HomeMy WebLinkAboutResolution 7619RESOLUTION 7619
CITY OF MOUNDS VIEW
COUNTY OF RAMSEY
STATE OF MINNESOTA
APPROVING THE COMPUTER TECHOLOGY USE AND ACCESS POLICIES
WHEREAS, the City's current Computer Use Policy, dated July 20, 2000, is very
outdated and does not address present day technologies; and
WHEREAS, the purpose of having computer and technology policies is to assist in
protecting the quality and integrity of the City's computer systems and to provide
employees with standards of behavior when using the computer, email and the internet;
and
WHEREAS, the Metro-INET group developed a series of computer, password,
Internet and email use policies; and
WHEREAS, since the City is part of the Metro-INET group, Metro-INET is requesting
that all agencies that utilize this shared network adopt the same policies.
NOW, THEREFORE BE IT RESOLVED that the Mounds View City Council
approves the attached Computer Technology Use and Access Policies in accordance with
Metro-INET's policies.
Adopted this 24th day of May, 2010.
~
, or
ATTEST:
d
~~ ~
James Ericson, City Administrator
(seal)
~r
Computer Technology Use and Access Policies
Computer Use Policy
Purpose
To set provisions for securing desktop and notebook computers, related computer media and
peripheral equipment.
Backaround
Most of City business is conducted with the use of desktop or notebook computers dedicated to
a single user's activity. It is essential to protect City information assets created, gathered,
shared or stored with desktop and notebook computers, related computer media (e.g. diskettes,
CDROMs, Personal Digital Assistants (PDAs), flash drives, etc.) and peripheral equipment such
as fax machines, printers and copiers.
Scope of the Policv
This policy applies to all individuals granted access to the City network and information systems
including but not limited to full and part-time employees, temporary workers, volunteers,
contractors, and those employed by others to perform City work.
This policy includes all computers (e.g., desktops and notebooks), stand alones as well as those
connected to the City network.
The same physical and technical security measures shall be implemented for mobile and
remote computers.
Policy
1. General
a. The City will ensure reasonable physical safeguards to maintain desktop and
notebook computers and peripheral equipment in such a way to avoid
inadvertent disclosure of City information.
b. The City IT Department shall be responsible for secure installations,
configurations, distribution, management and removal from service, of City
desktop and notebook computers.
c. The City may withdraw permission for any or all business or personal uses of
its network or information systems at any time.
2. Securing Desktop and Notebook Computers
a. When leaving a desktop or notebook computer unattended, users shall apply the
"Lock Workstation" feature (ctrl/alt/delete, enter) where systems allow.
b. Unattended desktop and notebook computers shall be secured from viewing by
password protected screen savers which should be set to automatically activate
after a period of non-use. The period of non-use shall be for no more than fifteen
(15) minutes
c. Desktop computer users shall store confidential and sensitive information on a
networked drive (shared directory on the City network) and not the user's hard
drive.
d. Desktop and notebook computers and monitors shall be turned off at the end of
each workday unless instructed otherwise by the IT Department to perform
routine maintenance.
e. Desktop and notebook computer users shall not disable or atter security
safeguards, such as virus detection software, installed on City desktop or
notebook computers.
f. Additional security requirements may be required for computers containing data
governed by other applicable State and Federal laws including law enforcement
data and data associated with the Health Insurance Portability and Accountability
Act (HIPPA).
3. Physical Security Measures
Physical security measures shall be used to secure notebooks, computer media, and
other forms of information storage media containing confidential or sensitive information.
a. Mobile notebook computers actively connected to the network or information
systems must not be left unattended.
b. Notebook computers left in a vehicle shall not be visible except in police, utility
department, code enforcement or fire emergency vehicles where the device is
mounted to the vehicle console. If possible, the notebook should be stored in a
locked trunk. (Weather conditions should be considered when leaving electronic
equipment in a vehicle for long periods of time.) Unattended vehicles shall be
locked at all times.
c. Mobile notebook computers, computer media and any other forms of removable
storage (e.g. diskettes, CD ROMs, zip disks, PDAs, flash drives) should be
stored in a secure location, attached to the workstation by a locking cable or
stored in a locked cabinet when not in use.
d. Other information storage media containing confidential data such as paper, files,
tapes, etc. shall be stored in a secure location or locked cabinet when not in use.
