4126 Acceptable Use of Technology and Data Procedure 

Policy Details 

Policy Name: Acceptable Use of Technology and Data

Policy Number: 4126  

Applicable Code/Law: RCW 42.52.160, WAC 292.110.010, RCW 40.14; RCW 42.17.260  

Account Access and Acceptable Use Procedure 

Purpose   

The purpose of this procedure is to establish clear guidelines for the access and acceptable use of Shoreline College's technology, communications resources, and services. This procedure aims to ensure the integrity, security, and proper utilization of these resources while supporting the educational and operational needs of the college. It outlines the expectations for privacy, acceptable and unacceptable use, account access, and the responsibilities of users to protect sensitive information and comply with relevant laws and policies. By adhering to these guidelines, users contribute to a secure and efficient technological environment that facilitates the college's mission and goals.   

Definitions   

Technology, Communications Resources, and Communication Services - Any hardware, software, or services implemented to support campus functions or operations. These resources and services include, but are not limited to:   

  • Client workstations, laptops, or mobile devices   
  • Server hardware, network storage, and share provisioning   
  • Audio, video, or other multimedia hardware and software   
  • Library automation and assistive devices   
  • All data and communications networks, network infrastructure, and hardware   
  • Operating systems and supporting application packages   
  • All information and data files, electronic correspondence (email, instant messages, voicemail)   
  • Campus or affiliated services internet websites and storage repositories   

Expectations of Privacy   

  • Shoreline College does not grant, implicitly or explicitly, any ownership or expectation of privacy with regards to digital communications (email, texting, voicemail, etc.), computing resources (file shares, information and data files, or campus provided services), or Internet browsing activities.    

Network Services (Internet Accessibility)   

  • These services are provided for the purpose of conducting such business as necessary to complete assigned college related tasks, functions, and responsibilities. Excessive utilization of personal network-based shared service primarily focusing on audio and video streaming services are not permitted unless it is identified and documented as an exception that such services are vital to student development or job completion. Authorized users of these services are bound by college policies and any/all applicable state and federal laws.     
  • Shoreline College’s Technology Support Services (TSS) regularly monitors network traffic to assist in identifying abnormalities or other issues that may impact the integrity of the network and/or access to provided services. Any activity that improperly or inappropriately uses up network bandwidth, interferes with normal campus business operation, or degrades the capacity for student capability to complete their course of studies is considered to be in violation of the acceptable use policy and may result in loss of access privileges and may be subject to other punitive measures. All information and technology resources may be subject to monitoring without prior notification under the following circumstances:   
  • There exists a reasonable need, necessary or appropriate, to protect the integrity, security, or functionality of campus technology resources.   
  • There exists a reasonable need, necessary or appropriate, to maintain compliance with any legal requirements protecting Shoreline College from liability or service disruption.     
  • An account appears to be engaged in unusual or unusually excessive activity.   
  • There exists a reasonable need, necessary or appropriate, to access an account or activity, and the access is reasonable in relation to the need.   

Traffic Monitoring   

  • Shoreline College’s Technology Support Services reserves the right to monitor, inspect, review, or take any action deemed appropriate upon any communications, device, software, data, etc. for the purpose of identifying any non-compliance, illegal, illicit, or malicious traffic or actions.   
  • The results of any such general or individual monitoring, including but not limited to the contents and records of individual communications, may be released pursuant to a public records request. In addition, the College may, at its discretion, disclose the results of any such general or individual monitoring for any legitimate purpose to appropriate and authorized College personnel or law enforcement agencies and may use those results in appropriate external and internal disciplinary and other proceedings.    

Rules of Behavior (Acceptable & Unacceptable Use) 

These Rules of Behavior apply to the use of Shoreline-provided IT resources, regardless of the geographic location:    

  • Use of College technology implies consent and acceptance of all policies, procedures, and guidelines and agree to be bound by all regulations therein.   
  • Data and system use must comply with Shoreline policies and standards.   
  • Unauthorized access to data and/or systems is prohibited.   
  • Users must prevent unauthorized disclosure or modification of sensitive information, including Personally Identifiable Information (PII).    

Acceptable Use  

Users shall:   

  • In accordance with college procedures, immediately report all lost, damaged, or stolen equipment, known or suspected security incidents, known or suspected security policy violations or compromises, or suspicious activity. Known or suspected security incidents are inclusive of an actual or potential loss of control or compromise, whether intentional or unintentional, of authenticator, password, or sensitive information, including PII, maintained or in possession of the user.   
  • Adhere to all standards and accessibility requirements as established by Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPPA), Children’s Online Privacy Protection Act (COPPA); any applicable policies and procedures set forth by SBCTC, and any applicable Shoreline College policies and procedures established concerning access, use, and/or release of an individual’s information. In accordance with law, the College will make every reasonable effort to ensure and maintain the confidentiality of sensitive data and communications.   
  • Ensure that software, including downloaded software, is properly licensed, free of malicious code, and authorized before installing and using it on college-owned systems.   
  • Log off or lock systems when leaving them unattended.   
  • Complete security awareness training before accessing any system and on an annual basis thereafter. Permit only authorized users to use college-provided systems.   
  • Secure sensitive information (on paper and in electronic formats) when left unattended.   
  • Keep sensitive information out of sight when visitors are present.   
  • Sanitize or destroy electronic media and papers that contain sensitive data when no longer needed, in accordance with college records management and sanitization policies, or as otherwise directed by management.   
  • Only access sensitive information necessary to perform job functions (e.g., need to know).   
  • Use PII only for the purposes for which it was collected, to include conditions set forth by stated privacy notices and published notices.   
  • Ensure the accuracy, relevance, timeliness, and completeness of PII, as is reasonably necessary.   

