5030 Student Account Access and Acceptable Use Procedure
Procedure:
Policy Name: Student Account Access and Acceptable Use
Policy Number: 5030 (Student Conduct)
Applicable Code/Law: N/A
Purpose
This policy establishes clear guidelines for student access and acceptable use of Shoreline College’s technology, communications resources, and services. It ensures the integrity, security, and proper utilization of these resources while supporting students’ academic success and personal development.
Definitions
Technology, Communications Resources, and Communication Services - Any hardware, software, or services implemented to support campus functions or operations. These resources and services include, but are not limited to:
- College-provided computers, tablets, and mobile devices
- Server hardware, network storage, and share provisioning
- Audio, video, or other multimedia hardware and software
- Library automation and assistive devices
- All data and communications networks, network infrastructure, and hardware
- All information and data files, electronic correspondence
- Campus or affiliated services internet websites and storage repositories
Expectations of Privacy
- Shoreline College provides students with means and access to technological resources for educational purposes. All provided resources used for educational advancement housed, accessed, and/or maintained on college owned resources are provided with no implied expectation of privacy.
Network Services (Internet Accessibility)
- Internet access is provided to support academic activities.
- Excessive use of bandwidth for non-academic streaming or downloads may be restricted.
- Network traffic may be monitored to maintain performance and security.
Traffic Monitoring
- Shoreline College’s Technology Support Services reserves the right to monitor, inspect, review, or take any action deemed appropriate upon any communications, device, software, data, etc. for the purpose of identifying any non-compliance, illegal, illicit, or malicious traffic or actions.
- The results of any such general or individual monitoring, including but not limited to the contents and records of individual communications, may disclose the results of any such general or individual monitoring for any legitimate purpose to appropriate and authorized College personnel or law enforcement agencies and may use those results in appropriate external and internal disciplinary and other proceedings.
Rules of Behavior (Acceptable & Unacceptable Use)
These Rules of Behavior apply to the use of Shoreline-provided IT resources, regardless of the geographic location:
- Use of College technology implies consent and acceptance of all policies, procedures, and guidelines and agree to be bound by all regulations therein.
- Data and system use must comply with Shoreline policies and standards.
- Unauthorized access to data and/or systems is prohibited.
- Users must prevent unauthorized disclosure or modification of sensitive information, including Personally Identifiable Information (PII).
Acceptable Use
Users shall:
- In accordance with college procedures, immediately report all lost, damaged, or stolen equipment, known or suspected security incidents, known or suspected security policy violations or compromises, or suspicious activity. Known or suspected security incidents are inclusive of an actual or potential loss of control or compromise, whether intentional or unintentional, of authenticator, password, or sensitive information, including PII, maintained or in possession of the user.
- Adhere to all standards and accessibility requirements as established by Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPPA), Children’s Online Privacy Protection Act (COPPA); any applicable policies and procedures set forth by SBCTC, and any applicable Shoreline Community College policies and procedures established concerning access, use, and/or release of an individual’s information. In accordance with law, the College will make every reasonable effort to ensure and maintain the confidentiality of sensitive data and communications.
- Ensure the use of only authorized, licenses, and malicious code free software and services on college-owned systems.
- Log off or lock systems when leaving them unattended.
- Secure sensitive information (on paper and in electronic formats) when left unattended.
- Receive support from designated college personnel to help with account access, setup, and technical issues.
- Receive reasonable accommodations and support services to promote inclusive access to technology and account related services.
- Use college systems only for academic and authorized purposes.
Prohibited Use on College Provided/Owned IT Resources
Users shall not:
- Direct or encourage others to violate college policies, procedures, standards, or guidelines.
- Circumvent security safeguards, reconfigure systems or attempt unauthorized access.
- Use another user’s account, identity, or password.
- Share individual account passwords, access levels, and/or any IT assets.
- Cause congestion, delay, or disruption of service to any college-owned IT resource. For example, greeting cards, video, sound or other large file attachments can degrade the performance of the entire network, as do some uses of “push” technology, such as audio and video streaming from the Internet.
- Misuse IT resources to cheat, plagiarize, or violate academic integrity policies.
- Unless for approved course assignments only with prior written approval from course instructor:
- Create, download, view, store, copy or transmit materials related to sexually explicit or sexually oriented materials.