4. Peripheral Equipment
Peripheral equipment (e.g, printers, faxes, copiers) that store, produce and/or transfer
confidential or sensitive information shall be protected from inadvertent or unauthorized
access.
a. Fax and telex machines that store or transmit confidential or sensitive information
shall be placed in secure locations and monitored.
b. All documents containing confidential or sensitive information shall be cleared
from printers and copiers immediately.
5. Unauthorized Software
a. Individual users shall not install or download software applications and/or
executable files to any City desktop or notebook computer without prior
authorization from the IT Department.
b. The IT shall make available to users, a list of authorized and accepted software
and applications approved by the City.
6. Viruses
a. Desktop and notebook computer users shall not write, compile, copy, knowingly
propagate, execute, or attempt to introduce any computer code designed to self-
replicate, damage, or otherwise hinder the performance of any computer system
(e.g. virus, bacteria, worm, Trojan horse, or the like).
b. Suspected viruses should be reported immediately to the IT Department.
c. Viruses shall not be deleted without expert assistance unless instructed by the IT
Department.
7. Monitoring of desktop and notebook computers.
a. The City reserves the right to monitor individual user desktop and notebook
computers at random or for cause.
8. Technical Security
Desktop and notebook computers shall be configured to reduce the risk of inadvertent or
unauthorized access to City information and systems.
a. All City desktop and notebook computers shall be configured according to City
desktop and notebook configuration standards.
b. Without exception, a user's standard login account cannot be a member of the
local machine administrator's group on the user's assigned desktop or notebook
computer.
c. User identification (name) and authentication (password) shall be required to
access the operating system of all desktop and notebook computers whenever
turned on or booted.
d. Local hard drives shall not be accessible when a desktop or notebook computer
is booted from mobile media, e.g., a diskette or compact disk.
e. City standard virus detection software shall be installed on all desktop and
notebook computers, mobile, and remote devices and shall be configured to
check files when read and routinely scan the system for viruses.
f. Desktop and notebook computers shall be configured to log all significant
computer security relevant events. (e.g., password guessing, unauthorized
access attempts or modifications to applications or systems software.)
4
9. Policy exceptions
a. The IT Department Network
policy exceptions regarding
requests shall be submitted
Manager.
Manager shall be authorized to approve or deny
elements of any security policy. Policy exception
electronically or in hard copy form to the Network
Failure to Complv
Violations of this policy will be treated like other allegations of wrongdoing at the City.
Allegations of misconduct will be adjudicated according to established procedures. Sanctions for
inappropriate use of any City desktop computer, notebook computer or related computing
device, software, or services may include, but are not limited to, one or more of the following:
1. Temporary or permanent revocation of use of computing equipment and network
access;
2. Termination of employment; and/or
3. Legal action according to applicable laws and contractual agreements.
Acceatance: Computer Use Policv
I hereby acknowledge that I have read and understand the Computer Use Policy of the City. I
agree to abide by these policies and ensure that persons working under my supervision abide
by these policies. I understand that if I violate such rules, I may face legal or disciplinary action
according to applicable law or departmental policy.
I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents
harmless for any loss, damage, expense or liability resulting from any claim, action or demand
arising out of or related to the user's use of the City owned computer resources and the
network, including reasonable attorney fees. Such claims shall include, without limitation, those
based on trademark or service mark infringement, trade name infringement, copyright
infringement, unfair competition, defamation, unlawful discrimination or harassment, and
invasion of privacy.