Prohibited Use   

Users shall not:   

  • Direct or encourage others to violate college policies, procedures, standards or guidelines.   
  • Circumvent security safeguards or reconfigure systems except as authorized (e.g., violation of least privilege).   
  • Use another user’s account, identity, or password.   
  • Share individual account passwords, access levels, and/or any IT assets.     
  • Exceed authorized access to sensitive information.   
  • Cause congestion, delay, or disruption of service to any college-owned IT resource. For example, greeting cards, video, sound or other large file attachments can degrade the performance of the entire network, as do some uses of “push” technology, such as audio and video streaming from the Internet.   
  • Create, download, view, store, copy or transmit materials related to sexually explicit or sexually oriented materials.   
  • Create, download, view, store, copy or transmit materials related to gambling, illegal weapons, terrorist activities, illegal activities or activities otherwise prohibited.   
  • Store sensitive information in public folders or other insecure physical or electronic storage locations.   
  • Store college owned data on unauthorized cloud storage systems.   
  • Share sensitive information, except as authorized and with formal agreements that ensure third parties will adequately protect it.      
  • Transport, transfer, email, remotely access, or download sensitive information, inclusive of PII, unless such action is explicitly permitted by the manager or owner of such information.   
  • Store sensitive information on mobile devices such as laptops, smartphones, USB flash drives, or on remote systems without authorization or appropriate safeguards, as stipulated by college policies.   
  • Knowingly or willingly conceal, remove, mutilate, obliterate, falsify, or destroy information for personal use for self or others.    
  • Use college-provided IT resources for commercial purposes or in support of “for-profit” activities or in support of other outside employment or business activity (e.g., such as consulting for pay, administration of business transactions, the sale of goods or services, etc.).   
  • Engage in any outside fund-raising activity, including non-profit activities, endorsing any product or service, participating in any lobbying activity, or engaging in any prohibited partisan political activity;   
  • Establish unauthorized personal, commercial or non-profit organizational web pages on college-provided systems.   
  • Use college-owned IT resources as a staging ground or platform to gain unauthorized access to other systems.   
  • Create, copy, transmit, or retransmit chain letters or other unauthorized mass mailings regardless of the subject matter.   
  • Use college-owned IT resources for activities that are inappropriate or offensive to fellow employees or the public. Such activities include, but are not limited to hate speech, harassment, bullying, intimidation or other abusive conduct that ridicules others on the basis of race, creed, religion, color, age, sex, disability, national origin, or sexual orientation.   
  • Add personal IT resources to existing college-owned systems without the appropriate management authorization, including the installation of modems on data lines and reconfiguration of systems.   
  • Intentionally acquire, use, reproduce, transmit, or distribute any controlled information including computer software and data that includes information subject to the Privacy Act, copyrighted, trademarked or material with other intellectual property rights (beyond fair use), proprietary data, or export-controlled software or data.   
  • Send anonymous messages.   
  • Remove college provided IT resources from college property without prior management authorization.   
  • Modify software without management approval.   
  • Post information on external blogs, social networking sites, newsgroups, bulletin boards or other public forums which are:   
  • Derogatory to Shoreline or its management;   
  • Contrary to Shoreline’s mission or stated positions; or   
  • Brings discredit or embarrassment to Shoreline.   

Additional Rules for Security & Privileged Users  

Security and system administration personnel with elevated privileges have significant access to processes and data in systems. As such, Security, Network, Systems, and Database Administrators have added responsibilities to ensure the secure operation of any Shoreline system.   

Personnel with elevated privileges are to:   

  • Advise the asset owner on matters concerning cybersecurity.    
  • Assist the asset owner in developing security plans, risk assessments, and supporting documentation for the certification and accreditation process.    
  • Ensure that any changes to any system that affect contingency and disaster recovery plans are conveyed to the asset custodian responsible for maintaining continuity of operations plans for that system.    
  • Ensure that adequate physical and technical safeguards are operational within their areas of responsibility and that access to information and data is restricted to authorized personnel on a need-to-know basis.    
  • Implement applicable security access procedures and mechanisms, incorporate appropriate levels of system auditing, and review audit logs.    
  • Document and investigate known or suspected security incidents or violations and report them to appropriate management staff.   

Violations  

Any violations of the aforementioned rules of behavior, acceptable use policy, other campus policies, or established campus or technology procedures will be provided to the appropriate agency to be dealt with appropriately.   

