HomeMy WebLinkAboutP-0340 - Personal Computer Policy 04-04-1996•
•
•
POLICY FOR INSERTION INTO THE POLICY MANUAL
MEETING DATE: April 14, 1988
DATE: April 14, 1988
NUMBER• A:0340
REVISIONS: Reissued
April 4, 1.996
POLICY: PERSONAL COMPUTER POLICY (See attached PC Policy
distributed by Data Processing Department)
• ORANGE COUNTY
POLICY GOVERNING THE USE OF PERSONAL COMPUTER EQUIPMENT
AND SOFTWARE (THE PC POLICY)
April 4, 1996
CONTENTS:
SECTION 1. EQUIPMENT
1.1 Purchase of Equipment
1.2 Use Qf Non-County Owned Equipment .
1.3 Repair of Equipment
SECTION 2. SOFTWARE
2.1 Purchase of Software
2.2 The County Standard Software
2.3 Use of Non-County Owned Software.
2.4 Software Library
SECTION 3. SECURITY
3.1 Departmental Responsibilities
3.2 User responsibility _
3.3 ,Computer Records
SECTION 4. TRAINIl~iG
• SECTION 5. VOLUNTEERS
5.1 Volunteers using county-owned equipment
5.2 Volunteer access to confidential information
SECTION 6. E-MAIL
SECTION 7. INTERNET
SECTION~8. POLICY RESPONSIBILITIES
•
• ORANGE COUNTY
POLICY GOVERNING THE USE OF PERSONAL COMPUTER EQUIPMENT
AND SOFTWARE (THE PC POLICY)
April, 1996
PURPOSE: This policy has been formulated to provide direction to County Employees,
Volunteers and any other users as it respects the use of personal computer hardware and
software. Violations of the policy governing the use of personal computer hardware and
sofhvare (the PC Policy) shall fall under the jurisdiction of the Orange County Personnet
Ordinance, Article IX, Appendix 2 and may result in disciplinary action under that
Ordinance. All automated systems (E--mail, Internet, etc.) are subject to monitoring and
examination by appropriate County officials at any time,
Further, this policy assumes the continued collaboration between the Data Processing
Department (hereinafter referred to as "DP") and the user department(s) to address future
automation needs as they arise.
Section 1. EQUIPMENT
1.1 Purchase of Equipment
All PC hardware requires review and consensus between DP and the user department
prior to it being ordered. Generally, County equipment is purchased on a bid basis. County
• Departments shall not contact vendors during the bidding process. Doing so could disqualify the
vendor from bidding. The specifications for the equipmenrt are done in collaboration with the DP
and the user department director.
1.2 Use of Non-County Owned Equipment .
The County assumes no responsibility for non-County owned equipment. This includes,
but is not limited to, insurance coverage for non-County owned equipment, maintenance for non-
County owned equipment, damages to non-County owned software, etc. This also includes
personal equipment used by a volunteer.
1.3 Repair of Equipment
Each Department should designate an employee to be the departmental coordinator for
equipment repairs. DP will ensure that the designated person receives training regarding various
equipment malfunctions in order that the employee can assess the malfunction as quickly and
efficiently as possible. The departmental designee will contact DP as deemed necessary. In the
event the problem cannot be addressed in a timely manner by the DP staff the outside service
provider will be contacted. DP will estimate the time needed for the repair and notify the
department.
~J
2
Users shall not attempt to repair equipment unless they are absolutely certain of the problem
• diagnosis and repair options. Users shall not contact the outside service provider without the
prior approval of DP. Failure to receive prior approval may be deemed an unauthorized
expenditure and as such will become the responsibility of the user.
Section 2. SOFTWARE
2.1 Purchase of Software
All PC software, including specific program applications (eg. Visions, used in Sheriffs
Department, App Tracking as used by Personnel) requires review and consensus between DP and
the Department prior to it being ordered.
2.2 The County Standard Software
At the time of the writing of this policy the County standard is Microsoft Windows,
Microsoft Word, Microsoft Access, Microsoft Excel, Microsoft Powerpoint, Crroupwise E-mail,
NetScape and Novell Netware. In order to ma_X~m»e limited departmental resources, these are
the only software packages that DP presently supports. Departments will be notified as new
standards are developed through the Data Processing Advisory Committee. DP may offer
additional software support to Departments who are required to use specific program
applications.
2.3 Use of Non-County Owned Software.
. Any non-County software (including screen savers) installed on County equipment shall
first be checked for viruses by DP. The user is subject to disciplinary action for any damage
incurred to County owned hardware or software installed on the unit that was not first
checked/tested by DP. DP maintains and supports only the software previously identified as the
County standard. Should you be in doubt as to the standard, contact DP directly.
