- Home
- Information Technology
- Security
- Acceptable Use Policy
Information Technology Acceptable Use Policy (AUP)
Issuing Office: Chief Information Officer, Information Technology Services
Policy Number: FY26-ITS-001-06
Policy Name: Acceptable Use Policy
Original Date Issued: August 14/2019
Revision #: 06
Last Update: July 15, 2026
I. Policy Statement
The University of Massachusetts Boston ("the University") provides technology services to support University activities, including teaching, research, public service, and the open exchange of ideas. This document outlines the Acceptable Use Policy ("AUP" or "Policy") governing the use of University technology resources. All users of University technology resources are expected to use these systems responsibly to ensure their reliable, secure, lawful, and academically appropriate use. Misuse of these resources may pose risks to the University community, its information assets, or its compliance obligations and may result in corrective action consistent with University policies and applicable law.
II. Purpose
The purpose of this policy is to:
-
Ensure lawful, secure, and responsible use of the University's information technology resources.
-
Lawful: The University must comply with applicable state and federal laws and regulations governing the use of information systems.
-
Secure: Information security safeguards protect University systems, institutional data, and the privacy of community members.
-
Responsible: Technology resources should be used in ways consistent with University policies and community standards.
-
Shared Resource Stewardship: University technology resources are shared institutional assets and should be used in a way that does not interfere with others' access or system reliability.
-
-
Support the University's mission by providing reliable access to shared technology infrastructure for teaching, research, administration, and collaboration.
-
Clarify user responsibilities related to the use of University technology resources.
III. Scope
The AUP applies to all University information technology resources, including University equipment, use of University technology services (e.g., network, applications), and use of personal devices for work-related purposes or while using the University's technology services. It covers all users of these resources, including, but not limited to, employees, students, contractors, consultants, temporary staff, visiting scholars, and third-party affiliates.
University information technology resources include, but are not limited to, the following:
-
Personal Computing Endpoints (Desktop and laptop computers, tablets, and other mobile devices). Personal computers connected to the University network or used for work-related purposes are subject to the AUP.
-
Infrastructure (Networks, core systems, storage media, and servers).
-
Applications (Electronic mail, database applications, and software). Use of these applications, both on and off campus, is covered by the Policy.
-
Physical Computing Equipment (Computer labs, data centers, and kiosks).
-
Data (Internet, Intranet, Cloud, Off and On-premises Data).
IV. University Rights and Reminders
The University is committed to providing robust technology resources for the community and to ensuring their efficient, ethical, safe, and lawful use. The University is also committed to safeguarding the integrity of its technology resources while upholding user privacy. To ensure cybersecurity and comply with applicable laws, the University:
-
Employs automated monitoring tools and processes to detect potential cybersecurity threats across its systems and networks.
-
Data Ownership
-
Data stored or transmitted on University information systems may be subject to institutional policies, record retention requirements, and applicable law.
-
The University does not claim ownership of all content stored on its devices or systems. Ownership and intellectual property rights remain governed by:
-
University intellectual property policies
-
Applicable law
-
Research agreements and grant terms
-
Faculty intellectual property protections
-
-
Institutional systems may contain a mix of University records, research data, academic work product, and personal files.
-
Users should be aware that information related to University business may be subject to disclosure under public records laws.
-
-
Searches/Inspection
-
The University may review data stored on or transmitted through institutional systems when required for:
-
Information security investigations
-
Compliance with legal obligations
-
Public records requests
-
Credible evidence of policy violations.
-
-
Such reviews are rare and are conducted only by authorized personnel in accordance with University procedures and applicable law.
-
Personal accounts and personal messaging services are not subject to routine inspections.
-
-
Device Seizure
-
The University may temporarily secure or preserve institutional devices or systems when necessary to comply with:
-
Legal obligations
-
Public records requests
-
Information security investigations
-
-
Such actions occur only when there is a documented need and are coordinated by appropriate University authorities.
-
V. Responsible Use of University Technology Resources
The University provides technology resources to support teaching, research, administration, and collaboration across the UMass Boston community. All users share responsibility for using these resources in a secure, lawful, and responsible manner.
The following guidelines outline expectations for the appropriate use of University technology systems and services.
-
Security Awareness and Training
Employees are required to complete periodic information security and privacy awareness training as required by state mandates and University policy. These training programs help protect University systems, data, and community members from cybersecurity risks.
-
Account and Credential Protection
Users are responsible for safeguarding their University login credentials and should not share passwords or authentication tokens.
Users should:
-
Access only the systems and information for which they are authorized.
-
Use approved tools for file sharing and delegated access rather than sharing account credentials.
-
Promptly report suspected credential compromise or any unauthorized access.
For shared workstations, such as those in labs or shared faculty offices, users should log out when finished and avoid storing credentials on shared devices.
Multi-Factor Authentication (MFA) must be enabled when required for University systems.
-
-
Responsible Communication
University communication systems, including email, collaboration tools, and online meeting platforms, should be used in accordance with University policies and applicable law.
Users should exercise professional judgment when communicating through University systems and take appropriate steps to protect confidential or restricted information.
