ITM-20.01 ACCEPTABLE USE 1-31-22.PDF

Maricopa County — Formal (2025-01-29)

View PDF Item 131 Meeting page

Extracted text (via pymupdf) 23626 characters
ARIZONA DEPARTMENT OF TRANSPORTATION (ADOT) 
POLICY 
ITM-20.01 Acceptable Use Policy 
 
Effective: January 31, 2022   
Review: January 31, 2024 
Supersedes:  ITM-20.01 (4/23/2021) 
  Transmittal: 2022 - January 
Responsible Office: Information Technology Group (ITG)  
(602) 712-7300 
Revision: 2.0 
Page 1 of 8 
 
1. AUTHORITY 
To effectuate the mission and purposes of the Arizona Department of Transportation (ADOT), a 
coordinated plan and program for Information Technology (IT) has been established, implemented and 
maintained through Policies, Standards and Procedures (PSPs) as authorized by Arizona Revised Statutes 
(A.R.S.) § 18-104, § 18-105, § 41-773 and § 44-7601.   
2. PURPOSE 
The purpose of this policy is to outline the acceptable use of ADOT information system assets and data 
to reduce the risk of inappropriate disclosure, modification or disruption, whether intentional or 
accidental. 
3.  SCOPE 
This policy applies to all ADOT information systems, processes, operations and personnel to include all 
employees, contractors, interns, volunteers, external partners and their respective programs and 
operations. 
 
 
4. EXCEPTIONS 
4.1 
Exceptions to all ITM policies and standards shall: 
4.1.1 Be properly documented and approved using the IT Policy Exception Form located on 
ADOTNet,   
4.1.2 Be approved by the requester’s Division Director, ADOT ISO and ADOT CIO, 
4.1.3 Be managed and tracked by the ADOT ISO,  
4.1.4 Not exceed one year in duration, and  
4.1.5 Be treated as confidential information, not to be shared or published. 
.

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 2 of 10      
 
ITM-20.01 
 
5. ROLES AND RESPONSIBILITIES 
5.1 
ADOT Director shall: 
5.1.1 Be responsible for the correct and thorough completion of ADOT IT PSPs within the 
agency; 
5.1.2 Ensure compliance with policy; and 
5.1.3 Promote efforts within the agency to establish and maintain effective use of agency 
information systems and assets. 
5.2 
ADOT Chief Information Officer (CIO) shall:  
5.2.1 Work with the ADOT Director to ensure the correct and thorough completion of agency 
IT  PSPs within the agency; and 
5.2.2 Ensure all IT policies are periodically reviewed and updated to reflect changes in 
requirements. 
5.3 
ADOT Information Security Officer (ISO) shall: 
5.3.1 Advise the ADOT CIO on the completeness and adequacy of the agency activities and 
documentation provided to ensure compliance with agency IT PSPs; 
5.3.2 Ensure the development and implementation of an adequate controls enforcing the IT 
policies for the agency information systems; and 
5.3.3 Ensure all personnel understand their responsibilities with respect to this and all IT 
policies. 
6. ADOT POLICY  
6.1 
Access Agreements – ADOT Chief Information Officer (CIO) shall ensure that individuals 
requiring access to organizational information and ADOT information systems acknowledge 
and accept appropriate legal agreements (e.g., Data Sharing, Acceptable Use, Non-Disclosure) 
prior to being granted access and shall update the access agreements annually. [NIST 800-53 
PS-6] [PCI DSS 12.3]. 
6.1.1 Assign Responsibility to Provide Policy - ADOT CIO shall assign responsibility to a 
department, role, or named individual to provide acceptable use and other related 
information security policies to employees and contractors.