2.4 Software Library
A software library will be maintained in DP for selected software which falls outside of
those previously identified as the County standard (see 2.2) but may have applicability in some
departments. While full support cannot be offered for this software, operational instructions are
available.
In addition, self-paced tutorials for most of the County standard software is available to
the employee on a sign-up basis through the Personnel department.
Section 3. SECURITY
3.1 Departmental Responsibilities:
Each department whose operation requires the handling of confidential information is
expected to develop departmental policies and procedures to ensure that this information is
protected from loss, damage, alteration or unauthorized use. The following considerations should
be observed as these policies and procedures are developed:
3.1.1. Each department is encouraged to have swell-defined process for ensuring that:
• a. authorized users have access only to the systems/functions that are
necessary to carry out the duties of their position; and
b. a written record is maintained of each user who has access to a system/fiinction;
and
c. passwords/IDs are immediately deleted for any user who leaves
employment; and
d. passwords/IDs for new users are added; and
e. passwords/IDs are changed periodically and when an user's duties change; and
3.1.2 Each department should appoint a primary security officer and a secondary
security officer responsible for assigning, deleting passwords/IDs; maintaining the list of users by
system/fimction access; keeping users apprised of responsibilities with respect to security policies
and other duties as assigned.
3.1.3 Each department should appoint a primary and secondary network coordinator
(may be the same person as s security officer) responsible for principle liaison with DP, initial
trouble-shooting within the department and other duties as assigned.
3.1.4 Each department is encouraged to provide training on security procedures to all
.. users, including at least a yearly reminder of the importance of security. This may be a
responsibility of the security officer.
3.1.5 Each de artment should have policies for the checkout and use of portable
P
equipment such as laptops, portable printers. Only portable equipment is available for checkout
and use outside the office. Any exception requires the advance written approval of the
Department Head and Information Systems Director with notification to the Purchasing/ Central
Services Director.
3.2 User responsibility
3.2.1 Users will not share information obtained through computer access with other
individuals and/or agencies unless permitted by policy and law.
3.2.2 Users will use only those systems/functions which they are authorized to use.
3.2.3 Users will ensure that whenever a terminal is not being used, it will be secured to
avoid use by unauthorized personnel.
3.2.4 Users will not share their passwords/IDs with others or use another user's
password/ID. Users will ensure that their passwordslIDs are not left out in the open where they
could be found and used by other individuals. Users who are not authorized for a particular
system/fimction will not seek access to that system/fimction through another user.
•
4
3.2.5 Users with access to confidential information should sign the Employee
Confidentiality Agreement (see Attachment I) and be given a copy of same when it is signed.
3.2.6 Users will keep any portable equipment in a secure place, adhere to the
department's checkout procedures, and use the equipment exclusively for County business.
3.2.7 Users will use County equipment for County business only. Personal use of County
equipment is prohibited.
3.3 Computer Records
Dissemination of records maintained on the computer are subject to the Public Records
Law and are disclosed only in accordance with the law. Users unfamiliar with the requirements
of the Public Records Law will be expected to seek clarification from a supervisor prior to
releasing information.
Section 4. TRAINING
4.1 The County recognizes the importance of providing adequate training opportunities to
enable employees to fully utilize the computer technology endorsedlpromoted by the organization.
It is an expectation that training will occur within 12 months after employees have access to
assigned County hazdwaze and softwaze.
• 4.2 The following statements establish the requirements and expectations of employees engaged
in computer hardware or softwaze training:
4.2.1 Once an employee is enrolled in County sponsored and funded training, mandatory
attendance throughout the training is required. Any exceptions must be approved by the
employee's Department Head and/or supervisor.
4.2.2 In order to enroll in County sponsored and/or funded training, the employee must
have access to the appropriate softwaze packages and hardware.
4.3 Supervisors are responsible for ensuring employees have access to training opportunities for
assigned County hazdwaze and softwaze. Presently, training opportunities aze provided through
in-house training, self-paced tutorials offered for check out through the Personnel Department
and training through outside contractors. Supervisors should consult with the employee to
determine their skill level and reach a mutual decision regazding training needs.
•
5
Section 5. VOLUNTEERS
•
5.1 Volunteers using County-owned equipment
Any volunteer using County equipment is expected to adhere to the same rules and
regulations for PC use as would a County employee. It should be the responsibility of the
Department Head to ensure that the volunteer has sufficient expertise to carry out the assigned
work. This is to include the operation of the equipment, including but not limited to, the loading
of software, network maintenance, etc.
5.2 Volunteer access to confidential information
Access to confidential information by any volunteer will be approved by the department
head. Any volunteer with access to confidential information shall be given specific instruction as
to the handling of this information. Volunteers will follow the same standards for handling
confidential information as would Orange County employees.
