friends, and family members, under any circumstances. 2. If someone demands your password, refer them to this policy or have them contact the IT Department. 3. Passwords are not to be transmitted electronically over the unprotected Internet, such as via e-mail. However, passwords may be used to gain remote access to company resources via the City's IPsec-secured Virtual Private Network or SSL-protected Web site. 4. No employee is to keep an unsecured written record of his or her passwords, either on paper or in an electronic file. If it proves necessarily to keep a record of a password, then it must be kept in a controlled access safe if in hardcopy form or in an encrypted file if in electronic form. 5. Do not use the "Remember Password" feature of applications. 6. Passwords used to gain access to City systems should not be used as passwords to access non-City accounts or information. 7. If possible, don't use the same password to access multiple databases or network systems. 8. If an employee either knows or suspects that their password has been compromised, it must be reported to the IT Department and the password changed immediately. 9. The IT Department may attempt to crack or guess users' passwords as part of its ongoing security vulnerability auditing process. If a password is cracked or guessed during one of these audits, the user will be required to change his or her password immediately. Failure to Complv Violations of this policy will be treated like other allegations of wrongdoing at the City. Allegations of misconduct will be adjudicated according to established procedures. Sanctions for 7 inappropriate use on the City's email systems and services may include, but are not limited to, one or more of the following: 1. Temporary or permanent revocation of network access; 2. Termination of employment; and/or 3. Legal action according to applicable laws and contractual agreements. Acceatance: Password Polic I hereby acknowledge that I have read and understand the Password Policy of the City. I agree to abide by these policies and ensure that persons working under my supervision abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary action according to applicable law or departmental policy. I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents harmless for any loss, damage, expense or liability resulting from any claim, action or demand arising out of or related to the user's use of the City owned computer resources and the network, including reasonable attorney fees. Such claims shall include, without limitation, those based on trademark or service mark infringement, trade name infringement, copyright infringement, unfair competition, defamation, unlawful discrimination or harassment, and invasion of privacy. Name Signature Date Email Acceptable Use Policy (EAUP) Purpose To establish an outline of appropriate and inappropriate use of the City's email system and services in order to minimize disruptions to services and activities, as well as comply with applicable policies and laws. Backqround Email is a critical mechanism for business communications. However, the improper use of electronic mail systems and services can compromise the security of the network or result in unnecessary legal liability. As a result, the provision of email to an employee is a privilege, not a right, and therefore must be used with respect and in accordance with the goals and policies of the City Scope of the Policv The City provides some, if not all, employees with electronic access, consisting of an email system, a network connection, and InterneUlntranet access. This policy governs the use of the City's network and email system at all City locations and offices. The following are covered by this policy: 1. Full or part-time employees of the City who have been provided a city email address. 2. Volunteers who are authorized to use the City email system and have been provided a city email address. Policv Email access is controlled through individual accounts and passwords. Each user of the City's email system is required to read and sign a copy of this Email Acceptable Use Policy prior to receiving an email access account and password. It is the responsibility of the employee to protect the confidentiality of their account and password information. All full-time employees of the City of Mounds View are entitled to an email account. Temporary email accounts will be granted to third party non-employees on a case-by-case basis. Applications for these temporary accounts must be submitted in writing to the Network Manager. All terms, conditions, and restrictions governing email use must be in a written and signed agreement. Email access will be terminated when the employee or third party terminates their association with the City, unless other arrangements are made. The City is under no obligation to store or forward the contents of an individual's email inbox/outbox after the term of their employment has ceased. General Expectations of End Users Important official communications are often delivered via email. As a result, employees of the City with email accounts are expected to check their email in a consistent and timely manner so that they are aware of important City announcements and updates, as well as for fulfilling business and assigned tasks. Email users are responsible for mailbox management, including organization and cleaning. If a user subscribes to a mailing list, he or she must be aware of how to remove their email address from the list, and is responsible for doing so in the event that their current email address changes. Email users are also expected to comply with normal standards of professional and personal courtesy and conduct. Appropriate Use Individuals at the City are encouraged to use email to further the goals and objectives of the City. The types of activities that are encouraged include: Communicating with fellow employees, business partners of the City, and clients within the context of an individual's assigned responsibilities. 