ITM-20.01 ACCEPTABLE USE 1-31-22.PDF
Extracted text (via pymupdf)
23626 characters
ARIZONA DEPARTMENT OF TRANSPORTATION (ADOT) POLICY ITM-20.01 Acceptable Use Policy Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/2021) Transmittal: 2022 - January Responsible Office: Information Technology Group (ITG) (602) 712-7300 Revision: 2.0 Page 1 of 8 1. AUTHORITY To effectuate the mission and purposes of the Arizona Department of Transportation (ADOT), a coordinated plan and program for Information Technology (IT) has been established, implemented and maintained through Policies, Standards and Procedures (PSPs) as authorized by Arizona Revised Statutes (A.R.S.) § 18-104, § 18-105, § 41-773 and § 44-7601. 2. PURPOSE The purpose of this policy is to outline the acceptable use of ADOT information system assets and data to reduce the risk of inappropriate disclosure, modification or disruption, whether intentional or accidental. 3. SCOPE This policy applies to all ADOT information systems, processes, operations and personnel to include all employees, contractors, interns, volunteers, external partners and their respective programs and operations. 4. EXCEPTIONS 4.1 Exceptions to all ITM policies and standards shall: 4.1.1 Be properly documented and approved using the IT Policy Exception Form located on ADOTNet, 4.1.2 Be approved by the requester’s Division Director, ADOT ISO and ADOT CIO, 4.1.3 Be managed and tracked by the ADOT ISO, 4.1.4 Not exceed one year in duration, and 4.1.5 Be treated as confidential information, not to be shared or published. . Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 2 of 10 ITM-20.01 5. ROLES AND RESPONSIBILITIES 5.1 ADOT Director shall: 5.1.1 Be responsible for the correct and thorough completion of ADOT IT PSPs within the agency; 5.1.2 Ensure compliance with policy; and 5.1.3 Promote efforts within the agency to establish and maintain effective use of agency information systems and assets. 5.2 ADOT Chief Information Officer (CIO) shall: 5.2.1 Work with the ADOT Director to ensure the correct and thorough completion of agency IT PSPs within the agency; and 5.2.2 Ensure all IT policies are periodically reviewed and updated to reflect changes in requirements. 5.3 ADOT Information Security Officer (ISO) shall: 5.3.1 Advise the ADOT CIO on the completeness and adequacy of the agency activities and documentation provided to ensure compliance with agency IT PSPs; 5.3.2 Ensure the development and implementation of an adequate controls enforcing the IT policies for the agency information systems; and 5.3.3 Ensure all personnel understand their responsibilities with respect to this and all IT policies. 6. ADOT POLICY 6.1 Access Agreements – ADOT Chief Information Officer (CIO) shall ensure that individuals requiring access to organizational information and ADOT information systems acknowledge and accept appropriate legal agreements (e.g., Data Sharing, Acceptable Use, Non-Disclosure) prior to being granted access and shall update the access agreements annually. [NIST 800-53 PS-6] [PCI DSS 12.3]. 6.1.1 Assign Responsibility to Provide Policy - ADOT CIO shall assign responsibility to a department, role, or named individual to provide acceptable use and other related information security policies to employees and contractors. Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 3 of 10 ITM-20.01 6.1.2 Assign Responsibility to Keep Records - ADOT CIO shall assign responsibility to a department, role, or named individual to keep records of distributed, acknowledged, and accepted acceptable use policies for employees and contractors. 6.2 Access Agreement Contents - Acceptable Use Agreements contain the following policy sections and statements: 6.2.1 Expected Behaviors - The following behaviors are required: 6.2.1.1 Practice Safe Computing 6.2.1.1.1 Those accessing ADOT information systems shall use caution and exercise good security practices to ensure the protection of ADOT information systems and data, including, but not limited to: 6.2.1.1.1.1 Opening Attachments or Links - Use caution when opening email attachments or following hypertext links received from unknown senders. 6.2.1.1.1.2 Keep Passwords Secure - Select strong passwords, do not write them down, change them frequently, and do not share them with anyone. 6.2.1.1.1.3 Keep Desk and Workstation Secure - Use available operating system functions to lock the workstation when away from the desk. At the end of the day, log out of the computer, but leave the equipment powered on. 6.2.1.1.1.4 Challenge Unauthorized Personnel - Assist in enforcing physical access controls by challenging unauthorized personnel who may not be following procedures for visitor sign-in, appropriate badge use, escort control, and/or entry. 6.2.1.1.1.5 Report Security or Privacy Weaknesses or Violations - Report any weaknesses in computer security or data privacy, suspicious behavior of others and any incidents of possible misuse or violation of this policy to the agency ISO. 6.2.1.2 Protect Confidential Information - Confidential information shall be protected in accordance with applicable statutes, rules, policies, standards, and procedures. Those accessing ADOT information systems shall protect confidential information in accordance with the Data Classification Policy (ITM- 12.01). Specifically, the following: 6.2.1.2.1 Unencrypted Confidential Information - Confidential information sent over email or other electronic messaging without adequate encryption shall be prohibited (even to an authorized user). Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 4 of 10 ITM-20.01 6.2.1.2.2 Storage of Confidential Information - Confidential information must be stored in accordance with the ITM-16.01, Media Protection Policy. 6.2.1.2.3 Electronic Transmission of Confidential Information - Confidential information that is transmitted outside of ADOT information systems or on any medium that can be accessed by authorized users shall be encrypted through link or end-to-end encryption with an encryption algorithm and key length in accordance with ITM-15.01 System and Communication Protection Policy. 6.2.2 Prohibited Behaviors 6.2.2.1 The following behaviors shall be prohibited: 6.2.2.1.1 Computer Tampering - Unauthorized access, interception, modification or destruction of any computer, computer system, ADOT information systems, computer programs or data; [ARS 13- 2316.1-2] 6.2.2.1.2 Use of Unauthorized Computing Equipment - Installation or connections of any computing equipment not provided or authorized by the ADOT CIO to ADOT information systems; 6.2.2.1.3 Use of Unauthorized Software - Installation or use of any unauthorized software, including but not limited to security testing, monitoring, encryption, or “hacking” software on ADOT computing resources; [NIST 800 53 CM-11] 6.2.2.1.4 Unauthorized Use of Software or Services - Use of peer-to-peer file sharing technology used for the unauthorized distribution, display, performance, or reproduction of copyrighted work; [NIST 800 53 CM-10] 6.2.2.1.5 Introduction of Malware - Knowingly introducing a computer contaminant into any computer, computer system or ADOT information systems; [ARS 13-2316.3] 6.2.2.1.6 System Disruption - Recklessly disrupting or causing the disruption of a computer, computer system or ADOT information systems; [ARS 13-2316.4] 6.2.2.1.7 Circumvention of Security Controls - Disabling software, modifying configurations, or otherwise circumventing security controls. [ARS 13-2316] Tampering with physical security measures (e.g., locks, cameras) is also prohibited; Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 5 of 10 ITM-20.01 6.2.2.1.8 False Identity - Falsifying identification information or routing information so as to obscure the origins or the identity of the sender, or using or assuming any information system or application identification other than your own; 6.2.2.2 Unauthorized Inappropriate or Unlawful Material - The unauthorized storage, transmission, or viewing of any pornography or other offensive, intimidating, hostile or otherwise illegal material is forbidden. Except to the extent required in conjunction with a bona fide ADOT approved research project or other ADOT approved undertaking, an employee of ADOT shall not knowingly use ADOT owned or ADOT leased computer equipment to access, download, print or store any information infrastructure files or services that depict nudity, sexual activity, sexual excitement or ultimate sex acts; [ARS 38-448] [ARS 13-2316.5] 6.2.2.3 Unauthorized Use of Electronic Messaging - The following use of electronic messaging shall be prohibited: 6.2.2.3.1 Spam - Sending of unsolicited commercial emails/electronic messages in bulk (identical content to multiple recipients). 6.2.2.3.2 Chain Letters - Creating or forwarding chain letters or pyramid schemes. 6.2.2.3.3 Unprofessional Communications - Unprofessional or un-businesslike in appearance or content. 6.2.2.3.4 Alter Message Content - Modification or deletion of email/electronic messages originating from another person or computer with the intent to deceive. 6.2.2.3.5 False Identity - Falsifying email/electronic message headers or routing information so as to obscure the origins of the email/electronic message or the identity of the sender, also known as spoofing. 6.2.2.3.6 Mask Identity - Unauthorized use of anonymous addresses for sending and receiving email/electronic messages. 6.2.2.3.7 Auto-Forward to External Accounts - Automatically forwarding email/electronic messages sent to an ADOT account to an external email/electronic messages without authorization. 6.2.2.3.8 Non-ADOT Email Accounts - Unauthorized use of a non-ADOT email account for ADOT business. Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 6 of 10 ITM-20.01 6.2.2.3.9 Unencrypted Confidential Information - Confidential information sent over email or other electronic messaging without adequate encryption (even to an authorized user). 6.2.2.3.10 Misrepresentation of ADOT - Presenting viewpoints or positions not held by ADOT as those of ADOT or attributing them to ADOT. 6.2.2.3.11 Using without benefit for the state any streaming audio or video transmission that could cause congestion, delay, or disruption of service to any state system or equipment. For example "Push" technology, video, sound or other large file attachments. 