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 3 of 10      
 
ITM-20.01 
 
6.1.2 Assign Responsibility to Keep Records - ADOT CIO shall assign responsibility to a 
department, role, or named individual to keep records of distributed, acknowledged, and 
accepted acceptable use policies for employees and contractors. 
6.2 
Access Agreement Contents - Acceptable Use Agreements contain the following policy 
sections and statements: 
6.2.1 Expected Behaviors - The following behaviors are required: 
6.2.1.1 
Practice Safe Computing 
6.2.1.1.1 
Those accessing ADOT information systems shall use caution and 
exercise good security practices to ensure the protection of ADOT 
information systems and data, including, but not limited to: 
6.2.1.1.1.1 
Opening Attachments or Links - Use caution when opening email 
attachments or following hypertext links received from unknown 
senders. 
6.2.1.1.1.2 
Keep Passwords Secure - Select strong passwords, do not write them 
down, change them frequently, and do not share them with anyone. 
6.2.1.1.1.3 
Keep Desk and Workstation Secure - Use available operating system 
functions to lock the workstation when away from the desk. At the 
end of the day, log out of the computer, but leave the equipment 
powered on. 
6.2.1.1.1.4 
Challenge Unauthorized Personnel - Assist in enforcing physical access 
controls by challenging unauthorized personnel who may not be 
following procedures for visitor sign-in, appropriate badge use, escort 
control, and/or entry. 
6.2.1.1.1.5 
Report Security or Privacy Weaknesses or Violations - Report any 
weaknesses in computer security or data privacy, suspicious behavior 
of others and any incidents of possible misuse or violation of this 
policy to the agency ISO. 
6.2.1.2 
Protect Confidential Information - Confidential information shall be protected 
in accordance with applicable statutes, rules, policies, standards, and 
procedures. Those accessing ADOT information systems shall protect 
confidential information in accordance with the Data Classification Policy (ITM-
12.01). Specifically, the following: 
6.2.1.2.1 
Unencrypted Confidential Information - Confidential information sent 
over email or other electronic messaging without adequate 
encryption shall be prohibited (even to an authorized user).

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 4 of 10      
 
ITM-20.01 
 
6.2.1.2.2 
Storage of Confidential Information - Confidential information must 
be stored in accordance with the ITM-16.01, Media Protection Policy.  
6.2.1.2.3 
Electronic Transmission of Confidential Information - Confidential 
information that is transmitted outside of ADOT information systems 
or on any medium that can be accessed by authorized users shall be 
encrypted through link or end-to-end encryption with an encryption 
algorithm and key length in accordance with ITM-15.01 System and 
Communication Protection Policy. 
6.2.2 
Prohibited Behaviors 
6.2.2.1 
The following behaviors shall be prohibited: 
6.2.2.1.1 
Computer 
Tampering 
- 
Unauthorized 
access, 
interception, 
modification or destruction of any computer, computer system, 
ADOT information systems, computer programs or data; [ARS 13-
2316.1-2] 
6.2.2.1.2 
Use of Unauthorized Computing Equipment - Installation or 
connections of any computing equipment not provided or authorized 
by the ADOT CIO to ADOT information systems; 
6.2.2.1.3 
Use of Unauthorized Software - Installation or use of any 
unauthorized software, including but not limited to security testing, 
monitoring, encryption, or “hacking” software on ADOT computing 
resources; [NIST 800 53 CM-11] 
6.2.2.1.4 
Unauthorized Use of Software or Services - Use of peer-to-peer file 
sharing technology used for the unauthorized distribution, display, 
performance, or reproduction of copyrighted work; [NIST 800 53 
CM-10] 
6.2.2.1.5 
Introduction of Malware - Knowingly introducing a computer 
contaminant into any computer, computer system or ADOT 
information systems; [ARS 13-2316.3] 
6.2.2.1.6 
System Disruption - Recklessly disrupting or causing the disruption of 
a computer, computer system or ADOT information systems; [ARS 
13-2316.4] 
6.2.2.1.7 
Circumvention of Security Controls - Disabling software, modifying 
configurations, or otherwise circumventing security controls. [ARS 
13-2316] Tampering with physical security measures (e.g., locks, 
cameras) is also prohibited;

