INTERNAL LAB SECURITY POLICY

1.0 Purpose

This policy establishes information security and usage requirements for Georgia Highlands College labs to ensure that the College’s confidential information and technologies are not compromised, and that production services and other Georgia Highlands College interests are protected from lab activities.

 

2.0 Scope

This policy applies to all internally connected labs, Georgia Highlands College employees, students and third parties who access these computers. All existing and future equipment, which fall under the scope of this policy, must be configured according to the referenced documents.

3.0 Policy

 

3.1 Ownership Responsibilities

  • The Georgia Highlands College Information Technology Department is responsible for the security of their labs and the lab's impact on the campus production network. Information Technology is responsible for adherence to this policy and associated processes. Where policies and procedures are undefined, Information Technology must do its best to safeguard Georgia Highlands College from security vulnerabilities.
  • Information Technology is responsible for the lab's compliance with all Georgia Highlands College security policies. The following are particularly important: Password Policy for networking devices and hosts, Wireless Security Policy, Anti-Virus Policy, and Physical Security.
  • Information Technology reserves the right to interrupt lab sessions that impact the campus production network negatively or pose a security risk.
  • Information Technology must record all lab IP addresses, which are routed within Georgia Highlands College networks.
  • No lab shall provide production services. Production services are defined as ongoing and shared business critical services that generate revenue streams or provide customer capabilities.

 

3.2 General Configuration Requirements

  • Labs are prohibited from engaging in port scanning, network auto-discovery, traffic spamming/flooding, and other similar activities that negatively impact the campus network and/or non-Georgia Highlands College networks.
  • In labs where non-Georgia Highlands College personnel or students have physical access (e.g., training labs), direct connectivity to the campus production network is not allowed. Additionally, no Georgia Highlands College confidential information can reside on any computer equipment in these labs.

 

3.3 Lab, Cluster area and Computer Enhanced Classroom Rules

  • No food, drink or tobacco products are allowed in labs, cluster areas or computer enhanced classrooms.
  • Cell or Internet phone use is not allowed in Georgia Highlands College labs, cluster areas or computer enhanced classrooms.
  • Disorderly conduct is prohibited. Fair and courteous use of lab facilities and resources are expected of all Georgia Highlands College students and employees
  • Students will adhere to the Georgia Computer Systems Protection Act which provides for criminal liability and penalties for computer crimes.
  • Bulletin boards for personal messages, commercial advertising or other profit-making activities are prohibited.
  • Students are not allowed to use Faculty workstations unless accompanied by a member of the Georgia Highlands College faculty/staff.
  • Viewing of pornographic material or material that would be offensive to others is not allowed

4.0 Enforcement

Any employee or student found to have violated this policy may be subject to:

  • Revocation of account privileges
  • Banishment from labs, cluster areas or computer enhanced classrooms
  • Disciplinary action, up to and including termination of employment or expulsion from school
  • Criminal charges

 

5.0 Definitions

Terms Definitions

Lab A lab is any non-production environment, intended specifically for developing, demonstrating, training and/or teaching. This term also includes computer cluster areas and computer enhanced classrooms

 

Internal A lab, cluster or computer enhanced classroom that is within Georgia Highlands College's campus firewall and connected to Georgia

Highlands College's campus production network.

Traffic Mass volume of unauthorized and/or unsolicited network Spamming/Flooding traffic.

Firewall A device that controls access between networks. It can be a PIX, a router with access control lists or similar security devices.

6.0 Revision History

07/08/03 Policy Origination jmc

07/10/03 jp, jmc

09/17/03 Group Review jp

11/24/04 Policy revision jp

11/09/05 Policy review jp