Loading...
HomeMy WebLinkAboutP-0340 - Personal Computer Policy 04-04-1996• • • POLICY FOR INSERTION INTO THE POLICY MANUAL MEETING DATE: April 14, 1988 DATE: April 14, 1988 NUMBER• A:0340 REVISIONS: Reissued April 4, 1.996 POLICY: PERSONAL COMPUTER POLICY (See attached PC Policy distributed by Data Processing Department) • ORANGE COUNTY POLICY GOVERNING THE USE OF PERSONAL COMPUTER EQUIPMENT AND SOFTWARE (THE PC POLICY) April 4, 1996 CONTENTS: SECTION 1. EQUIPMENT 1.1 Purchase of Equipment 1.2 Use Qf Non-County Owned Equipment . 1.3 Repair of Equipment SECTION 2. SOFTWARE 2.1 Purchase of Software 2.2 The County Standard Software 2.3 Use of Non-County Owned Software. 2.4 Software Library SECTION 3. SECURITY 3.1 Departmental Responsibilities 3.2 User responsibility _ 3.3 ,Computer Records SECTION 4. TRAINIl~iG • SECTION 5. VOLUNTEERS 5.1 Volunteers using county-owned equipment 5.2 Volunteer access to confidential information SECTION 6. E-MAIL SECTION 7. INTERNET SECTION~8. POLICY RESPONSIBILITIES • • ORANGE COUNTY POLICY GOVERNING THE USE OF PERSONAL COMPUTER EQUIPMENT AND SOFTWARE (THE PC POLICY) April, 1996 PURPOSE: This policy has been formulated to provide direction to County Employees, Volunteers and any other users as it respects the use of personal computer hardware and software. Violations of the policy governing the use of personal computer hardware and sofhvare (the PC Policy) shall fall under the jurisdiction of the Orange County Personnet Ordinance, Article IX, Appendix 2 and may result in disciplinary action under that Ordinance. All automated systems (E--mail, Internet, etc.) are subject to monitoring and examination by appropriate County officials at any time, Further, this policy assumes the continued collaboration between the Data Processing Department (hereinafter referred to as "DP") and the user department(s) to address future automation needs as they arise. Section 1. EQUIPMENT 1.1 Purchase of Equipment All PC hardware requires review and consensus between DP and the user department prior to it being ordered. Generally, County equipment is purchased on a bid basis. County • Departments shall not contact vendors during the bidding process. Doing so could disqualify the vendor from bidding. The specifications for the equipmenrt are done in collaboration with the DP and the user department director. 1.2 Use of Non-County Owned Equipment . The County assumes no responsibility for non-County owned equipment. This includes, but is not limited to, insurance coverage for non-County owned equipment, maintenance for non- County owned equipment, damages to non-County owned software, etc. This also includes personal equipment used by a volunteer. 1.3 Repair of Equipment Each Department should designate an employee to be the departmental coordinator for equipment repairs. DP will ensure that the designated person receives training regarding various equipment malfunctions in order that the employee can assess the malfunction as quickly and efficiently as possible. The departmental designee will contact DP as deemed necessary. In the event the problem cannot be addressed in a timely manner by the DP staff the outside service provider will be contacted. DP will estimate the time needed for the repair and notify the department. ~J 2 Users shall not attempt to repair equipment unless they are absolutely certain of the problem • diagnosis and repair options. Users shall not contact the outside service provider without the prior approval of DP. Failure to receive prior approval may be deemed an unauthorized expenditure and as such will become the responsibility of the user. Section 2. SOFTWARE 2.1 Purchase of Software All PC software, including specific program applications (eg. Visions, used in Sheriffs Department, App Tracking as used by Personnel) requires review and consensus between DP and the Department prior to it being ordered. 2.2 The County Standard Software At the time of the writing of this policy the County standard is Microsoft Windows, Microsoft Word, Microsoft Access, Microsoft Excel, Microsoft Powerpoint, Crroupwise E-mail, NetScape and Novell Netware. In order to ma_X~m»e limited departmental resources, these are the only software packages that DP presently supports. Departments will be notified as new standards are developed through the Data Processing Advisory Committee. DP may offer additional software support to Departments who are required to use specific program applications. 2.3 Use of Non-County Owned Software. . Any non-County software (including screen savers) installed on County equipment shall first be checked for viruses by DP. The user is subject to disciplinary action for any damage incurred to County owned hardware or software installed on the unit that was not first checked/tested by DP. DP maintains and supports only the software previously identified as the County standard. Should you be in doubt as to the standard, contact DP directly. 