Section 6. E-MAIL
6.1 The County's E-Mail system is provided to County employees for the purposes of carrying
out business for the County. The use of E-mail for personal purposes is not permitted. As noted
in the Purpose Statement of this policy, the County has the right to examine E-mail
communications at any_ time. E-mail communications are governed by the same guidelines for
. conduct as any other employee communications.
Section 7. INTERNET
7.1 Internet access may be provided to County employees. Internet use must be consistent
with County policies, ethics, values and provide business benefit.
7.2 Internet use, via County facilities, is restricted to County employees with approved business
needs. Any use of the Internet for personal purposes is not permitted.
7.3 "Confidential" information must be appropriately encrypted before being transmitted using
the Internet.
7.4 The License (or Usage) Agreement for all software obtained from the Internet and used on
County resources will be strictly followed.
7.5 Software, data, and information integrity should be considered questionable when obtained
from the Internet.
• s
7.6 A.s noted in the Purposed statement of this policy, the County has the right to examine any
. information sent or received via the Internet.
7.7 County employees/volunteers shall not enter into contractual agreements via the Internet or
further to make statements on the Internet that may be interpreted as contractual.
Section 8. POLICY RESPONSIBILITIES
8.1 DP will be responsible for on-going review and maintenance of the PC policy and will
respond to questions of interpretation. It is expected that major policy changes would be
accomplished by consensus with Department Heads.
•
•
7
•
Attachment I
Employee Confidentiality Agreement
•
•
I, an employee of Orange County, acknowledge
that I have access to information which is confidential by State and Federal law, regulation and/or
policy. I recognize my legal obligation and my obligation as an Orange County employee to
maintain the confidentiality of information in conformance with law.
I agree, consistent with State and federal law, to preserve the security of computer access by not
permitting the use of my computer access code by any one else and by not placing my computer
access code in any place accessible to unauthorized persons.
I acknowledge that release of information confidential by law to unauthorized persons may result
in criminal prosecution. I also acknowledge that failure to maintain legally required confidentiality
of information constitutes "misconduct" within the meaning of the Orange County Personnel
Ordinance and may lead to disciplinary action, including dismissal from Orange County
employment. _
I certify that I fully understand the conditions stated above and the confidentiality requirements of
my position. I further certify that I have had an opportunity to discuss the conditions stated above
and the confidentiality requirements of my position with my supervisor.
Employee's Signature
Date
I certify that I have reviewed with the above employee the conditions stated above and the
confidentiality requirements of his or her position.
Supervisor's Signature
Date
(2-19-96)
i
i•
030
04/14/88
iw
MEMO
To: Depart nt Head
From: Keith Bro ks - Data Processing
Re: Personal Co pater Policy
The installation of one or mo personal computErs in your
department necessitates a Data rocessing Personal Computer
Policy. Please distribute the a closed making your users
aware of its contents.
i•
POLICY FOR INSERTION INTO THE POLICY MANUAL
MEETI'.
EFFEC
POLIC
•
•
,~ ,
PC RRSTRICTIONS
Personal computer capabilities create a special environment
in which certain restrictions must be observed. These are
the following:
AUTHORIZED US Personal computer resources are provided for
County busines Personal and other non-County uses must be
approved by the epartment director with those tasks
completed outsid normal. working hours. It is the
responsibility of he department director or designated
representative to b aware of and approve all applications
installed on persona computers.
NON-COUNTY SOFTWARE: ~nly software purchased or otherwise
obtained by the County to be operated on the personal
computers. The operatio of personal or other non-County
software is not permitted or County business.
OFF-SITE USE: Since persona computers are purchased for
specific business needs, they are not to be transported from
their approved business locati s unless the move is
associated with the proper cond t of County business. This
restriction is applicable to data data media, programs,
documentation, and equipment. '
DEVELOPMENT SOFTWARE OWNERSHIP: Any software developed on a
County personal computer is the prop ty of the County and
shall not be sold or given to anyone w'thout written consent
of the user department director.
COPYRIGHT PROTECTION: Through the purcha of hardware and
software the County automatically comes un r provisions. of
the copyright laws. These laws are normall contained in
equipment and software manuals and they must a adhered to.
These. laws generally prohibit the copying of p ograms for use
on other personal computer installations. No s ftware or
software manuals are to be copied for anything o er than the
owners use.
,,~
DATA FROCESSING SUPPORT: Hon-authorized equipment o
software will not be supported. `~
r
SECURITY CONCERNS -
he placement of a personal computer system in a user area
nd the portability of the equipment and associated data
m is creates a need for special user concerns as follows:
1) S ce s personal computer and other related equipment are
Basil transportable, the user must ensure that ali such
equipme t is located in a secure area and that the -
opportun ties for theft are minimized.
