IT Usage Policy

IT Usage Policy

IT Resources Use Policy & Operational Advisories

 

Indian Institute of Information Technology, Allahabad (IIIT-A & referred to hereafter, as the institute) has established a policy for use of Email and Other IT resources for the timely dissemination of information relevant to individuals and equitable usage of network resource, while shielding its faculty, students, and staff from information mismanagement and clutter caused by unwanted or unsolicited large-scale e-mails or unauthorized server access/activity. This policy applies to all electronic communication / data originating from the institute domain as well as information/data/email sent from other domain(s) using IT hardware and/ or software services of IIIT-A directed to any/all of its stakeholders. The following enumerated constituent points of the policy have been formulated with the object to protect IIIT Allahabad and its stakeholders from legal liability, reputation damage and security breaches - not to mention ensure equitable IT resource utilization.

1.      Faculty, Staff, and Students are allocated an email mailbox and are encouraged to utilize it for positive, productive and effective communication while ensuring a check on unnecessary emails cluttering up the mail box: The following will be applicable hereafter with regards to the email service.

a.      Sending emails to “everyone” is being restricted to only the system admin.

b.      For important announcements and broadcast messages, all faculty and staff members should use target mailing lists such as “faculty”, “staff”, “students” etc.

c.       Any mail originating from an unauthorized sender (within IIITA domain) to email groups/ mailing lists will automatically be placed in a moderation queue/discarded.

d.      Messages from external entities to any email groups/ mailing lists will be summarily rejected before ingress.  

e.      While congratulatory or condolence messages are important – it is specifically requested to please refrain from using the “reply-all” when responding to such messages as it creates a significant inbox clutter for all but the target individual. Please address the target individual only.

f.       Email messages from multi-authored accounts such as AAA, Accounts, Stores, etc. must include the name of the actual faculty/officer/staff sending the particular message. 

2.     IIIT-A reserves the right to control access to IT resources, that are deemed harmful to not only its IT infrastructure but to the general harmony of the campus. Towards this end, the network services team will monitor and periodically evaluate to ensure that access to resources and tools that aid and enable undesirable behavior is restricted. Users are advised not to host services or spread messages to/from the IIITA network service that are to the detriment of the Institute and its functioning or those that they are not authorized to. Additionally – moving forward, all outbound emails will carry a disclaimer appended to each message. For the sake of uniformity, users are requested to remove any additional disclaimer text they may have in their individual email signatures.

3.      Users are responsible for ensuring the confidentiality and integrity of their accounts. Sharing of passwords (apart from multi-authored accounts) - for any purpose is strictly prohibited and any unexpected or undesirable outcome from such a share or an otherwise impetuous action will be attributed to the concerned user. Such events may leads to disciplinary action.

4.      Users must not impersonate another individual or misrepresent authorization to act on behalf of another individual or the institute. Messages stored on or transmitted through the institute network must correctly identify the sender. No one should modify the original attribution of email messages or posts nor should they send anonymous, obscene, defamatory or threatening messages or in any way harass others. Users must not attempt to undermine the security or integrity of the institute network and must not attempt to gain unauthorized access and should certainly refrain from using any computer program or device to intercept or decode passwords or any access-control credentials. While this is not an exhaustive list, these are all serious offenses and will be treated as such – leading to disciplinary actions.

5.      All users are expected to follow the established process chain for the resolution of their grievance(s). Towards this end, it is expected that the residents will avoid sending messages to external entities without exhausting their institutional grievance redressal options. This is also expected as per the previously notified standard process for resolution of grievances. Violation of this will lead to possible revocation of email send privileges. 

6.      Network services, ERP and other institutional groups that have web development work within their task profiles are required to ensure that their development servers are secure and NOT visible/accessible from outside IIIT Network. Any external access to their servers MUST be through authorized VPN clients and by authorized VPN users.

7.      All email/web service accounts created for short term events such as workshops/conferences or short-term visitors will be purged within a predetermined period after the completion of the said event or the end of stay of the visitor.

8.      No email/web account will be created per verbal instructions. All requests for such accounts must be made through the ERP portal though a faculty, officer or the respective Dean and must include the following information (without which the request will not be entertained).

a.      Purpose

b.      Tenure of the account

c.       Individual who shall operate and maintain the sanctity of the said account.

These requests will be fulfilled after a feasibility assessment from the FIC Network services and approval from office of CISO.

9.      Every individual using electronic devices connected to the Institute network are strongly advised to scan their devices for Malware/Virus/Spam Ware etc. These infected hosts create a lot of traffic for the edge devices (especially the firewall) and in turn increases the overall latency of the network, and also attracts the attention and possible admonishment from Government Agencies such as CERT-IN (a highly undesirable scenario). Nodes found generating such undesirable traffic will be blocked at the network edge.  

10.   The MeitY requires the institute network to undergo IT security audits along with network penetration tests twice a year (conducted by an independent authorized agency). Only one of these audit/tests will be announced. During these tests, vulnerabilities (if any) of the network along with that of internal hosts may be discovered and subsequently reported. Based on the report, residents would be asked to make some changes to web servers or nodes/endpoints controlled by them. These activities will be conducted and monitored by the office of CISO in conjunction with the Network & IT services group of the institute.

11.   Any software installation on an institutional computer system must be preceded by due consent of the respective facility/faculty in charge. Unlicensed software should NOT be installed on any IIIT-Allahabad owned machine or any personal machine that is connected to the IIIT-Allahabad network. In the event that such software (unlicensed/unauthorized) is detected, the concerned user(s) will be required to remove it immediately failing which such machines will be blocked from accessing the network services.

12.   Usage of institute IT and power infrastructure for non-academic/commercial purposes (like crypto-mining) without prior approval from the competent authority is expressly prohibited.

13.   Individual Wireless Access points/Routers are strictly not allowed in Hostels/Dormitories/Scholar Residence/Administrative or Academic Areas. Wherever allowed, such wireless routers or APs should employ sufficient authentication mechanisms to prevent unauthorized access. However, these devices will not be allowed to bypass the Institutional firewall and Proxy Devices unless approved by the office of CISO.

14.   It goes without saying that the internet access and other resources of the Institute are considered as privilege which can be withdrawn if abused. 

15.   Any electronic message/post that is addressed to person(s) outside this institute containing material deemed privileged by the institute without authorization or poses a legal liability, brings disrepute or precipitates threats and security breaches etc. to the institute and/or its stakeholders are expressly prohibited. Such acts shall have serious consequences through enforcement of institute/local/state/central & international law(s).

16.   Email account retention: The following policy shall govern the time permitted for access to mail box / web storage / LDAP credential validity:

   A.     ALL undergraduate/graduate students: (All Services): One month after their final no-dues. 

   B.    Doctoral candidates: (All Services*): Six months following their final defense.

   C.    Visiting faculty: (All services*):  Up to their contractual period (following which their account will be suspended). If contract not renewed then account purge after 6 months.

   D.    Officers/Staff (regular) superannuating or voluntarily leaving the institution: Mail box access*: Three Years. Web storage and  other resources – One year.

   E.   Regular faculty members voluntarily leaving the institute: Mail box access*: Number of years equal to their service tenure. Web  storage and other resources – One year.

   F.      For superannuating faculty: Mail box access*: Lifetime. Web storage and other resources – One year.

        * With modified mail send privileges

 

These guidelines and policy points are issued with the approval of the board and the competent authority. Further – these guidelines and policy points are not exhaustive and are subject to periodic revision(s).