6.2.2.3.12 Connecting non-ADOT or personal electronic equipment to ADOT networks or technology resources except for approved remote access. Using non-ADOT or personal electronic equipment to store or transmit state data or information. Exemption requests need to be submitted through the ADOT Service Desk by emailing atg@azdot.gov or calling 602-712-7249. 6.2.2.3.13 Using ADOT’s electronic equipment as a platform to gain unauthorized access to other systems or equipment. 6.2.2.3.14 Creating, copying, transmitting, or re-transmitting chain letters or other unauthorized mass mailings regardless of the subject matter. 6.2.2.3.15 Posting, storing, sending, transmitting, or disseminating any information or material which could be deemed defamatory, false, abusive, obscene, pornographic, profane, sexually oriented, threatening, racially offensive, or otherwise biased, discriminatory, or violates or infringes on the rights of any other person. 6.2.2.3.16 Creating, downloading, viewing, storing, copying, printing or transmitting sexually explicit or sexually oriented materials. 6.2.2.3.17 Creating, downloading, viewing, storing, copying, printing or transmitting materials related to gambling, weapons or terrorist activities. 6.2.2.3.18 Engaging in any outside fund-raising activity, endorsing any product or service, participating in any lobbying activity, or engaging in any prohibited partisan political activity. 6.2.2.3.19 Acquiring, using, reproducing, transmitting, or distributing any unauthorized controlled information including computer software and data, personally identifying information, privacy information, copyrighted, trademarked or material with other intellectual property rights (beyond fair use), proprietary data, or exporting controlled software or data. Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 7 of 10 ITM-20.01 6.2.2.3.20 Storing, sending or transmitting any personal identifying information (PII) in an unencrypted form. 6.2.2.3.21 Engaging in conduct that would constitute a criminal offense, give rise to civil liability, or otherwise violate any local, state, federal law, order or regulation. 6.2.2.3.22 Using or distributing tools designed for compromising security, such as password guessing programs, decoders, password gatherers, unauthorized keystroke loggers, analyzers, cracking tools, packet sniffers, encryption circumvention devices, or Trojan Horse programs. Unauthorized port scanning, for any reason, is prohibited. 6.2.2.3.23 Accessing any other person's computer or computer system, software, or data; or attempting to circumvent the user authentication or security of any host, network, or account. This includes, but is not limited to, accessing data not intended for you, logging into or making use of a server or account you are not expressly authorized to access, or probing the security of other hosts, networks, or accounts. 6.2.2.3.24 Using text features (texting) or video call capabilities on Mobile Communication Devices (MCD) while operating motorized equipment. 6.2.2.3.25 Recording meetings or conversations without prior consent of all participants of the meeting or conversation. This provision does not apply to investigations authorized by the ADOT Director or ADOT operations to conduct formal administrative or criminal investigations, such as Employee Relations, the Civil Rights Office, and the Office of Inspector General. 6.2.2.4 INCIDENTAL USE Incidental use means non job-related use (i.e., personal use). Incidental use of the Department’s Internet access is permitted, but should be restrained and limited to the extent it cannot reasonably be accomplished outside normal work hours without using state owned information technology resources. Reasonable use is allowed, but should only occur before and after normal work hours or during the lunch period. However, it is prohibited if it: 6.2.2.4.1 Interferes with the user’s productivity or work performance, or with any other user’s productivity or work performance. 6.2.2.4.2 Adversely affects the efficient operation of the Department’s information resources. 6.2.2.4.3 Creates additional cost to the Department. 6.2.2.4.4 Brings discredit or embarrassment to the Department. Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 8 of 10 ITM-20.01 6.2.2.4.5 Involves performing work for profit or results in personal gain. 6.2.2.4.6 Otherwise violates any local, state or federal law or regulation. 6.2.2.5 Violation of Intellectual Property Laws - Unauthorized receipt, use or distribution of unlicensed software, copyrighted materials, or communications of proprietary information or trade secrets. 6.2.2.6 Unauthorized Access of Confidential Information - Unauthorized access of information that has been classified as Confidential could cause harm to the state and/or the citizens of the state. The Confidentiality of information is protected by law. The unauthorized access of any confidential information is prohibited. [ARS 13-2316.07] 6.2.2.7 Unauthorized Release of Confidential Information - Disclosure of information that has been classified as Confidential could cause harm to the state and/or the citizens of the state. The Confidentiality of information is protected by law. The unauthorized release or disclosure of any confidential information is prohibited. [ARS 36-342] [ARS 36-666] [ARS 41-151.12] [ARS 41-1750.01] 6.2.2.8 User responsibilities: 6.2.2.8.1 Deleting all content (emails, files, etc.) that is not essential from mobile electronic equipment. 