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 5 of 10      
 
ITM-20.01 
 
6.2.2.1.8 
False Identity - Falsifying identification information or routing 
information so as to obscure the origins or the identity of the sender, 
or using or assuming any information system or application 
identification other than your own; 
6.2.2.2 
Unauthorized Inappropriate or Unlawful Material - The unauthorized storage, 
transmission, or viewing of any pornography or other offensive, intimidating, 
hostile or otherwise illegal material is forbidden. Except to the extent required 
in conjunction with a bona fide ADOT approved research project or other ADOT 
approved undertaking, an employee of ADOT shall not knowingly use ADOT 
owned or ADOT leased computer equipment to access, download, print or 
store any information infrastructure files or services that depict nudity, sexual 
activity, sexual excitement or ultimate sex acts; [ARS 38-448] [ARS 13-2316.5] 
6.2.2.3 
Unauthorized Use of Electronic Messaging - The following use of electronic 
messaging shall be prohibited: 
6.2.2.3.1 
Spam - Sending of unsolicited commercial emails/electronic 
messages in bulk (identical content to multiple recipients). 
6.2.2.3.2 
Chain Letters - Creating or forwarding chain letters or pyramid 
schemes. 
6.2.2.3.3 
Unprofessional Communications - Unprofessional or un-businesslike 
in appearance or content. 
6.2.2.3.4 
Alter Message Content - Modification or deletion of email/electronic 
messages originating from another person or computer with the 
intent to deceive. 
6.2.2.3.5 
False Identity - Falsifying email/electronic message headers or 
routing information so as to obscure the origins of the 
email/electronic message or the identity of the sender, also known 
as spoofing. 
6.2.2.3.6 
Mask Identity - Unauthorized use of anonymous addresses for 
sending and receiving email/electronic messages. 
6.2.2.3.7 
Auto-Forward to External Accounts - Automatically forwarding 
email/electronic messages sent to an ADOT account to an external 
email/electronic messages without authorization. 
6.2.2.3.8 
Non-ADOT Email Accounts - Unauthorized use of a non-ADOT email 
account for ADOT business.

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 6 of 10      
 
ITM-20.01 
 
6.2.2.3.9 
Unencrypted Confidential Information - Confidential information 
sent over email or other electronic messaging without adequate 
encryption (even to an authorized user). 
6.2.2.3.10 
Misrepresentation of ADOT - Presenting viewpoints or positions not 
held by ADOT as those of ADOT or attributing them to ADOT. 
6.2.2.3.11 
Using without benefit for the state any streaming audio or video 
transmission that could cause congestion, delay, or disruption of 
service to any state system or equipment. For example "Push" 
technology, video, sound or other large file attachments. 
  
6.2.2.3.12 
Connecting non-ADOT or personal electronic equipment to ADOT 
networks or technology resources except for approved remote 
access.  Using non-ADOT or personal electronic equipment to store 
or transmit state data or information.  Exemption requests need to 
be submitted through the ADOT Service Desk by emailing 
atg@azdot.gov or calling 602-712-7249.   
 
6.2.2.3.13 
Using ADOT’s electronic equipment as a platform to gain 
unauthorized access to other systems or equipment. 
 
6.2.2.3.14 
Creating, copying, transmitting, or re-transmitting chain letters or 
other unauthorized mass mailings regardless of the subject matter. 
 
6.2.2.3.15 
Posting, storing, sending, transmitting, or disseminating any 
information or material which could be deemed defamatory, false, 
abusive, obscene, pornographic, profane, sexually oriented, 
threatening, racially offensive, or otherwise biased, discriminatory, 
or violates or infringes on the rights of any other person. 
 
6.2.2.3.16 
Creating, downloading, viewing, storing, copying, printing or 
transmitting sexually explicit or sexually oriented materials. 
 
6.2.2.3.17 
Creating, downloading, viewing, storing, copying, printing or 
transmitting materials related to gambling, weapons or terrorist 
activities. 
 
6.2.2.3.18 
Engaging in any outside fund-raising activity, endorsing any product 
or service, participating in any lobbying activity, or engaging in any 
prohibited partisan political activity. 
 
6.2.2.3.19 
Acquiring, using, reproducing, transmitting, or distributing any 
unauthorized controlled information including computer software 
and data, personally identifying information, privacy information, 
copyrighted, trademarked or material with other intellectual 
property rights (beyond fair use), proprietary data, or exporting  
controlled software or data.

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 7 of 10      
 
ITM-20.01 
 
6.2.2.3.20 
Storing, sending or transmitting any personal identifying information 
(PII) in an unencrypted form. 
 
6.2.2.3.21 
Engaging in conduct that would constitute a criminal offense, give 
rise to civil liability, or otherwise violate any local, state, federal law, 
order or regulation. 
 
