|
Recommended Guidelines for Email & Internet Usage
Email & Internet Policy Email & Internet Code of Practice
Email & Internet Policy
Email & Internet Code of Practice Recommended Guidelines for Email & Internet Usage 1. Policy 1.1 Policy Statement Email and Internet services are (INSERT ORGANISATION NAME) facilities and are intended for use for communication, research and administration in support of (insert organisation name) mission. (INSERT ORGANISATION NAME) will place constraints on the use of Email and Internet usage to protect its legal position with respect to telecommunications, copyright and contractual law, to ensure the confidentiality of communications and the protection of privacy and to comply with record keeping requirements. 1.2 Policy Objective The purpose of this Policy is to ensure that:
1.3 Definitions The following definitions apply in the policies, guidelines and codes of practice related to the use of the (insert organisation name) computing and networking facilities: (INSERT ORGANISATION NAME) : Throughout this document (INSERT ORGANISATION NAME) stands for (INSERT ORGANISATION NAME) NSW Inc. (INSERT ORGANISATION NAME) Record: a record in the form of electronic mail exists whenever such electronic mail is in support of (INSERT ORGANISATION NAME) business, whether or not the equipment, software, or facilities used to create, or store the electronic mail record are owned by (INSERT ORGANISATION NAME) . Electronic Mail Services: Information technologies used to create, send, forward, receive, store, or print electronic mail. Use of Electronic Mail Services: To create, send, forward, reply, copy, store, print, or possess electronic mail messages. For the purpose of this Policy, receipt of electronic mail is excluded from this definition to the extent that the electronic mail user does not have control over the email received. The terms electronic mail and email are used interchangeably throughout this Policy. 1.4 Scope This Policy applies to all electronic communication services (email, internet) provided by (INSERT ORGANISATION NAME) on all facilities and to all users and uses of such services; and to all (INSERT ORGANISATION NAME) records in the form of electronic mail in the possession of (INSERT ORGANISATION NAME) employees or other users of electronic mail services provided by (INSERT ORGANISATION NAME) . This Policy does not apply to paper records, including printed copies of electronic mail. The purpose of this Policy is to set out guidelines for the use of electronic mail as a mechanism for general communication. 2. Guidelines (INSERT ORGANISATION NAME) encourages staff to use Email and Internet in order to further the mission and corporate objectives of (INSERT ORGANISATION NAME) . (INSERT ORGANISATION NAME) encourages the use of Email to share information, to improve communication and to exchange ideas. This guideline only applies to (INSERT ORGANISATION NAME) provided email addresses. 2.1 Accountability 2.1.1 (Position of relevant person/people in your organisation) are responsible for ensuring that the Email & Internet Policy and associated Code of Practice are observed with regard to the Email and Internet services under the control and management of the (Chief Executive Officer or relevant person). 2.1.2 (Department Managers or relevant people) are responsible for ensuring that all staff associated with their area are made aware of and comply with the Email & Internet Policy and associated Code of Practice. 2.1.3 (Position of relevant person/people in your organisation) are the responsible officers for the control and administration of the (insert organisation name) Email & Internet Policy. 2.2 Personal Use (INSERT ORGANISATION NAME) allows the use of (INSERT ORGANISATION NAME) provided Email for appropriate, limited incidental personal purposes. (INSERT ORGANISATION NAME) prohibits the use of free email accounts such as Hotmail, Yahoo and Excite on (INSERT ORGANISATION NAME) provided equipment and communications. 2.3 Commercial or for-profit activities (INSERT ORGANISATION NAME) Email and Internet services may not be used for personal business or personal gain. 2.4 Related Legislation, Policies and Regulations Users should be aware that Email and Internet browsing are subject to the full range of laws applying to other communications, including copyright, breach of confidence, defamation, privacy, contempt of court, harassment, vilification and anti-discrimination legislation, the creation of contractual obligations and criminal law. Privacy Amendment (Private Sector) Bill 2000 2.5 Security and Confidentiality (INSERT ORGANISATION NAME) cannot guarantee confidentiality or undiscovered alteration of communications as current methods used to transport email cannot be regarded as secure. 2.6 Authority for Approving Amendments to the Policy and Code of Practice on Email & Internet usage The (CEO or relevant person) is the authority for approving significant amendments to (insert organisation name) policy and guidelines on Email & Internet usage. 2.6.1 Inclusion of Policy Statement in Policy Documents The policy statement Email & Internet Policy will be included in the relevant (INSERT ORGANISATION NAME) Policies and Procedures manuals. 2.7 Effective Date The policy on Email & Internet usage will come into effect immediately upon being approved. 2.8 Review of Policy The policy on Email & Internet usage will be reviewed every two years by the (CEO or relevant person). 3. Administrative Procedures 3.1 Email Accounts 3.1.1 Email accounts will be issued to staff for as long as they are considered staff of (INSERT ORGANISATION NAME) . 