Personal Use of College IT Assets 

Utilizing principles outlined in RCW 42.52.160 and WAC 292-110-010, de minimus use of the College’s technology and communications resources and services may allow authorized users to use college-owned IT resources for non-official purposes when such use involves no additional expense to the college, is performed on the employee’s non-work time, does not interfere with the mission or operations of the college, and does not violate the ethical conduct or Rules of Behavior.   

Managers may adopt more restrictive personal use policies or existing labor management agreements may preclude one or more of the personal use guidelines listed below:   

  • Any use of college-provided IT resources, including e-mail, is made with the understanding that such use may not be secure, is not private, is not anonymous and may be subject to monitoring. Users do not have a right to, nor shall they have an expectation of, privacy while using college-provided IT resources at any time, including accessing the Internet through college-provided connectivity. To the extent that users wish that their private activities remain private, they shall avoid making personal use of college-provided IT resources.   
  • Employees have no inherent right to utilize college-provided IT resources for personal use.   
  • Unauthorized or inappropriate use of college-provided IT resources could result in loss of use or limitations on use of equipment, disciplinary or adverse actions, criminal penalties and/or employees or other users being held financially liable for the cost of inappropriate use.   
  • Users are permitted limited personal use of college-provided IT resources. This personal use shall not result in loss of employee productivity, interference with official duties or other than “minimal additional expense” to the college in areas such as:   
  • Communications costs for voice, data, or video image transmission;   
  • Use of consumables in limited amounts (e.g., paper, ink, and toner);   
  • General wear and tear on equipment;   
  • Data storage on local storage devices; and   
  • Transmission impacts with moderate e-mail message sizes, such as e-mails with small attachments.   
  • Employees are expected to conduct themselves professionally in the workplace and to refrain from using college-provided IT resources for activities that are inappropriate.    
  • Departments may adopt policies that are more restrictive than these guidelines.   
  • Future labor management agreements shall comply with this policy.   

Use of Personal Devices on College Network 

The college permits the use of personal devices (e.g., smartphones, tablets, laptops) on its network to enhance flexibility and convenience for students, faculty, and staff. However, this practice introduces potential risks to data security and network integrity. This section outlines the requirements and best practices for using personal devices on the college network.   

  • Security Updates: It is recommended personal devices run operating systems that receive regular security updates. Automatic updates should be enabled to ensure devices remain secure.   
  • Sensitive Data: The storage of sensitive college data is prohibited on personal devices.    
  • All work-related college data should be stored on college approved storage platforms.    
  • Multi-Factor Authentication (MFA): Access to college systems and data must be protected by MFA. Users should set up MFA on their personal devices using college approved methods to enhance security.   
  • Incident Reporting: If a personal device containing college data is lost or stolen, the incident must be reported immediately to the Technology Support Services department.   
  • Data Deletion: The college reserves the right to request the deletion of any college data stored on personal devices. Users must securely delete college data before transferring ownership or disposing of their devices.   
  • Compliance: Users must comply with all relevant laws, regulations, and college policies regarding data protection and privacy.   

Account Access Request and Approval 

  • Individuals requiring access must have the appropriate paperwork submitted by the supervisor/representative to the Human Resources department for processing and approval.    
  • Once approved, the individual’s information is entered to begin the automated onboarding processes.     

Account Creation 

  • Shoreline accounts are created 3 days prior to the start date entered for the individual.   
  • In the event the individual’s information was entered after 3 days before the start date, the Shoreline account will be created during the next process run.    
  • Each process run is performed overnight.    
  • Previous employees returning to Shoreline are created as new accounts. Previous access rights and information will require approval via appropriate channels.    

Account Login, Passwords, and Multifactor Authentication 

  • Notifications: Appropriate notifications are sent out once the new individual account is created.    
  • Supervisors and/or designated staff will receive an email notification for account creation with the new username and instructions for additional access requirements.    
  • New Employee will receive two separate email notifications to their preferred email address entered into ctcLink: one with the username information; and another with a one-time temporary password.    
  • Upon first login, the individual must change their temporary password to a secure, unique password.   
  • Multifactor authentication is required to enhance account security. This should be set up at the time of first login.    

Account Review and Auditing 

  • Technology Support Services, with the assistance of other authorized staff, conducts regular reviews of account access to ensure accuracy and integrity of appropriate access permissions.    

Account Deactivation 

  • To ensure proper security compliance, supervisors or the department representative  must  inform the Human Resources department of a pending separation as soon as the separation date is known.    
  • The offboarding process is triggered by the termination date entered by the Human Resources department in the college HCM system.    
  • Special situations for immediate terminations should communicate directly with the Human Resources department with all necessary information.    
  • Human Resources will communicate the immediate termination to Technology Support Services (TSS) to initiate the immediate account deactivation process.   
  • Employees cannot have an active job record in the system if they are not actively working at the college. Separations greater than 45 days require an offboarding of the employee to remain in compliance with applicable governance processes.    

Approvals 

Procedures Adopted: 5/14/01  

Procedures Revised by ET: 6/18/19 

Reviewed and Approved by Executive Team: 07/21/2026