2) The user must take care that only authorized personnel
have access t the personal computer system.
3) Gocal data f es and programs must be safeguarded from
accidental or del berate damage, loss or unauthorized use.
4) Users are respon ble for the backup and retention of
local data files.
5) Confidential and/or nsitive data must be carefully
controlled and safe-guard d.
RESPON HILITIES
DATA PROCESSING will:
•
A} Maintain a County-wide inventory hardware and software;
B) Evaluate .and recommend all personal omputer equipment and
software purchased;
C) Periodically review all PC usage to Bete mine the cost
effectiveness and adherence to the County po cy;
D}, Advise and assist the user.
USER DEPARTMENT will:
A) Provide security of all hardware, software, data, a d PC
produced reports in their department;
,,
4
B) Implement backup procedures;
C) Provide all computer furniture and supplies;
D) Maintain .personal computer work area;. -
'E) Train employees on departmental applications.
CARE OF DISKETTES
1) Pr rly label diskettes in order to
help prevent
accide tal destruction of work and enable files to be located
quickly nd with unnecessary effort. Labels should be placed
on the d kette, not on the protective sleeve. Labels should
not be pl ed over any holes in the diskette packet. .
2) Diskette abels should be prepared before placing labels
on the diske tea.
3) Replace old. iskette labels with new labels.
4) Place the disk tte in its protective sleeve as soon as it
is removed from th drive.
5) Handle diskettes s if they are very fragile phonograph.
records. Hold them g ntly by the edges and never fold or
flex them.
6) Keep diskettes away f m heat sources.
7) Keep diskettes between and $5 degrees and out of direct
sunlight. .
8) Do not touch the recording urface.
9) Isolate diskettes from any fo m of magnetism. This
includes the telephone.
10) Never paper clip or staple a di ette to a report or
printout.
11) Never open a disk drive door when t e red light is on.
This light indicates that a file is bein written to or read.
12) Do not allow diskettes to be passed th ugh x-ray devices
iri airports.
`'
•
MEMO R=A N D U M
To All De artment Heads
p
From: Keith Brooks, Data Processing Manager
Re Copyright infringement of PC based software
Date: March 10, 1994
f
i',' '!`
I,~
~~;:
Ir
~~' I I
Company raided for possible copyright violation
Washington, DC -The Business Software
Alliance (BSA) said it raided the offices of
Healthcare Revenue Management Inc. for
suspectedcopyright infringement ofsoftware
programs loaded onto company computers.
Acting under an order issued by the U.S.
District Court for Northern District of Cali-
fornia, BSA auditors, accompanied by US
~ Marshals, raided the premises of the San
Francisco company on Nov. 17, 1993. Mul-
e tiple copies of unlicensed software - includ-
g products by Lotus Development Corp.,
rosoft Corp., and WordPerfect Corp., al!
members ofthe B S A -were found on comput-
ers used by the company. Healthcare Rev-
. enueManagement,amid-sizedcompanyspe-
cializing in analysis and admini,-tr-.ttion of
heal thcare expenses, faces a peter Val liability
of $100,000 foreach illegal software product.
"Illegal copying occurs in small and mid-
sized companies, as well as among the For-
tune 500," explained Robert Knrger, BSA's
director of enforcement. "All companies need
to adopt programs to control software piracy
and make it clear that they will take action
against employees who engage in This form of
theft. T'he BSA will nol hesitate to act where
we have clear evidence of infringement re-
gardless of the size of the company °
BSA promotes the continued growth of the
software industry through its programs in the
U.S. and more than SOothercountries through-
out the world. BSA's members -including
Aldus, Apple Computer, Autodesk, Com-
puler Associates, Intergraph, Lotus, Microsoft,
Novell, and WordPerfect -provide nearly
75 percent of the world's packaged PC soft-
ware published by U.S: based compa..,es.
Since its inception in 1988, BSA has filed
more than 400 lawsuits worldwide against
suspected softwanecopyright in5-ingers. 'The
BSA also initiates audits of organizations
suspected of usi»g copied software.
BSA operates 20 hotlines around the world
for callers seeking information about copy-
right matters or to report suspected incidents
of unauthorized copying of softwarti. Callers
in the U.S. can dial (800) 688.BSA1 (2721).
This article appeared in the current issue of a leading PC
magazine. As you can see, the..unauthorized copying of
software is taken seriously by the PC software industry.
The County has a set of approved PC Policies which state we
will adhere to all copyright laws governing software
protection. My staff indicates to me that we do have several
ilegal copies of some software loaded on County computers. I
have instructed them to bring any of this to my attention in
the future and I will discuss it with the appropriate
department heads.