Name
Signature
Date
Password Policy
Purpose
To set a standard for creating, protecting, and changing passwords such that they are strong,
secure, and protected.
Backqround
Passwords are a critical part of information and network security. Passwords serve to protect
user accounts, but a password, if compromised, could put the entire network at risk of
unauthorized access and loss of electronic data. As a result, all employees are required to take
appropriate steps to ensure that they create strong, secure passwords and keep them
safeguarded at all times.
Scope of the Policv
This policy applies to all employees, volunteers or contractors of the City who have or are
responsible for a computer account, or any form of access that supports or requires a password,
on any system that resides at any City facility, has access to the City network, or stores any
non-public City information.
Policv
General
1. Passwords must be changed every 120 days.
2. Old passwords cannot be re-used for a period of 12 months.
3. Users will be notified by system prompts two weeks in advance of password expiration
date. At this time, users will be prompted to select a new password.
4. All passwords must conform to strong password guidelines outlined below.
Password Construction Guidelines
Passwords are used to access any number of City information systems, including the network,
database applications, email, and the Internet. Poorly designed passwords are easily cracked,
and put the entire system at risk. Therefore, strong passwords are necessary to protect the
integrity of the network and data. Try to create a password that is also easy to remember.
1. Passwords should not be based on well-known or easily accessible personal
information.
2. Passwords must contain at least 8 characters. A strong password will contain a series of
numbers, letters and special characters and would contain the following:
• At least 1(one) uppercase letters (e.g. N) and 1(one) lowercase letters (e.g. t).
• At least 1(one) numerical characters (e.g. 5).
• At least 1(one) special characters (e.g. $).
3. Passwords must not be based on a users' personal information or that of his or her
friends, family members, or pets. Personal information includes logon I.D., name,
birthday, address, phone number, social security number, or any permutations thereof.
4. Passwords must not be words that can be found in a standard dictionary (English or
foreign) or are publicly known slang or jargon.
5. Passwords must not be based on publicly known fictional characters from books, films,
and so on.
6. Passwords must not be based on the company's name or geographic location.
Password Protection Guidelines
1. Passwords should be treated as confidential information. No employee is to give, tell, or
hint at their password to another person, including IT staff, administrators, superiors,
other co-workers, friends, and family members, under any circumstances.
2. If someone demands your password, refer them to this policy or have them contact the
IT Department.
3. Passwords are not to be transmitted electronically over the unprotected Internet, such as
via e-mail. However, passwords may be used to gain remote access to company
resources via the City's IPsec-secured Virtual Private Network or SSL-protected Web
site.
4. No employee is to keep an unsecured written record of his or her passwords, either on
paper or in an electronic file. If it proves necessarily to keep a record of a password, then
it must be kept in a controlled access safe if in hardcopy form or in an encrypted file if in
electronic form.
5. Do not use the "Remember Password" feature of applications.
6. Passwords used to gain access to City systems should not be used as passwords to
access non-City accounts or information.
7. If possible, don't use the same password to access multiple databases or network
systems.
8. If an employee either knows or suspects that their password has been compromised, it
must be reported to the IT Department and the password changed immediately.
9. The IT Department may attempt to crack or guess users' passwords as part of its
ongoing security vulnerability auditing process. If a password is cracked or guessed
during one of these audits, the user will be required to change his or her password
immediately.
Failure to Complv
Violations of this policy will be treated like other allegations of wrongdoing at the City.
Allegations of misconduct will be adjudicated according to established procedures. Sanctions for
7
inappropriate use on the City's email systems and services may include, but are not limited to,
one or more of the following:
1. Temporary or permanent revocation of network access;
2. Termination of employment; and/or
3. Legal action according to applicable laws and contractual agreements.
Acceatance: Password Polic
I hereby acknowledge that I have read and understand the Password Policy of the City. I agree
to abide by these policies and ensure that persons working under my supervision abide by
these policies. I understand that if I violate such rules, I may face legal or disciplinary action
according to applicable law or departmental policy.
