Acceptable Technology Use Policy
The purpose of the acceptable use policy (AUP) is to define the standards and expectations for the responsible, ethical, and legal use of Butler University’s information technology resources. This policy aims to protect the security and integrity of technology systems, ensure compliance with all relevant laws and regulations, and promote a safe and productive environment for all users. By adhering to the AUP, users contribute to the overall effectiveness and security of Butler’s IT infrastructure.
This policy applies to all users of university technology and associated services including but not limited to faculty, staff, students (current, prospective, and former), affiliates, contractors, vendors, and volunteers.
This policy does not alter or supersede individuals’ or the University’s rights or obligations to comply with applicable federal and state laws or regulations governing the use and privacy of information, including:
- Family Educational Rights and Privacy Act (FERPA),
- Gramm-Leach- Bliley Act (GLBA),
- Health Insurance Portability and Accountability Act of 1996 (HIPAA), and
- Payment Card Industry Data Security Standard (PCI-DSS).
- Fair & appropriate use cases of Butler technology resources include:
- Supporting the mission of the University: teaching/learning, creative activities, research, or engaging Butler constituents
- Supporting studies, instruction, duties as employees, official University business, and University sanctioned activities
- Incidental personal use
- Individuals covered by this policy must:
- Comply with all University rules and policies
- Comply with all federal, Indiana, and other applicable laws and all applicable contracts and licenses. Users must use institutional information technology resources only for lawful purposes, and not for any purpose that is illegal, immoral, unethical, dishonest, damaging to the reputation of the University, inconsistent with the mission and values of the University, or likely to subject the University to harm.
- Use only those information technology resources they are authorized for use and use them only in the manner and to the extent authorized.
- Observe the privacy of other users and their accounts, regardless of whether those accounts are securely protected. Accounts, passwords, and access to University information technology resources may not, under any circumstances, be shared with, transferred to, or used by, persons other than those to whom they have been assigned by the University.
- Respect the finite capacity of information technology resources and limit use to the extent needed for authorized activities, so as not to consume an unreasonable amount of those resources or to interfere unreasonably with the activity of other users.
- The University may require users of information technology resources to limit or refrain from specific uses in accordance with this principle. The University will judge the reasonableness of any particular use in the context of all of the relevant circumstances.
- Comply with the law with respect to the rights of copyright owners in the use, distribution, or reproduction of copyrighted materials.
- The University is also required by law to investigate claims of possible copyright infringement taking place through its computer networks. Internal University sanctions for unauthorized use or distribution of copyrighted material range from warnings to the loss of privilege to use University information technology resources.
- Store university data only in University-approved secure locations and handle data according to the university Data Policy.
- Promptly report any confirmed or suspected security incidents to the Information Technology department.
- Subject to the Privacy of Personally Created Content Policy, the University reserves the right to inspect any activities or accounts of individual users of University information technology resources, including individual login sessions and communications, without notice, unless otherwise prohibited by law. The University may inspect such information technology resources under circumstances when the University determines inspection is necessary, including but not limited to the following:
- To protect the integrity, security, or functionality of University or other information technology resources, or to protect the University from harm;
- There is reasonable cause to believe that the user has violated, or is violating, any Butler policy or applicable civil or criminal law; or
- An information technology resource appears to be engaged in unusual or unusually excessive activity, as indicated by monitoring of general activity and usage patterns.
- The University, in its discretion, may use or disclose the results of any such inspection, including the contents and records of individual communications, as it considers appropriate to University personnel, third parties, or law enforcement agencies.
- Individuals covered by this policy must not:
- Use information technology resources for commercial or personal purposes, for personal financial gain (except as part of a class sponsored activity), or as primary computer systems for an outside organization.
- The University permits occasional non-commercial personal use of Butler’s information technology resources. Such use should not consume a significant amount of those resources, interfere with job performance or other University responsibilities, interfere with the efficient operation of the University or its information technology resources, and must be otherwise in compliance with this Policy.
- The University assumes no responsibility for the loss or recovery of personal files.
- Exception may be made where approval has been granted from college/division leadership and Information Technology and applicable accounts obtained in advance.
- Use University resources to post, view, print, store, or send obscene, pornographic, sexually explicit, or offensive material, except for officially approved, legitimate academic or University purposes.
- Circumvent security measures at Butler or on other networks.
- Engage in any activity intended to cause harm to University systems or data, information, or files contained therein.
- Impersonate others.