2.4 Software Library A software library will be maintained in DP for selected software which falls outside of those previously identified as the County standard (see 2.2) but may have applicability in some departments. While full support cannot be offered for this software, operational instructions are available. In addition, self-paced tutorials for most of the County standard software is available to the employee on a sign-up basis through the Personnel department. Section 3. SECURITY 3.1 Departmental Responsibilities: Each department whose operation requires the handling of confidential information is expected to develop departmental policies and procedures to ensure that this information is protected from loss, damage, alteration or unauthorized use. The following considerations should be observed as these policies and procedures are developed: 3.1.1. Each department is encouraged to have swell-defined process for ensuring that: • a. authorized users have access only to the systems/functions that are necessary to carry out the duties of their position; and b. a written record is maintained of each user who has access to a system/fiinction; and c. passwords/IDs are immediately deleted for any user who leaves employment; and d. passwords/IDs for new users are added; and e. passwords/IDs are changed periodically and when an user's duties change; and 3.1.2 Each department should appoint a primary security officer and a secondary security officer responsible for assigning, deleting passwords/IDs; maintaining the list of users by system/fimction access; keeping users apprised of responsibilities with respect to security policies and other duties as assigned. 3.1.3 Each department should appoint a primary and secondary network coordinator (may be the same person as s security officer) responsible for principle liaison with DP, initial trouble-shooting within the department and other duties as assigned. 3.1.4 Each department is encouraged to provide training on security procedures to all .. users, including at least a yearly reminder of the importance of security. This may be a responsibility of the security officer. 3.1.5 Each de artment should have policies for the checkout and use of portable P equipment such as laptops, portable printers. Only portable equipment is available for checkout and use outside the office. Any exception requires the advance written approval of the Department Head and Information Systems Director with notification to the Purchasing/ Central Services Director. 3.2 User responsibility 3.2.1 Users will not share information obtained through computer access with other individuals and/or agencies unless permitted by policy and law. 3.2.2 Users will use only those systems/functions which they are authorized to use. 3.2.3 Users will ensure that whenever a terminal is not being used, it will be secured to avoid use by unauthorized personnel. 3.2.4 Users will not share their passwords/IDs with others or use another user's password/ID. Users will ensure that their passwordslIDs are not left out in the open where they could be found and used by other individuals. Users who are not authorized for a particular system/fimction will not seek access to that system/fimction through another user. • 4 3.2.5 Users with access to confidential information should sign the Employee Confidentiality Agreement (see Attachment I) and be given a copy of same when it is signed. 3.2.6 Users will keep any portable equipment in a secure place, adhere to the department's checkout procedures, and use the equipment exclusively for County business. 3.2.7 Users will use County equipment for County business only. Personal use of County equipment is prohibited. 3.3 Computer Records Dissemination of records maintained on the computer are subject to the Public Records Law and are disclosed only in accordance with the law. Users unfamiliar with the requirements of the Public Records Law will be expected to seek clarification from a supervisor prior to releasing information. Section 4. TRAINING 4.1 The County recognizes the importance of providing adequate training opportunities to enable employees to fully utilize the computer technology endorsedlpromoted by the organization. It is an expectation that training will occur within 12 months after employees have access to assigned County hazdwaze and softwaze. • 4.2 The following statements establish the requirements and expectations of employees engaged in computer hardware or softwaze training: 4.2.1 Once an employee is enrolled in County sponsored and funded training, mandatory attendance throughout the training is required. Any exceptions must be approved by the employee's Department Head and/or supervisor. 4.2.2 In order to enroll in County sponsored and/or funded training, the employee must have access to the appropriate softwaze packages and hardware. 4.3 Supervisors are responsible for ensuring employees have access to training opportunities for assigned County hazdwaze and softwaze. Presently, training opportunities aze provided through in-house training, self-paced tutorials offered for check out through the Personnel Department and training through outside contractors. Supervisors should consult with the employee to determine their skill level and reach a mutual decision regazding training needs. • 5 Section 5. VOLUNTEERS • 5.1 Volunteers using County-owned equipment Any volunteer using County equipment is expected to adhere to the same rules and regulations for PC use as would a County employee. It should be the responsibility of the Department Head to ensure that the volunteer has sufficient expertise to carry out the assigned work. This is to include the operation of the equipment, including but not limited to, the loading of software, network maintenance, etc. 5.2 Volunteer access to confidential information Access to confidential information by any volunteer will be approved by the department head. Any volunteer with access