I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents
harmless for any loss, damage, expense or liability resulting from any claim, action or demand
arising out of or related to the user's use of the City owned computer resources and the
network, including reasonable attorney fees. Such claims shall include, without limitation, those
based on trademark or service mark infringement, trade name infringement, copyright
infringement, unfair competition, defamation, unlawful discrimination or harassment, and
invasion of privacy.
Name
Signature
Date
Email Acceptable Use Policy (EAUP)
Purpose
To establish an outline of appropriate and inappropriate use of the City's email system and
services in order to minimize disruptions to services and activities, as well as comply with
applicable policies and laws.
Backqround
Email is a critical mechanism for business communications. However, the improper use of
electronic mail systems and services can compromise the security of the network or result in
unnecessary legal liability. As a result, the provision of email to an employee is a privilege, not
a right, and therefore must be used with respect and in accordance with the goals and policies
of the City
Scope of the Policv
The City provides some, if not all, employees with electronic access, consisting of an email
system, a network connection, and InterneUlntranet access. This policy governs the use of the
City's network and email system at all City locations and offices.
The following are covered by this policy:
1. Full or part-time employees of the City who have been provided a city email address.
2. Volunteers who are authorized to use the City email system and have been provided a
city email address.
Policv
Email access is controlled through individual accounts and passwords. Each user of the City's
email system is required to read and sign a copy of this Email Acceptable Use Policy prior to
receiving an email access account and password. It is the responsibility of the employee to
protect the confidentiality of their account and password information.
All full-time employees of the City of Mounds View are entitled to an email account. Temporary
email accounts will be granted to third party non-employees on a case-by-case basis.
Applications for these temporary accounts must be submitted in writing to the Network Manager.
All terms, conditions, and restrictions governing email use must be in a written and signed
agreement.
Email access will be terminated when the employee or third party terminates their association
with the City, unless other arrangements are made. The City is under no obligation to store or
forward the contents of an individual's email inbox/outbox after the term of their employment has
ceased.
General Expectations of End Users
Important official communications are often delivered via email. As a result, employees of the
City with email accounts are expected to check their email in a consistent and timely manner so
that they are aware of important City announcements and updates, as well as for fulfilling
business and assigned tasks.
Email users are responsible for mailbox management, including organization and cleaning. If a
user subscribes to a mailing list, he or she must be aware of how to remove their email address
from the list, and is responsible for doing so in the event that their current email address
changes.
Email users are also expected to comply with normal standards of professional and personal
courtesy and conduct.
Appropriate Use
Individuals at the City are encouraged to use email to further the goals and objectives of the
City. The types of activities that are encouraged include:
Communicating with fellow employees, business partners of the City, and clients within
the context of an individual's assigned responsibilities.
2. Participating in educational or professional development activities.
Inappropriate Use
The City's email systems and services are not to be used for purposes that could be reasonably
expected to cause excessive strain on systems. Individual email use will not interfere with
others' use of the City's email system and services. Email use at the City will comply with all
applicable laws, all the City policies, and all City contracts.
The following activities are deemed inappropriate uses of the City systems and services and are
prohibited:
1. Use of email in any way that violates the City's policies, rules, or administrative orders.
2. Viewing, copying, altering, or deletion of email accounts or files belonging to the City or
another individual without authorized permission.
3. Sending of unreasonably large email attachments. The total size of an individual email
message sent or received (including attachment) must be 100Mb or less.
4. Opening email attachments from unknown or unsigned sources. Attachments are the
primary source of computer viruses and should be treated with utmost caution.
5. Sharing email account passwords with another person, or attempting to obtain another
person's email account password. Email accounts are only to be used by the registered
user.
