Cleveland Metropolitan School District



Cleveland Metropolitan School District

Department of Technology: IT Security

System Compliance and Acceptable Use Acknowledgement

Applicable to: Contractors, Consultants, Vendors, Temporaries,

Business Partners, etc. (third party personnel)

Overview

Information Technology Security is committed to protecting Cleveland Metropolitan School District’s (CMSD) data and information systems from illegal and/or damaging actions by individuals or networked devices, either knowingly or unknowingly. Internet/Intranet/Extranet-related systems, including but not limited to computer equipment, software, operating systems, storage media, network accounts, electronic mail, WWW browsing, and FTP, provide a significant risk to CMSD if the system(s) are not maintained with up-to-date system patches, service packs and security updates. These systems are to be used for business purposes in serving the interests of the CMSD, and of our students and employees, in the course of normal business operations. It is the responsibility of every computer user to know these guidelines, and to conduct their activities accordingly.

Scope

This acknowledgement applies to contractors, consultants, vendors, temporaries, business partners, third party and other workers at or under consideration for employment by the CMSD, including all personnel affiliated with third parties; or engaged in a business partnership with the CMSD.

Network Security

1. Contractors, consultants, vendors, business partners, and Third Party employees, may be subject to background checks prior to initiating any service agreements, contracts or business relationship with the Cleveland Metropolitan School District. The CMSD has the right to terminate any contracts or agreements with contractor, vendor or Third Party if the background checks reveal a violation of the Ohio Revised Code pertaining to schools.

2. Consultant, Vendor and Third Party or business partners will not install any application on systems hosted or connecting to the CMSD network that have any of the following capabilities, this includes but is not limited to applications that have port-scanning, system enumeration, web proxies, or packet sniffing capabilities.

3. Contractors, consultants, vendors, business partners, and Third Party employees’ internet access will be conducted thru CMSD’s web content filter while connected to the CMSD network.

General Use and Ownership

1. Contractors, consultants, vendors, third parties, and business partners are responsible for exercising good judgment and industry best practices regarding use of the CMSD network.

2. Information Technology Security requires that any information that users consider sensitive or vulnerable be password protected, in some instances encryption may be required.

3. The CMSD reserves the right to audit networks and systems on a periodic basis to ensure compliance with this acknowledgement. All communications and files stored on district servers (including iNotes) are the property of the district and users should not have any expectation of privacy.

4. Upon completion of the contract and/or partnership, contractors, consultants, temporary, vendor, business partners, and third parties agrees to dispose of confidential and/or proprietary CMSD information both in electronic and hard copy formats. This would include information that may be contained on personal devices such as, but not limited to, computers, PDA, electronic storage media such as USB drives, external hard drives, CDs or DVDs.

Security Guidelines

1. Confidential CMSD information must be handled appropriately. Confidential information includes but is not limited to: student information, employee information, trade secrets, intellectual property, specifications, personnel lists, and research data. Contractors, vendors, business partners and all third parties should take all necessary steps to prevent unauthorized access to or unauthorized dissemination of this information. Strict adherence to FERPA () and HIPPA () guidelines is required.

2. Keep passwords secure and do not share accounts. Authorized users are responsible for the security of their passwords and accounts.

3. All PC’s laptops and workstations should be secured with a password-protected screensaver with the automatic activation feature.

4. Information stored on a portable computer is especially vulnerable, special care should be exercised. Protect laptops and PDAs with power-on passwords.

5. Any computer connected to the CMSD network must maintain up-to-date anti-virus software with the latest signatures (patches).

6. Any computer connected to the CMSD network must update their operating system and applications software to protect against known vulnerabilities and exploits. This includes the latest service packs, security patches, and application patches.

7. Contractors, consultants, vendors, third parties, business partners must use extreme caution when opening email attachments received from unknown senders, which may contain viruses, e-mail bombs, or Trojan horse code.

Enforcement

Should the Contractor, Consultant, Vendor, Temporary, Business Partner, or Third Party be found to be non-compliant with these standards or in violation of this agreement, the Cleveland Metropolitan School District reserves the right to revoke and/or terminate any agreements business partnerships or contracts immediately. Any Contractor, Consultant, Vendor, Temporary, Business Partner, or Third Party found to have violated this acknowledgement might be subject to disciplinary and/or legal action.

System Compliance and Acceptable Use Acknowledgement

I, acknowledge that I have read and understand this “System

Compliance and Acceptable Use Acknowledgement” document and accept responsibility for my use of data accessible by me, my workstation, and all network activity. I acknowledge that should I not comply with tenets set forth in this Acknowledgement that I and/or my company may be held liable.

| | | |

(Signature of Consultant, Contractor, Vendor, etc) (Date)

| | | |

(Title) (Date) (Company Name)

| | | |

(Company’s Phone Number) (Address / City / State / Zip Code)

| | | |

(CMSD’s Sponsor / Official Signature) (Title) (Date)

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download