to confidential information shall be given specific instruction as to the handling of this information. Volunteers will follow the same standards for handling confidential information as would Orange County employees. Section 6. E-MAIL 6.1 The County's E-Mail system is provided to County employees for the purposes of carrying out business for the County. The use of E-mail for personal purposes is not permitted. As noted in the Purpose Statement of this policy, the County has the right to examine E-mail communications at any_ time. E-mail communications are governed by the same guidelines for . conduct as any other employee communications. Section 7. INTERNET 7.1 Internet access may be provided to County employees. Internet use must be consistent with County policies, ethics, values and provide business benefit. 7.2 Internet use, via County facilities, is restricted to County employees with approved business needs. Any use of the Internet for personal purposes is not permitted. 7.3 "Confidential" information must be appropriately encrypted before being transmitted using the Internet. 7.4 The License (or Usage) Agreement for all software obtained from the Internet and used on County resources will be strictly followed. 7.5 Software, data, and information integrity should be considered questionable when obtained from the Internet. • s 7.6 A.s noted in the Purposed statement of this policy, the County has the right to examine any . information sent or received via the Internet. 7.7 County employees/volunteers shall not enter into contractual agreements via the Internet or further to make statements on the Internet that may be interpreted as contractual. Section 8. POLICY RESPONSIBILITIES 8.1 DP will be responsible for on-going review and maintenance of the PC policy and will respond to questions of interpretation. It is expected that major policy changes would be accomplished by consensus with Department Heads. • • 7 • Attachment I Employee Confidentiality Agreement • • I, an employee of Orange County, acknowledge that I have access to information which is confidential by State and Federal law, regulation and/or policy. I recognize my legal obligation and my obligation as an Orange County employee to maintain the confidentiality of information in conformance with law. I agree, consistent with State and federal law, to preserve the security of computer access by not permitting the use of my computer access code by any one else and by not placing my computer access code in any place accessible to unauthorized persons. I acknowledge that release of information confidential by law to unauthorized persons may result in criminal prosecution. I also acknowledge that failure to maintain legally required confidentiality of information constitutes "misconduct" within the meaning of the Orange County Personnel Ordinance and may lead to disciplinary action, including dismissal from Orange County employment. _ I certify that I fully understand the conditions stated above and the confidentiality requirements of my position. I further certify that I have had an opportunity to discuss the conditions stated above and the confidentiality requirements of my position with my supervisor. Employee's Signature Date I certify that I have reviewed with the above employee the conditions stated above and the confidentiality requirements of his or her position. Supervisor's Signature Date (2-19-96) i i• 030 04/14/88 iw MEMO To: Depart nt Head From: Keith Bro ks - Data Processing Re: Personal Co pater Policy The installation of one or mo personal computErs in your department necessitates a Data rocessing Personal Computer Policy. Please distribute the a closed making your users aware of its contents. i• POLICY FOR INSERTION INTO THE POLICY MANUAL MEETI'. EFFEC POLIC • • ,~ , PC RRSTRICTIONS Personal computer capabilities create a special environment in which certain restrictions must be observed. These are the following: AUTHORIZED US Personal computer resources are provided for County busines Personal and other non-County uses must be approved by the epartment director with those tasks completed outsid normal. working hours. It is the responsibility of he department director or designated representative to b aware of and approve all applications installed on persona computers. NON-COUNTY SOFTWARE: ~nly software purchased or otherwise obtained by the County to be operated on the personal computers. The operatio of personal or other non-County software is not permitted or County business. OFF-SITE USE: Since persona computers are purchased for specific business needs, they are not to be transported from their approved business locati s unless the move is associated with the proper cond t of County business. This restriction is applicable to data data media, programs, documentation, and equipment. ' DEVELOPMENT SOFTWARE OWNERSHIP: Any software developed on a County personal computer is the prop ty of the County and shall not be sold or given to anyone w'thout written consent of the user department director. COPYRIGHT PROTECTION: Through the purcha of hardware and software the County automatically comes un r provisions. of the copyright laws. These laws are normall contained in equipment and software manuals and they must a adhered to. These. laws generally prohibit the copying of p ograms for use on other personal computer installations. No s ftware or software manuals are to be copied for anything o er than the owners use. ,,~ DATA FROCESSING SUPPORT: Hon-authorized equipment o software will not be supported. `~ r SECURITY CONCERNS - he placement of a personal computer system in a user area nd the portability of the equipment and associated data m is creates a need for special user concerns as follows: 1) S ce s personal computer and other related equipment are Basil transportable, the user must ensure that ali such equipme t is located in a secure area and that the - opportun ties for theft are minimized. 