6.2.2.3.22 
Using or distributing tools designed for compromising security, such 
as password guessing programs, decoders, password gatherers, 
unauthorized keystroke loggers, analyzers, cracking tools, packet 
sniffers, encryption circumvention devices, or Trojan Horse 
programs.  Unauthorized port scanning, for any reason, is prohibited. 
 
6.2.2.3.23 
Accessing any other person's computer or computer system, 
software, or data; or attempting to circumvent the user 
authentication or security of any host, network, or account. This 
includes, but is not limited to, accessing data not intended for you, 
logging into or making use of a server or account you are not 
expressly authorized to access, or probing the security of other 
hosts, networks, or accounts. 
 
6.2.2.3.24 
Using text features (texting) or video call capabilities on Mobile 
Communication 
Devices 
(MCD) 
while 
operating 
motorized 
equipment. 
 
6.2.2.3.25 
Recording meetings or conversations without prior consent of all 
participants of the meeting or conversation. This provision does not 
apply to investigations authorized by the ADOT Director or ADOT 
operations 
to 
conduct 
formal 
administrative 
or 
criminal 
investigations, such as Employee Relations, the Civil Rights Office, 
and the Office of Inspector General. 
6.2.2.4 
INCIDENTAL USE Incidental use means non job-related use (i.e., personal use). 
Incidental use of the Department’s Internet access is permitted, but should be 
restrained and limited to the extent it cannot reasonably be accomplished 
outside normal work hours without using state owned information technology 
resources. Reasonable use is allowed, but should only occur before and after 
normal work hours or during the lunch period. However, it is prohibited if it:  
6.2.2.4.1 
Interferes with the user’s productivity or work performance, or with any 
other user’s productivity or work performance.  
6.2.2.4.2 
Adversely affects the efficient operation of the Department’s information 
resources.  
6.2.2.4.3 
Creates additional cost to the Department.  
6.2.2.4.4 
Brings discredit or embarrassment to the Department.

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 8 of 10      
 
ITM-20.01 
 
6.2.2.4.5 
Involves performing work for profit or results in personal gain.  
6.2.2.4.6 
Otherwise violates any local, state or federal law or regulation. 
6.2.2.5 
Violation of Intellectual Property Laws - Unauthorized receipt, use or 
distribution of unlicensed software, copyrighted materials, or communications 
of proprietary information or trade secrets. 
6.2.2.6 
Unauthorized Access of Confidential Information - Unauthorized access of 
information that has been classified as Confidential could cause harm to the 
state and/or the citizens of the state. The Confidentiality of information is 
protected by law. The unauthorized access of any confidential information is 
prohibited. [ARS 13-2316.07]  
6.2.2.7 
Unauthorized Release of Confidential Information - Disclosure of information 
that has been classified as Confidential could cause harm to the state and/or 
the citizens of the state. The Confidentiality of information is protected by law. 
The unauthorized release or disclosure of any confidential information is 
prohibited. [ARS 36-342] [ARS 36-666] [ARS 41-151.12] [ARS 41-1750.01] 
6.2.2.8 
User responsibilities: 
6.2.2.8.1 
Deleting all content (emails, files, etc.) that is not essential from 
mobile electronic equipment. 
 
6.2.2.8.2 
Using hands free cell phone devices when operating a vehicle for 
state business.  
 
6.2.2.8.3 
Ensuring data is stored regularly on Department servers (such as U:\ 
or G:\ drives) in case the mobile electronic equipment is lost, 
damaged, or unrecoverable. 
 
6.2.2.8.4 
Reporting lost or stolen mobile electronic equipment to 
security@azdot.gov. 
 
  
1. 
Cell Phone – The loss or theft of the cell phone shall be 
immediately reported to the appropriate supervisor.  The 
supervisor shall ensure the cell phone provider is contacted so 
that service on the device is canceled. 
 
2. 
Laptop – The loss or theft of these devices shall be 
immediately reported to the appropriate supervisor, ITG and 
law enforcement.  Notify ITG by emailing security@azdot.gov.  
Notify Risk Management by completing the Property Loss 
Report, then submit it to propertyloss@azdot.gov  
 
3. 
USB flash drive and other data storage devices – The loss or 
theft of these devices shall be immediately reported to the

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 9 of 10      
 
ITM-20.01 
 
appropriate supervisor and ITG.  Notify ITG by emailing 
security@azdot.gov. 
 