3.1.2 Accounts are to be issued on receipt of the appropriate form requesting an account, whether on paper or electronically. By this request and by using the account the staff member agrees to be bound by this policy and (insert organisation name) policies on the use of IT and the associated Codes of Practice. 3.1.3 When an individual's affiliation with (INSERT ORGANISATION NAME) no longer exists, the individual's email account will be terminated 3.2 Authority for Approving Amendments to the Administrative Procedures on Email & Internet Policy The (CEO or relevant person) is the authority for approving amendments to the administrative procedures of (insert organisation name) policy on Email & Internet usage. Email & Internet Code of PracticeEmail & Internet Policy Recommended Guidelines for Email & Internet Usage 1.0 General Procedures 1.1 (INSERT ORGANISATION NAME) Property (INSERT ORGANISATION NAME) Email and Internet services are (INSERT ORGANISATION NAME) facilities; all (INSERT ORGANISATION NAME) email addresses are owned by (INSERT ORGANISATION NAME) ; and all electronic mail which is in support of (INSERT ORGANISATION NAME) business, whether or not the equipment, software, or facilities used to create or store the electronic mail record are owned by (INSERT ORGANISATION NAME) , are (INSERT ORGANISATION NAME) records. 1.2 (INSERT ORGANISATION NAME) Records Electronic mail, whether or not created or stored on (INSERT ORGANISATION NAME) -owned equipment, may constitute a (INSERT ORGANISATION NAME) record subject to disclosure under the Freedom of Information laws or as a result of litigation. 1.3 Service Restriction Use of (INSERT ORGANISATION NAME) Email and Internet services is a privilege that may be restricted, without the prior consent of the user of such services, as per paragraph 4.3. (INSERT ORGANISATION NAME) reserves the right to designate those categories of user to whom it will provide access to Email and Internet and may revoke access at any time to persons who misuse the services. 1.4 Privacy (INSERT ORGANISATION NAME) respects the privacy of users. It does not wish to routinely inspect or monitor Email & Internet browsing or to be the arbiter of its contents. Nevertheless, subject to the requirements for authorisation and notification defined in this Policy, (INSERT ORGANISATION NAME) may deny access to Email and Internet services and may retrieve, inspect, monitor, or disclose Email when appropriate as per paragraph 4.3. 2.0 Use of Email & Internet Services 2.1 Responsible Use Those who use the Email & Internet services are expected to do so responsibly, that is, to comply with state and federal laws, with policies and procedures of (INSERT ORGANISATION NAME) , and with normal standards of professional and personal courtesy and conduct. (INSERT ORGANISATION NAME) cannot, in general, protect users from receiving Email they may find offensive. (INSERT ORGANISATION NAME) staff, therefore, are strongly encouraged to use the same personal and professional courtesies and considerations in Email as they would in other forms of communication. 2.2 Personal Use (INSERT ORGANISATION NAME) Email & Internet services may be used for incidental personal purposes provided such use does not interfere with (INSERT ORGANISATION NAME) operation of information technologies or email services, burden (INSERT ORGANISATION NAME) with incremental costs, or interfere with the user's employment or other obligations to (INSERT ORGANISATION NAME) . Because of the difficulty in determining whether or not an email message pertains to personal business or is a (INSERT ORGANISATION NAME) record, an email message will be deemed a (INSERT ORGANISATION NAME) record for the purposes of this Code of Practice if it resides on (INSERT ORGANISATION NAME) computing and networking facilities. 2.3 Restrictions Email & Internet services may not be used for: unlawful activities; commercial purposes not under the auspices of (INSERT ORGANISATION NAME) ; personal financial gain; or purposes that contravene other (INSERT ORGANISATION NAME) policies or guidelines. The latter include, but are not limited to, policies and guidelines regarding sexual or other forms of harassment, religious or political activities or copyright. 2.4 Representation When creating and sending email, users should take care not to give the impression that they are representing, giving opinions, or otherwise making statements on behalf of (INSERT ORGANISATION NAME) or any unit of (INSERT ORGANISATION NAME) unless appropriately authorised (explicitly or implicitly) to do so. 2.5 False Identity (INSERT ORGANISATION NAME) email & Internet users shall not employ a false identity or send email anonymously. 2.6 Interference (INSERT ORGANISATION NAME) Email & Internet services shall not be used for purposes that could reasonably be expected to cause, directly or indirectly, excessive strain on any computing or networking facility, or unwarranted or unsolicited interference with others' use of email & Internet services. (Such uses include but are not limited to:
2.7 Misuse Australian law and (INSERT ORGANISATION NAME) policy prohibit, in general, the theft or other abuse of information technology facilities or resources. Such prohibitions apply to Email services, and include (but are not limited to): unauthorised entry, use, transfer, and tampering with the accounts and files of others; interference with the work of others and with other information technology resources or services. Under certain circumstances, the law contains provisions for felony offences. Users of email are encouraged to familiarise themselves with these laws and policies. 2.8 Prohibition (INSERT ORGANISATION NAME) policy prohibits swearing, possession of pornography and any harassing actions and prohibits the use of company resources to visit Internet sites that are pornographic, that promote gambling and that transmit hate mail. 3.0 Security and Confidentiality 3.1 Precautionary measures All users of the email & Internet services are required to take necessary precautions to protect the confidentiality of email or other records containing personal or confidential information encountered in the performance of their duties or otherwise. They should therefore utilise whatever means of protection, such as passwords, that are available to them to safeguard their email. Since such means of protection are not necessarily foolproof, the security and confidentiality of electronic mail cannot be guaranteed. 3.2 Duties of Administrators of Services Users should be aware that on occasion Network Administrators (IT Co-ordinator and Office Manager Kent Street) may, during the performance of their duties, inadvertently see the contents of email messages. Except as provided elsewhere in the Policy, such personnel are not permitted to do so intentionally or disclose or otherwise use what they have seen. Network Administrators will, from time to time, monitor usage and conduct an audit of email and internet usage. 3.3 Back-ups of Email Users of email services should be aware that even though the sender and recipient have discarded their copies of an electronic mail record, there may be back-up copies of such email that can be retrieved. Systems involved in the transmission and storage of email records may be "backed-up" on a routine or occasional basis to protect system reliability and integrity, and to prevent potential loss of data. The back-up process results in the copying of data onto storage media that may be retained for periods of time and in locations unknown to the originator or recipient of electronic mail. The practice and frequency of back-ups and the retention of back-up copies of email vary from system to system. 3.4 Archiving of Email (INSERT ORGANISATION NAME) does not maintain, at present, central or distributed archives of all email sent or received. If email is backed up (see paragraph 3.3), the purposes are to assure system integrity and reliability, not archiving and retention. Users of email services should not rely on electronic mail for purposes of archiving and retention where this involves (INSERT ORGANISATION NAME) records. Consideration should be given to printing emails where archiving or retention becomes an issue for reasons of policy or sound business practice. 4.0 Inspection and Monitoring of Email & Internet usage Users should be aware that most software used to operate networks log transactions and communications. These logs will normally include the email addresses of senders and recipients of email and the time of transmission. The content of emails themselves would not normally be logged but may be stored on mail servers. Similarly, web server logs record information on the sites people visit. The keeping of these logs is usually necessary for the routine maintenance and management of networks and systems. System Administrators are also capable of reading the contents of emails sent and received by the corporate network. 4.1 Privacy (INSERT ORGANISATION NAME) , in general, cannot and does not wish to be the arbiter of the contents of email. (INSERT ORGANISATION NAME) respects free speech and privacy of information. (INSERT ORGANISATION NAME) therefore does not permit retrieval, inspection, monitoring, or disclosure of email messages without the prior consent of the addressee of such messages except as provided for in paragraphs 3.2 and 4.3. 4.2 Consent and Compliance The email addressee's consent shall normally be sought prior to any inspection, monitoring or disclosure of (INSERT ORGANISATION NAME) email records, except as provided for in paragraph 4.3. To comply with this and other (INSERT ORGANISATION NAME) policies, and to enable (INSERT ORGANISATION NAME) to meet its business and legal obligations, staff of (INSERT ORGANISATION NAME) are expected to comply with management requests for copies of electronic mail that pertain to the business of (INSERT ORGANISATION NAME) . In the event of failure to comply with such requests the provisions of paragraph 4.3 apply. 4.3 Inspection of Electronic Mail without Consent (INSERT ORGANISATION NAME) shall only permit the inspection, monitoring or disclosure of electronic mail without the consent of the holder of such email when:
When access to an individual's electronic mail must be restricted or the content of an individual's email must be retrieved, inspected, monitored, or disclosed:
5.0 Policy Violations Violations of (INSERT ORGANISATION NAME) policies governing the use of (INSERT ORGANISATION NAME) Email & Internet services may result in restriction of access to (INSERT ORGANISATION NAME) information technology resources in addition to any disciplinary action that may be applicable under other (INSERT ORGANISATION NAME) policies, guidelines or enterprise agreements, up to and including dismissal. 6.0 Responsible Officer Position of relevant person/people) are responsible for the control and administration of the policy and Code of Practice. 7.0 Area Responsibilities It is the responsibility of each (Department Manager / relevant person) to ensure the intent of (insert organisation name) Email & Internet policy and practice is supported. |