-
Protection of Sensitive Data
Users must protect sensitive or regulated information in accordance with applicable laws and University policies.
Examples of sensitive information include:
-
Student records protected under FERPA
-
Employee personnel records
-
Financial account information
-
Protected health information
-
Confidential or restricted University data
Sensitive data should be handled, stored, transmitted, and disposed of using appropriate safeguards. When required by law, regulation, or University policy, sensitive information must be protected using encryption or other approved security controls.
-
-
Use of Artificial Intelligence Tools
Artificial intelligence (AI) tools may be used to support University activities, including teaching, research, and administrative work. Users should exercise caution when sharing information with such systems.
Sensitive or regulated information should not be entered into external AI services unless those services have been approved by the University for that purpose.
Institutionally supported AI tools should be used when working with University data or internal documents.
Locally hosted research tools or AI models that process data entirely on a user's device and do not transmit data externally are generally outside the scope of these restrictions.
Meeting participants must be notified if AI transcription or meeting summarization tools are used. Users should also be aware that transcripts or summaries related to University business may be subject to public records requests.
-
Compliance with Laws and Intellectual Property Rights
Users must comply with applicable laws, contractual obligations, and University policies when using technology resources.
This includes respecting copyright, licensing agreements, and intellectual property rights when using software, digital materials, or online services.
-
Privacy Protection
Users must respect the privacy and personal rights of others when accessing or handling personal information. Personal data should be handled in accordance with applicable privacy laws and University policies.
Confidential information should be shared only when permitted by job responsibilities, University policy, or legal requirements.
-
Incident Reporting
Users should report suspected information security incidents, data breaches, or the loss or theft of devices containing University data to the IT Service Desk or the Information Security Office as soon as possible.
Prompt reporting enables the University to respond quickly and limit potential risks to individuals and the institution.
-
Use of Personal Devices
The University recognizes that employees may occasionally use personal devices to conduct University business.
When doing so, users must:
-
Follow this Acceptable Use Policy when conducting University-related work.
-
Ensure that personal devices used for substantive University work meet reasonable security standards.
-
Be aware that University-related records stored on personal devices may be subject to public records laws.
This policy applies only to University-related activities conducted on personal devices and does not grant the University access to personal content.
Use of a personal device solely for authentication purposes, such as Multi-Factor Authentication (MFA), does not grant the University access to personal device data.
-
Prohibited Uses
University technology resources may not be used in ways that compromise the security, integrity, or lawful operation of University systems.
Examples of prohibited activities include:
-
Unauthorized access to systems, accounts, or data
-
Interference with the normal operation of University networks or technology services
-
Unauthorized disclosure of sensitive or protected information
-
Circumvention or disabling of security controls
-
Harassment, threats, or unlawful activity conducted through University systems
-
Intentional damage to University systems, networks, or data
These examples are illustrative, not exhaustive. Additional technical and operational requirements are outlined in the University's information security standards and procedures.
VI. Compliance
All members of the University community who use University technology resources are expected to comply with this Acceptable Use Policy and with related University information security policies and standards.
Failure to comply with this policy may result in actions consistent with applicable University policies, collective bargaining agreements, and relevant laws. Such actions may include restrictions on technology access, administrative review, or disciplinary action.
The University may limit or suspend access to technology resources when necessary to protect the security and integrity of University systems or to comply with legal or regulatory requirements.
If evidence of potential violations of University policy or applicable law is discovered during routine system administration or security investigations, the matter may be referred to the appropriate University office or, if required, to law enforcement authorities.
University information security standards and procedures provide additional guidance for the secure operation of the University's systems and services.
VII. References
This policy aligns with applicable laws, regulations, and recognized information security frameworks.
Applicable Laws and Regulations
-
Family Educational Rights and Privacy Act (FERPA)
-
Health Insurance Portability and Accountability Act (HIPAA)
-
Gramm-Leach-Bliley Act (GLBA)
-
Massachusetts Data Security Regulations (201 CMR 17.00)
Security Frameworks
-
Center for Internet Security (CIS) Critical Security Controls
-
National Institute of Standards and Technology (NIST) Cybersecurity Framework
VIII. Version Control
Version Control
| Revision Number | Date | Name | Description |
|---|---|---|---|
| R1 | 08/14/2019 | Wil Khouri | UMB-AUP-ISOPOL04-19-R1 |
| R2 | 05/31/2021 | Wil Khouri | UMB-AUP-ISOPOL04-21-R1 |
| R3 | 12/10/2021 | Wil Khouri | UMB-AUP-ISOPOL04-21-R2 |
| R4 | 04/30/2024 | Wil Khouri | UMB-AUP-ISOPOL04-24-R1 |
| R5 | 02/28/2025 | Wil Khouri | UMB-AUP-ISOPOL04-25-R1 |
| R6 | 07/15/2026 | David Albrecht Wil Khouri | FY26-ITS-001-06 |
| R7 | (Next Rev.) 07/2028 |
Signature Page
APPROVED BY:
David M. Albrecht
Chief Information Officer
APPROVED BY:
Wil Khouri
Assistant Vice Chancellor and Chief Information Security Officer