6. Excessive personal use of the City email resources. The City allows limited personal use
for communication with family and friends, independent learning, and public service so
long as it does not interfere with staff productivity, pre-empt any business activity, or
consume more than a trivial amount of resources. The City prohibits personal use of its
email systems and services for unsolicited mass mailings, non-City commercial activity,
political campaigning, dissemination of chain letters, and use by non-employees.
Email Retention - Please refer to the Email Archiving and Retention Policy
10
Reporting Misuse
Any allegations of misuse should be promptly reported to Network Manager. If you receive an
offensive email, do not forward, delete, or reply to the message. Instead, report it directly to the
individual named above.
Failure to Complv
Violations of this policy will be treated like other allegations of wrongdoing at the City.
Allegations of misconduct will be adjudicated according to established procedures. Sanctions for
inappropriate use on the City's email systems and services may include, but are not limited to,
one or more of the following:
1. Temporary or permanent revocation of email access;
2. Disciplinary action according to applicable the City policies;
3. Termination of employment; and/or
4. Legal action according to applicable laws and contractual agreements.
Monitoring and Confidentiality
The email systems and services used at the City are the property of the City. As such, the City
has the right to monitor any and all email traffic passing through its email system. While the City
does not actively read end-user email, email messages may be read by IT staff during the
normal course of managing the email system.
In addition, backup copies of email messages may exist, despite end-user deletion, in
compliance with the City's records retention policy. The goals of these backup and archiving
procedures are to ensure system reliability and prevent business data loss.
If the City discovers or has good reason to suspect activities that do not comply with applicable
laws or this policy, email records may be retrieved and used to document the activity in
accordance with due process. All reasonable efforts will be made to notify an employee if his or
her email records are to be reviewed. Notification may not be possible, however, if the
employee cannot be contacted, as in the case of employee absence due to vacation.
Use extreme caution when communicating confidential or sensitive information via email. Keep
in mind that all email messages sent outside of the City become the property of the receiver. A
good rule is to not communicate anything that you wouldn't feel comfortable being made public.
Demonstrate particular care when using the "Reply" command during email correspondence.
Disclaimer
The City assumes no liability for direct and/or indirect damages arising from the user's use of
the City's email system and services. Users are solely responsible for the content they
disseminate. The City is not responsible for any third-party claim, demand, or damage arising
out of use the City's email systems or services.
Acceatance: Email Acceatable Use Policv (EUAP)
I hereby acknowledge that I have read and understand the Email Acceptable Use Policy of the
City. I agree to abide by these policies and ensure that persons working under my supervision
11
abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary
action according to applicable law or departmental policy.
I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents
harmless for any loss, damage, expense or liability resulting from any claim, action or demand
arising out of or related to the user's use of the City owned computer resources and the
network, including reasonable attorney fees. Such claims shall include, without limitation, those
based on trademark or service mark infringement, trade name infringement, copyright
infringement, unfair competition, defamation, unlawful discrimination or harassment, and
invasion of privacy.
Name
Signature
Date
12
Internet Acceptable Use Policy (IAUP)
Purpose
To establish a policy to ensure efficient, ethical, and legal use of Internet resources.
Backpround
The Internet is a worldwide, publicly accessible network of interconnected computer networks
that transmit data by packet switching using the standard Internet Protocol (IP). It is a"network
of networks" that consists of millions of smaller domestic, academic, business, and government
networks, which together carry various information and services, such as electronic mail, online
chat, file transfer, and the interlinked Web pages and other documents of the World Wide Web.
Access to the Internet provides employees with the opportunity to locate and use current and
historical data from multiple sources worldwide in their decision-making processes. Employees
are encouraged to develop the skills necessary to effectively utilize these tools in the
performance of their jobs.
Scope of the Policv
The following are covered by this policy:
1. Full or part-time employees of the City.
2. Volunteers who are authorized to use City resources to access the Internet.
3. Contractors who are authorized to use City-owned equipment or facilities to access the
Internet.
Policv
Internet access at the City is controlled through individual accounts and passwords.