2. Participating in educational or professional development activities. Inappropriate Use The City's email systems and services are not to be used for purposes that could be reasonably expected to cause excessive strain on systems. Individual email use will not interfere with others' use of the City's email system and services. Email use at the City will comply with all applicable laws, all the City policies, and all City contracts. The following activities are deemed inappropriate uses of the City systems and services and are prohibited: 1. Use of email in any way that violates the City's policies, rules, or administrative orders. 2. Viewing, copying, altering, or deletion of email accounts or files belonging to the City or another individual without authorized permission. 3. Sending of unreasonably large email attachments. The total size of an individual email message sent or received (including attachment) must be 100Mb or less. 4. Opening email attachments from unknown or unsigned sources. Attachments are the primary source of computer viruses and should be treated with utmost caution. 5. Sharing email account passwords with another person, or attempting to obtain another person's email account password. Email accounts are only to be used by the registered user. 6. Excessive personal use of the City email resources. The City allows limited personal use for communication with family and friends, independent learning, and public service so long as it does not interfere with staff productivity, pre-empt any business activity, or consume more than a trivial amount of resources. The City prohibits personal use of its email systems and services for unsolicited mass mailings, non-City commercial activity, political campaigning, dissemination of chain letters, and use by non-employees. Email Retention - Please refer to the Email Archiving and Retention Policy 10 Reporting Misuse Any allegations of misuse should be promptly reported to Network Manager. If you receive an offensive email, do not forward, delete, or reply to the message. Instead, report it directly to the individual named above. Failure to Complv Violations of this policy will be treated like other allegations of wrongdoing at the City. Allegations of misconduct will be adjudicated according to established procedures. Sanctions for inappropriate use on the City's email systems and services may include, but are not limited to, one or more of the following: 1. Temporary or permanent revocation of email access; 2. Disciplinary action according to applicable the City policies; 3. Termination of employment; and/or 4. Legal action according to applicable laws and contractual agreements. Monitoring and Confidentiality The email systems and services used at the City are the property of the City. As such, the City has the right to monitor any and all email traffic passing through its email system. While the City does not actively read end-user email, email messages may be read by IT staff during the normal course of managing the email system. In addition, backup copies of email messages may exist, despite end-user deletion, in compliance with the City's records retention policy. The goals of these backup and archiving procedures are to ensure system reliability and prevent business data loss. If the City discovers or has good reason to suspect activities that do not comply with applicable laws or this policy, email records may be retrieved and used to document the activity in accordance with due process. All reasonable efforts will be made to notify an employee if his or her email records are to be reviewed. Notification may not be possible, however, if the employee cannot be contacted, as in the case of employee absence due to vacation. Use extreme caution when communicating confidential or sensitive information via email. Keep in mind that all email messages sent outside of the City become the property of the receiver. A good rule is to not communicate anything that you wouldn't feel comfortable being made public. Demonstrate particular care when using the "Reply" command during email correspondence. Disclaimer The City assumes no liability for direct and/or indirect damages arising from the user's use of the City's email system and services. Users are solely responsible for the content they disseminate. The City is not responsible for any third-party claim, demand, or damage arising out of use the City's email systems or services. Acceatance: Email Acceatable Use Policv (EUAP) I hereby acknowledge that I have read and understand the Email Acceptable Use Policy of the City. I agree to abide by these policies and ensure that persons working under my supervision 11 abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary action according to applicable law or departmental policy. I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents harmless for any loss, damage, expense or liability resulting from any claim, action or demand arising out of or related to the user's use of the City owned computer resources and the network, including reasonable attorney fees. Such claims shall include, without limitation, those based on trademark or service mark infringement, trade name infringement, copyright infringement, unfair competition, defamation, unlawful discrimination or harassment, and invasion of privacy. Name Signature Date 12 Internet Acceptable Use Policy (IAUP) Purpose To establish a policy to ensure efficient, ethical, and legal use of Internet resources. Backpround The Internet is a worldwide, publicly accessible network of interconnected computer networks that transmit data by packet switching using the standard Internet Protocol (IP). It is a"network of networks" that consists of millions of smaller domestic, academic, business, and government networks, which together carry various information and services, such as electronic mail, online chat, file transfer, and the interlinked Web pages and other documents of the World Wide Web. Access to the Internet provides employees with the opportunity to locate and use current and historical data from multiple sources worldwide in their decision-making processes. Employees are encouraged to develop the skills necessary to effectively utilize these tools in the performance of their jobs. Scope of the Policv The following are covered by this policy: 1. Full or part-time employees of the City. 2. Volunteers who are authorized to use City resources to access the Internet. 