6.2.2.8.5 
Contacting the ADOT Service Desk by emailing atg@azdot.gov or 
calling 602-712-7249 for deactivation of an electronic device. 
6.2.3 
Notifications 
and 
Acknowledgements 
- 
The 
following 
notifications 
and 
acknowledgements shall be used to inform those granted access to ADOT information 
systems of controls used to ensure the security of ADOT information systems: 
6.2.3.1 
User Responsibility Acknowledgement - All users review and acknowledge their 
understanding of this policy and other related information security policies on 
an annual basis; [PCI DSS 12.6.2] 
6.2.3.2 
Assets and Intellectual Property - All ADOT information system assets remain 
the sole property of ADOT. Any data or intellectual property created by the 
user, including voicemail and electronic messages, shall remain the property of 
the ADOT and shall not be removed, copied or shared with any person or entity 
except as part of the user’s normal job responsibilities; 
6.2.3.3 
Monitoring - ADOT reserves the right to monitor all activities that occur on its 
ADOT information systems or to access any data residing on its systems or 
assets at any time without further notice; 
6.2.3.4 
Potential Blocking of Inappropriate Content - ADOT may block access to web 
content it deems as inappropriate and filter email destined for a user’s mailbox; 
6.2.3.5 
Incomplete Blocking of Inappropriate Content - ADOT shall not be responsible 
for material viewed or downloaded by users from the Internet or messages 
delivered to a user’s mailbox. Users are cautioned that many Internet pages 
and emails include offensive, sexually explicit, and inappropriate material. Even 
though ADOT intends to filter and block inappropriate content and messages, it 
is not always possible to avoid it; 
6.2.3.6 
No Expectation of Privacy - Users shall have no expectation of privacy for any 
communication or data created, stored, sent, or received on ADOT information 
systems and assets; and 
6.2.3.7 
User Acknowledgement - By using ADOT information systems, users shall 
acknowledge they explicitly consent to the monitoring of such use and the right 
of ADOT to conduct such monitoring. 
6.3 
Business Use:  
State owned information technology resources, including electronic equipment, are 
furnished by ADOT for use in conducting state business.  ADOT does not allow improper use 
of its electronic equipment.  Improper use shall result in disciplinary action up to and

Effective:  January 31, 2022                                                                                            Review:  January 31, 2024 
Supersedes:  ITM-20.01 (4/23/21)                                                                                                       Page 10 of 10     
 
ITM-20.01 
 
including termination of employment.  In addition, improper use may result in the initiation 
of legal action (civil or criminal), or notifying appropriate law enforcement authorities for 
further action. 
6.4 
Consequences for Non-compliance - Users of ADOT information systems who fail to comply 
with established information security and privacy policies and procedures may be subject to 
disciplinary action, including referral to law enforcement for appropriate action.  [NIST 80053 
PS-8] [HIPAA 164.308(a)(1)(ii)(C)] [HIPAA 164.530(e)(1), (2)] [State Personnel System (SPS) 
Rule R2-5A-501] 
7. DEFINITIONS AND ABBREVIATIONS 
7.1 
Refer to the IT Glossary of Terms located on the ADOA-ASET website. 
8. REFERENCES 
8.1 
NIST 800-53, Recommended Security Controls for Federal Information Systems and 
Organizations 
 
8.2 
HIPAA Administrative Simplification Regulation, Security and Privacy, CFR 45 Part 164 
 
8.3 
IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local 
Agencies 
 
8.4 
Payment Card Industry Data Security Standard (PCI DSS), PCI Security Standards Council 
9. ATTACHMENTS 
None. 
10. REVISION HISTORY 
 
Date 
Revision 
Change 
Approver 
06/28/2019 
1.0 
Initial Draft 
Thomas Branham 
01/06/2022 
2.0 
Combined ITM-5.01 Electronic 
Equipment Policy with this Policy (ITM-
20.01 Acceptable Use) 
Thomas Branham, ADOT 
Infrastructure Protection 
Manager (Cyber Security and 
Privacy Officer)