Department managers are responsible for defining appropriate Internet access levels for the
persons in their department and conveying that information to the Network Manager.
Each user of the City system is required to read this Internet policy and sign an Internet use
agreement prior to receiving an Internet access account and password.
Appropriate Use
Individuals at the City are encouraged to use the Internet to further the goals and objectives of
the City. The types of activities that are encouraged include:
1. Acquiring or sharing information necessary or related to the performance of an
individual's assigned responsibilities;
2. Participating in educational or professional development activities.
Inappropriate Use
Individual Internet use will not interfere with others' use and enjoyment of the Internet. Users
will not violate the network policies of any network accessed through their account. Internet use
13
at the City will comply with all Federal and State laws, all City policies, and all the City contracts.
This includes, but is not limited to, the following:
1. The Internet may not be used in any way that violates the City's policies, rules, or
administrative orders including, but not limited to, the City's employee code of conduct
policies. Use of the Internet in a manner that is not consistent with the mission of the
City, misrepresents the City, or violates any the City policy is prohibited.
2. Individuals should limit their personal use of the Internet. The City allows limited
personal use for communication with family and friends, independent learning, and
public service. The City prohibits use for mass unsolicited mailings, access for non-
employees to the City resources or network facilities, competitive commercial activity
unless pre-approved by the City, and the dissemination of chain letters.
Security
For security purposes, users may not share account or password information with another
person. Internet accounts are to be used only by the assigned user of the account for
authorized purposes. Attempting to obtain another user's account password is strictly prohibited.
Users are required to change or obtain a new password if they have reason to believe that any
unauthorized person has learned their password. Users are required to take all necessary
precautions to prevent unauthorized access to Internet services.
Monitoring
The City may monitor any Internet activity occurring on the City equipment or accounts. If the
City discovers activities which do not comply with applicable law or departmental policy, records
retrieved may be used to document the violation of this policy statement.
Website Blocking and Filtering
The City currently does employ filtering software to limit access to sites on the Internet.
Restricted sites typically contain adult or pornographic material. To preserve Internet bandwidth
websites that use an inordinate amount of bandwidth will be filtered. These sites typically
contain streaming video and audio but also includes sites that contain large file downloads.
Exceptions to the filtering policy can be submitted to the Network Manager for review.
Failure to Complv
Violations of this policy will be treated like other allegations of wrongdoing at the City.
Allegations of misconduct will be adjudicated according to established procedures. Sanctions
for inappropriate use of the Internet may include, but are not limited to, one or more of the
following:
1. Temporary or permanent revocation of access to the Internet.
2. Disciplinary action according to applicable the City policies;
3. Legal action according to applicable laws and contractual agreements;
Disclaimer
The City assumes no liability for any direct or indirect damages arising from the user's
connection to the Internet. The City is not responsible for the accuracy of information found on
the Internet and only facilitates the accessing and dissemination of information through its
systems. Users are solely responsible for any material that they access and disseminate
through the Internet.
14
We encourage you to use your Internet access responsibly. Should you have any questions
regarding this Internet Acceptable Use Policy, feel free to contact the Network Manager at 651-
792-7092.
Acceptance: Internet Acceptable Use Policy (IUAP)
I hereby acknowledge that I have read and understand the Internet Acceptable Use Policy of the
City. I agree to abide by these policies and ensure that persons working under my supervision
abide by these policies. I understand that if I violate such rules, I may face legal or disciplinary
action according to applicable law or departmental policy.
I hereby agree to indemnify and hold the City and its officers, trustees, employees, and agents
harmless for any loss, damage, expense or liability resulting from any claim, action or demand
arising out of or related to the user's use of the City owned computer resources and the
network, including reasonable attorney fees. Such claims shall include, without limitation, those
based on trademark or service mark infringement, trade name infringement, copyright
infringement, unfair competition, defamation, unlawful discrimination or harassment, and
invasion of privacy.
Name
Signature
Date
15