3. Contractors who are authorized to use City-owned equipment or facilities to access the Internet. Policv Internet access at the City is controlled through individual accounts and passwords. Department managers are responsible for defining appropriate Internet access levels for the persons in their department and conveying that information to the Network Manager. Each user of the City system is required to read this Internet policy and sign an Internet use agreement prior to receiving an Internet access account and password. Appropriate Use Individuals at the City are encouraged to use the Internet to further the goals and objectives of the City. The types of activities that are encouraged include: 1. Acquiring or sharing information necessary or related to the performance of an individual's assigned responsibilities; 2. Participating in educational or professional development activities. Inappropriate Use Individual Internet use will not interfere with others' use and enjoyment of the Internet. Users will not violate the network policies of any network accessed through their account. Internet use 13 at the City will comply with all Federal and State laws, all City policies, and all the City contracts. This includes, but is not limited to, the following: 1. The Internet may not be used in any way that violates the City's policies, rules, or administrative orders including, but not limited to, the City's employee code of conduct policies. Use of the Internet in a manner that is not consistent with the mission of the City, misrepresents the City, or violates any the City policy is prohibited. 2. Individuals should limit their personal use of the Internet. The City allows limited personal use for communication with family and friends, independent learning, and public service. The City prohibits use for mass unsolicited mailings, access for non- employees to the City resources or network facilities, competitive commercial activity unless pre-approved by the City, and the dissemination of chain letters. Security For security purposes, users may not share account or password information with another person. Internet accounts are to be used only by the assigned user of the account for authorized purposes. Attempting to obtain another user's account password is strictly prohibited. Users are required to change or obtain a new password if they have reason to believe that any unauthorized person has learned their password. Users are required to take all necessary precautions to prevent unauthorized access to Internet services. Monitoring The City may monitor any Internet activity occurring on the City equipment or accounts. If the City discovers activities which do not comply with applicable law or departmental policy, records retrieved may be used to document the violation of this policy statement. Website Blocking and Filtering The City currently does employ filtering software to limit access to sites on the Internet. Restricted sites typically contain adult or pornographic material. To preserve Internet bandwidth websites that use an inordinate amount of bandwidth will be filtered. These sites typically contain streaming video and audio but also includes sites that contain large file downloads. Exceptions to the filtering policy can be submitted to the Network Manager for review. Failure to Complv Violations of this policy will be treated like other allegations of wrongdoing at the City. Allegations of misconduct will be adjudicated according to established procedures. Sanctions for inappropriate use of the Internet may include, but are not limited to, one or more of the following: 1. Temporary or permanent revocation of access to the Internet. 2. Disciplinary action according to applicable the City policies; 3. Legal action according to applicable laws and contractual agreements; Disclaimer The City assumes no liability for any direct or indirect damages arising from the user's connection to the Internet. The City is not responsible for the accuracy of information found on the Internet and only facilitates the accessing and dissemination of information through its systems. Users are solely responsible for any material that they access and disseminate through the Internet. 14 We encourage you to use your Internet access responsibly. Should you have any questions regarding this Internet Acceptable Use Policy, feel free to contact the Network Manager at 651- 792-7092. Acceptance: Internet Acceptable Use Policy (IUAP) I hereby acknowledge that I have read and understand the Internet Acceptable Use Policy of the City. I agree to abide by these policies and ensure that persons working under my supervision abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary action according to applicable law or departmental policy. I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents harmless for any loss, damage, expense or liability resulting from any claim, action or demand arising out of or related to the user's use of the City owned computer resources and the network, including reasonable attorney fees. Such claims shall include, without limitation, those based on trademark or service mark infringement, trade name infringement, copyright infringement, unfair competition, defamation, unlawful discrimination or harassment, and invasion of privacy. Name Signature Date 15