2) The user must take care that only authorized personnel have access t the personal computer system. 3) Gocal data f es and programs must be safeguarded from accidental or del berate damage, loss or unauthorized use. 4) Users are respon ble for the backup and retention of local data files. 5) Confidential and/or nsitive data must be carefully controlled and safe-guard d. RESPON HILITIES DATA PROCESSING will: • A} Maintain a County-wide inventory hardware and software; B) Evaluate .and recommend all personal omputer equipment and software purchased; C) Periodically review all PC usage to Bete mine the cost effectiveness and adherence to the County po cy; D}, Advise and assist the user. USER DEPARTMENT will: A) Provide security of all hardware, software, data, a d PC produced reports in their department; ,, 4 B) Implement backup procedures; C) Provide all computer furniture and supplies; D) Maintain .personal computer work area;. - 'E) Train employees on departmental applications. CARE OF DISKETTES 1) Pr rly label diskettes in order to help prevent accide tal destruction of work and enable files to be located quickly nd with unnecessary effort. Labels should be placed on the d kette, not on the protective sleeve. Labels should not be pl ed over any holes in the diskette packet. . 2) Diskette abels should be prepared before placing labels on the diske tea. 3) Replace old. iskette labels with new labels. 4) Place the disk tte in its protective sleeve as soon as it is removed from th drive. 5) Handle diskettes s if they are very fragile phonograph. records. Hold them g ntly by the edges and never fold or flex them. 6) Keep diskettes away f m heat sources. 7) Keep diskettes between and $5 degrees and out of direct sunlight. . 8) Do not touch the recording urface. 9) Isolate diskettes from any fo m of magnetism. This includes the telephone. 10) Never paper clip or staple a di ette to a report or printout. 11) Never open a disk drive door when t e red light is on. This light indicates that a file is bein written to or read. 12) Do not allow diskettes to be passed th ugh x-ray devices iri airports. `' • MEMO R=A N D U M To All De artment Heads p From: Keith Brooks, Data Processing Manager Re Copyright infringement of PC based software Date: March 10, 1994 f i',' '!` I,~ ~~;: Ir ~~' I I Company raided for possible copyright violation Washington, DC -The Business Software Alliance (BSA) said it raided the offices of Healthcare Revenue Management Inc. for suspectedcopyright infringement ofsoftware programs loaded onto company computers. Acting under an order issued by the U.S. District Court for Northern District of Cali- fornia, BSA auditors, accompanied by US ~ Marshals, raided the premises of the San Francisco company on Nov. 17, 1993. Mul- e tiple copies of unlicensed software - includ- g products by Lotus Development Corp., rosoft Corp., and WordPerfect Corp., al! members ofthe B S A -were found on comput- ers used by the company. Healthcare Rev- . enueManagement,amid-sizedcompanyspe- cializing in analysis and admini,-tr-.ttion of heal thcare expenses, faces a peter Val liability of $100,000 foreach illegal software product. "Illegal copying occurs in small and mid- sized companies, as well as among the For- tune 500," explained Robert Knrger, BSA's director of enforcement. "All companies need to adopt programs to control software piracy and make it clear that they will take action against employees who engage in This form of theft. T'he BSA will nol hesitate to act where we have clear evidence of infringement re- gardless of the size of the company ° BSA promotes the continued growth of the software industry through its programs in the U.S. and more than SOothercountries through- out the world. BSA's members -including Aldus, Apple Computer, Autodesk, Com- puler Associates, Intergraph, Lotus, Microsoft, Novell, and WordPerfect -provide nearly 75 percent of the world's packaged PC soft- ware published by U.S: based compa..,es. Since its inception in 1988, BSA has filed more than 400 lawsuits worldwide against suspected softwanecopyright in5-ingers. 'The BSA also initiates audits of organizations suspected of usi»g copied software. BSA operates 20 hotlines around the world for callers seeking information about copy- right matters or to report suspected incidents of unauthorized copying of softwarti. Callers in the U.S. can dial (800) 688.BSA1 (2721). This article appeared in the current issue of a leading PC magazine. As you can see, the..unauthorized copying of software is taken seriously by the PC software industry. The County has a set of approved PC Policies which state we will adhere to all copyright laws governing software protection. My staff indicates to me that we do have several ilegal copies of some software loaded on County computers. I have instructed them to bring any of this to my attention in the future and I will discuss it with the appropriate department heads.