Contents
- Acceptable Use of Systems
- Administrator Rights & Responsibilities
This is an overview of the Northwestern policies governing the acceptable use of our systems, briefly summarizing the key concepts. Details can be found in the Northwestern Policies linked below as well as in the Staff Handbook.
Acceptable Use of Systems
When given access to systems and information you are agreeing to use these resources in a responsible and secure manner as outlined in Northwestern University policies, which can be found here. Specifically, you are agreeing to the “Appropriate Use of Electronic Resources” and “Rights and Responsibilities for the Use of Central Network and Computing Resources”, and “Guidelines for Security and Confidentiality of Data Files” Policies, which include these important key concepts:
- Access should occur only for a legitimate University purpose.
- These resources may not be used for commercial purposes.
- You are responsible for the use of your network ID (NetID) and all computer accounts that are assigned to you. You may not give anyone else access to your NetID or computer accounts
- You are expected to respect the privacy of the individuals whose information you access.
- You must use reasonable and prudent methods to preserve the integrity and privacy of the accessed information.
- You will not seek personal benefit or permit others to benefit personally from any confidential information that has come to them by virtue of their work assignment.
- All use of University systems and information must comply with appropriate law including FERPA, as well as University policies on policies on Minors at Northwestern, Sexual Misconduct, Discrimination and Harassment, Conflict of Interest, and Civility and Mutual Respect.
- Be aware that while the University does not routinely monitor the information content exchanged or stored on its systems, it retains the right to access Electronic Resources when necessary and appropriate.
- It is prohibited to provided unauthorized access to University systems or provide information to anyone who is not authorized.
Certain system and data access require additional protections, covered in the Data Access policy as well as agreements required for access to specific systems such as CatConnect, NUHR, Slate, and SES.
ADMINISTRATOR RIGHTS & RESPONSIBILITIES
If you are an administrator of a system, you have additional responsibilities that come along with your privileged access.
- To monitor the use of system activities. This may include real-time monitoring of system activity and/or maintaining a log of activity for later review.
- To remove a user should the user violate the Acceptable Use agreement.
- To provide internal and external controls as appropriate and feasible. Such controls shall include the right to determine who will have access to Kellogg data at which access levels and, specifically, to exclude those who do not abide by Acceptable Use Agreement or other policies governing the use of school information.
- To track the granting of permissions in the system and audit who has elevated levels of access on a regular basis.
- To provide guidelines and make reasonable efforts to train staff, faculty, students, and others in acceptable use and policies governing the system.
- To alert a direct supervisor and the Kellogg Information Services (KIS) in a very timely fashion should they become aware of a data breach.
- Periodically, to review and make determinations on whether specific uses of the system are consistent with the acceptable use practice and to adjust/update these policies accordingly.