Links

Technology Services Home
Policies
Survey Results
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 

 

 

 

 

 

 

 

 

 

 

 

 

Security policy

The NCCC Chief Information Officer (CIO) has the responsibility and authority to evaluate the seriousness and immediacy of any threat to campus information resources and to take action to mitigate that threat.  Action that is taken will be based on the risk associated with that threat and the potential negative impact to the campus mission caused by making the offending computer(s) inaccessible.  Examples of threats that are serious enough to invoke these procedures are: 1) the level of network activity is sufficiently large as to cause serious degradation in the performance of the network; 2) system administrative privilege has been acquired by someone who is not authorized to have it; 3) an attack on another information resource has been launched; 4) confidential, private, or proprietary electronic information or communications are being collected, destroyed, or disseminated inappropriately; or, there is reason to believe the possibility exists to collect electronic information inappropriately; 5) serious complaints have been received regarding inappropriate activity, or 6) any other threat that has been reported .

College information resources that are defined as critical and essential to the functions of the College must be reviewed before connection to the campus network by the NCCC CIO.

NCCC is committed to compliance with applicable federal and state laws including but not limited to the: Counterfeit Access Device and Computer Fraud and Abuse Act of 1984 (Title 18 of the U.S. Code); Electronics Communications Privacy Act of 1986 (Public Law 99-474); Computer Security Act of 1987 (Public Law 100-235); and USA Patriot Act of 2001.

Responsibilities

Departments

- Each department or unit will notify the Technology Services department to terminate access rights when authorized users change status (e.g., terminate employment, graduate, retire, change positions or responsibilities within the College, etc.).  The department or unit is responsible for maintaining access protocols on their locally maintained information resources and informing College and appropriate system administrators of employee changes in status that affect access to central systems.
- Each department will assist administration in providing appropriate access controls to all information resources.
- Each department will keep contact information current in the designated NCCC Information Technology databases.
- Each department will monitor communications from the Technology Services and implement appropriate actions on the systems for which they are responsible.

NCCC Technology Services

- The NCCC Technology Services department  will investigate security incidents to determine severity of threats; make decisions on appropriate actions; and notify appropriate information technology personnel.  CIO will coordinate and communicate with departmental technical liaisons regarding necessary actions.
- Technology Services will work with the technical liaison to ensure that the computer(s) are properly re-secured after an incident.
- Technology Services will track open incidents to ensure timely resolution.
- Technology Services will maintain individuals’ privileges and respect their privacy to the extent reasonably possible when accessing others’ files for the maintenance of networks and computer and storage systems.
- Technology Services will cultivate awareness of security issues and vulnerabilities within the College.
- Technology Services will approve the connection of critical and essential systems to the campus network.

Authorized Users of Information Technology

- Authorized users of information technology must become aware and acknowledge responsibilities for security when obtaining access to College information resources.
- Authorized users of information technology must accept responsibility for any use of information resources and personal accounts.  Computer accounts, access codes, passwords, and other types of authorization are assigned to individual users and must not be shared with others.
- Authorized users of information technology must protect the access and integrity of information resources by following the security practices recommended by NCCC Information Services.

Vendors

The NCCC CIO will be responsible for educating vendors about the security protocols on College information resources and any federal laws that might apply.  All staff employed by vendors who work on College information resources are required to sign the NCCC Non-Disclosure Agreement and be certified by either their employer or the NCCC CIO before accessing College systems.   Vendors will only be granted the necessary access to fulfill tasks that have been predetermined.  Agreed upon vendor work will be reviewed upon completion to ensure its quality, accuracy, and completeness.

Protocol

Blocking Network Access or System Isolation

The ability to quickly contact responsible departmental personnel and have them take appropriate action can mitigate the negative effects of an incident both locally in the department and more globally throughout the campus and the Internet. When a problem is identified, Technology Services must be able to quickly contact the department so that any affected user(s) may be informed of the situation. If the threat is immediate, Technology Services will block the offending information resource immediately (or isolate it) and will notify the department that the block has occurred.  If the threat is not immediate, notification of the threat will be sent to the department.  If a response is not received indicating that the department is taking action to mitigate the threat, the offending information resource will then be blocked (or isolated) until a resolution has been reached.  In either case, Technology Services will work with the department to ensure that the information resource is properly re-secured.  If a block (or isolation) has been put in place, it will be removed when the CIO is assured that the information resource is safe.

Reporting Security and Abuse Incidents

All authorized users are stakeholders and share a measure of responsibility in intrusion detection, prevention, and response.
All users and units have the responsibility to report any discovered unauthorized access attempts or other improper usage of NCCC information resources.  If you observe, or have reported to you, a security or abuse problem with any College information resource, including violations of this policy, immediately notify the NCCC Help Desk (x218; help@neosho.edu) and take immediate steps as minimally necessary to ensure the security and integrity of information resources.  The Help Desk will notify the CIO, who will coordinate the technical and administrative response to such incidents. 

EXCLUSIONS OR SPECIAL CIRCUMSTANCES: 

 Exceptions to this Policy shall only be allowed if previously approved by the Technology Services department  and this approval is documented and verified by the CIO.

CONSEQUENCES:

Faculty, staff, and student employees who violate this College policy may be subject to disciplinary action for misconduct and/or performance based on the administrative process appropriate to their employment.

Students who violate this College policy may be subject to proceedings for non-academic misconduct based on their student status.
Faculty, staff, student employees, and students may also be subject to the discontinuance of specified information technology services based on the policy violation.


 

Copyright 2010 by Neosho County Community College | Terms Of Use | Privacy Statement | Non Discrimination Statement Register | Login