Skip Navigation

Information Technology

Information Systems Security

Policy and Procedures
Angelo State University

Information systems at Angelo State University (ASU) are provided for the use of ASU students, faculty and staff. Access to information systems at ASU imposes certain responsibilities and obligations and is granted subject to University policies. All students, faculty and staff are responsible for appropriate use of ASU information systems. Appropriate use is always ethical and lawful, reflects academic honesty and shows restraint in the consumption of shared resources. Users will demonstrate respect for all aspects of information systems at ASU including, but not limited to, intellectual property, ownership of data, system security and individuals' rights to privacy.

This document outlines the appropriate use of Angelo State University information systems. Additional University policies and/or guidelines may govern the use of particular resources. Federal and Texas Law also regulate unauthorized access and misuse of information resources.

Security of Information Systems

The administrator of an information system is responsible for exercising care in securing the information contained on that system. The administrator will establish and maintain all policies regarding access to his/her particular information system. The failure of any information system to prevent unauthorized use of that information system does not relieve an individual of the responsibility of obtaining authorization prior to his or her use of the information system. Anyone discovering a "breach" in the security of an information system must report it immediately to the Information System Administrator.

User Accounts and Passwords

An account and/or password assigned to an individual may not be used by others unless the intent of the account and/or password is for group access. The individual is responsible for the proper use of the account, including proper account and/or password protection. The individual should never allow anyone else to access an information system using his or her account and/or password. The individual will be held responsible for any misuse or damage caused by another individual using the first individual's account and/or password. Accounts and/or passwords will not be left in any form that would allow discovery by another. Individual's password should not be something that could be easily guessed and it should include at least one special character whenever possible. Individuals should change their password on a regular basis to maintain the security of their account.

The user of an information system should never leave an account logged on an unattended workstation unless the machine is in a secure area that would prevent someone else from gaining access, such as a private office. Machines in common work areas should be logged off when unattended. If an individual discovers that someone has made unauthorized use of his/her account, he/she should change their password immediately and infrom to the Information System Administrator.

Information system accounts which expire will be deleted. All files associated with the expired account will be reviewed by the appropriate department head and will be deleted or transferred to another account at the conclusion of the review. Accounts expire in accordance with the terms of the account established by the administrator of the information system.

Access to Information Systems

Access to information systems at ASU is a privilege, not a right, which may be revoked at any time.

Access or attempts to access another person’s information or data, whether protected or not, without the owner’s permission is prohibited. All information is presumed to be private and confidential unless it has explicitly been made available to other authorized individuals. An individual’s information may be accessed by authorized personnel for compelling business and/or security reasons with the approval of the appropriate information system administrator. Attempts to access unauthorized information systems, to decrypt encrypted materials, or to obtain privileges to which the user is not entitled are prohibited.

Comments regarding this policy statement should be directed to Doug Fox at doug.fox@angelo.edu