6.2.2.8.2 Using hands free cell phone devices when operating a vehicle for state business. 6.2.2.8.3 Ensuring data is stored regularly on Department servers (such as U:\ or G:\ drives) in case the mobile electronic equipment is lost, damaged, or unrecoverable. 6.2.2.8.4 Reporting lost or stolen mobile electronic equipment to security@azdot.gov. 1. Cell Phone – The loss or theft of the cell phone shall be immediately reported to the appropriate supervisor. The supervisor shall ensure the cell phone provider is contacted so that service on the device is canceled. 2. Laptop – The loss or theft of these devices shall be immediately reported to the appropriate supervisor, ITG and law enforcement. Notify ITG by emailing security@azdot.gov. Notify Risk Management by completing the Property Loss Report, then submit it to propertyloss@azdot.gov 3. USB flash drive and other data storage devices – The loss or theft of these devices shall be immediately reported to the Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 9 of 10 ITM-20.01 appropriate supervisor and ITG. Notify ITG by emailing security@azdot.gov. 6.2.2.8.5 Contacting the ADOT Service Desk by emailing atg@azdot.gov or calling 602-712-7249 for deactivation of an electronic device. 6.2.3 Notifications and Acknowledgements - The following notifications and acknowledgements shall be used to inform those granted access to ADOT information systems of controls used to ensure the security of ADOT information systems: 6.2.3.1 User Responsibility Acknowledgement - All users review and acknowledge their understanding of this policy and other related information security policies on an annual basis; [PCI DSS 12.6.2] 6.2.3.2 Assets and Intellectual Property - All ADOT information system assets remain the sole property of ADOT. Any data or intellectual property created by the user, including voicemail and electronic messages, shall remain the property of the ADOT and shall not be removed, copied or shared with any person or entity except as part of the user’s normal job responsibilities; 6.2.3.3 Monitoring - ADOT reserves the right to monitor all activities that occur on its ADOT information systems or to access any data residing on its systems or assets at any time without further notice; 6.2.3.4 Potential Blocking of Inappropriate Content - ADOT may block access to web content it deems as inappropriate and filter email destined for a user’s mailbox; 6.2.3.5 Incomplete Blocking of Inappropriate Content - ADOT shall not be responsible for material viewed or downloaded by users from the Internet or messages delivered to a user’s mailbox. Users are cautioned that many Internet pages and emails include offensive, sexually explicit, and inappropriate material. Even though ADOT intends to filter and block inappropriate content and messages, it is not always possible to avoid it; 6.2.3.6 No Expectation of Privacy - Users shall have no expectation of privacy for any communication or data created, stored, sent, or received on ADOT information systems and assets; and 6.2.3.7 User Acknowledgement - By using ADOT information systems, users shall acknowledge they explicitly consent to the monitoring of such use and the right of ADOT to conduct such monitoring. 6.3 Business Use: State owned information technology resources, including electronic equipment, are furnished by ADOT for use in conducting state business. ADOT does not allow improper use of its electronic equipment. Improper use shall result in disciplinary action up to and Effective: January 31, 2022 Review: January 31, 2024 Supersedes: ITM-20.01 (4/23/21) Page 10 of 10 ITM-20.01 including termination of employment. In addition, improper use may result in the initiation of legal action (civil or criminal), or notifying appropriate law enforcement authorities for further action. 6.4 Consequences for Non-compliance - Users of ADOT information systems who fail to comply with established information security and privacy policies and procedures may be subject to disciplinary action, including referral to law enforcement for appropriate action. [NIST 80053 PS-8] [HIPAA 164.308(a)(1)(ii)(C)] [HIPAA 164.530(e)(1), (2)] [State Personnel System (SPS) Rule R2-5A-501] 7. DEFINITIONS AND ABBREVIATIONS 7.1 Refer to the IT Glossary of Terms located on the ADOA-ASET website. 8. REFERENCES 8.1 NIST 800-53, Recommended Security Controls for Federal Information Systems and Organizations 8.2 HIPAA Administrative Simplification Regulation, Security and Privacy, CFR 45 Part 164 8.3 IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies 8.4 Payment Card Industry Data Security Standard (PCI DSS), PCI Security Standards Council 9. ATTACHMENTS None. 10. REVISION HISTORY Date Revision Change Approver 06/28/2019 1.0 Initial Draft Thomas Branham 01/06/2022 2.0 Combined ITM-5.01 Electronic Equipment Policy with this Policy (ITM- 20.01 Acceptable Use) Thomas Branham, ADOT Infrastructure Protection Manager (Cyber Security and Privacy Officer)