- Create, download, view, store, copy or transmit materials related to gambling, illegal weapons, terrorist activities, illegal activities or activities otherwise prohibited.
- Store sensitive information in public folders or other insecure physical or electronic storage locations.
- Use college-provided/owned IT resources for commercial purposes or in support of “for-profit” activities or in support of other outside employment or business activity (e.g., such as consulting for pay, administration of business transactions, the sale of goods or services, etc.).
- Use college-provided/owned IT resources to engage in any outside fund-raising activity, including non-profit activities, endorsing any product or service, participating in any lobbying activity, or engaging in any prohibited partisan political activity;
- Establish unauthorized personal, commercial, or non-profit organizational web pages on college-provided systems.
- Use college-provided/owned IT resources as a staging ground or platform to disrupt services or gain unauthorized access to other systems.
- Create, copy, transmit, or retransmit chain letters or other unauthorized mass mailings regardless of the subject matter.
- Use college-provided/owned IT resources for activities that are inappropriate or offensive to fellow students or the public. Such activities include, but are not limited to hate speech, harassment, bullying, intimidation or other abusive conduct that ridicules others on the basis of race, creed, religion, color, age, sex, disability, national origin, sexual orientation or other protected status.
- Add personal IT resources to existing college-owned systems, including the installation of modems on data lines and reconfiguration of systems.
- Intentionally acquire, use, reproduce, transmit, or distribute any controlled information including computer software and data that includes information subject to the Privacy Act, copyrighted, trademarked or material with other intellectual property rights (beyond fair use), proprietary data, or export-controlled software or data.
- Send anonymous messages.
- Remove college provided IT resources from college property without prior authorization.
Use of Personal Devices on College Network
The college permits the use of personal devices (e.g., smartphones, tablets, laptops) on its network to enhance flexibility and convenience for students. However, this practice introduces potential risks to data security and network integrity. This section outlines the requirements and best practices for using personal devices on the college network.
- Security Updates: It is recommended that personal devices run operating systems that receive regular security updates. Automatic updates should be enabled to ensure devices remain secure.
- Multi-Factor Authentication (MFA): Access to college systems and data must be protected by MFA. Users should set up MFA on their personal devices using college approved methods to enhance security.
- Incident Reporting: If a personal device containing college data is lost or stolen, the incident must be reported immediately to the Technology Support Services department.
- Data Deletion: The college reserves the right to request the deletion of any college data stored on personal devices. Users must securely delete college data before transferring ownership or disposing of their devices.
- Compliance: Users must comply with all relevant laws, regulations, and college policies regarding data protection and privacy.
- Creating, Viewing, Downloading, or Transmitting sexually explicit or sexually oriented materials while on campus or while using the campus Wi-Fi is prohibited unless for approved course assignments only with prior written approval from course instructor.
- Create, download, view, store, copy or transmit materials related to gambling, illegal weapons, terrorist activities, illegal activities, or activities otherwise prohibited while on campus or while using the campus Wi-Fi.
Account Access and Creation
- Student accounts are automatically created upon admission. These accounts initially receive limited license access to college resources.
- Full licensed access to college services is granted once a student registers for classes.
- Login credentials are sent to the student’s preferred email address on record. Upon first login, students must change their temporary password to a secure, unique password.
- Password Requirements: Passwords must meet the college's security standards:
- Minimum of 12 characters
- Required: 1 capital letter, 1 number, and 1 special character
- Must not match any of the last 24 passwords
- Multifactor authentication (MFA) is required to enhance account security and should be set up during the initial login.
- Passwords must be reset every 180 days.
Account Review and Auditing
- Technology Support Services (TSS), in collaboration with authorized staff, conducts regular reviews of account access to ensure accuracy and appropriate permission levels.
Account Deactivation
- Student accounts are deactivated upon graduation or extended enrollment inactivity.
- Accounts may also be deactivated immediately due to policy violations or identified security risks.
- Extended enrollment inactivity is no enrollment in undergraduate classes up to the second census date after previous class completion. Accounts will be moved into a grace period for up to four quarters past pervious class completion.
- During the grace period, account access is limited to specific college resources under restricted license terms.
Adopted:
Reviewed and Approved by Executive Team: 02/24/2026