PVAMU Home Business Affairs
PVAMU Business Affairs

Business Affairs


Home » Business Affairs » Policy Library » Information Security Standards » Internet/Intranet Usage

Internet/Intranet Usage


1. General

Under the provisions of the Information Resources Management Act, Information Resources are strategic assets of the State of Texas and must be managed as valuable state resources. This procedure is established to achieve the following:

    • To ensure compliance with applicable statutes, regulations, and mandates regarding the management of information resources;

    • To establish acceptable practices regarding the use of information resources; and,

    • To educate individuals who may use information resources with respect to their responsibilities associated with such use.

2. Applicability

This procedure applies to all University information resources. The purpose of this procedure is to provide a set of measures that will mitigate information security risks associated with internet/intranet use. The intended audience is all users of University information resources.

3. Definitions

    • Confidential Information: information that is excepted from disclosure requirements under the provisions of applicable state or federal law, e.g., the Texas Public Information Act.

    • Information Resources (IR): the procedures, equipment, and software that are designed, employed, operated, and maintained to collect, record, process, store, retrieve, display, and transmit information or data.

    • Mission Critical Information: information that is defined by the University or information resource owner to be essential to the continued performance of the mission of the University or department. Unavailability of such information would result in more than an inconvenience. An event causing the unavailability of mission critical information would result in consequences such as significant financial loss, institutional embarrassment, and failure to comply with regulations or legal obligations, or closure of the University or department.

4. Procedures

1. All files downloaded from the internet/intranet shall be scanned by software to safeguard against malicious code.
2.
University Internet access may not be used for personal gain or solicitations.
3.
No University mission critical or confidential information shall be made available via University websites without ensuring that the material is accessible to only authorized individuals or groups.

  • All mission critical or confidential information transmitted over external networks must be encrypted.

  • Electronic files are subject to the same records retention rules that apply to other documents and must be retained in accordance with University records retention schedules.

4. Any security violations, and all signs of wrongdoing pertaining to this procedure, shall be reported according to the University Management for appropriate action.
5.
Incidental use of internet/intranet access is subject appropriate action as detailed.