Terms of Use for Technical Assets Policy
Document Classification: Internal – Restricted
 

  1. General Items
    • 1-1. Information must be handled according to the specified classification, in accordance with data classification policy and data protection and information security policies of Najran University, ensuring the confidentiality, integrity, and availability of information.
1-2. It is prohibited to infringe upon the rights of any individual or company protected by copyrights, patents, or other intellectual property rights or similar laws and regulations; including installing unauthorized software or through illegal means.
  • 1-3. Must not leave publications on the shared printer without supervision.
  • 1-4. External storage devices (such as USB drives, portable hard drives) must be securely and appropriately protected, such as by setting a suitable password and storing them in an isolated and secure location.
  • 1-5. It is prohibited to use your access card or another user’s or subordinate’s password on any device.1-6. Must comply with the Cleanliness Policy and General Hygiene Standards; and ensure that the desk surface and display screen are free of classified or sensitive information.1-7. Prohibits the disclosure of any information pertaining to Najran University, including information related to systems and networks, to any party or entity not authorized, whether internally or externally.1-8. Prohibits the dissemination of information related to Najran University through media outlets or social media platforms without prior authorization.
  • 1-9. Prohibited is the use of university assets of Najran in pursuing personal gain or any private activities or endeavors that are inconsistent with the University’s mission and security.
  • 1-10. It is prohibited to link personal devices to the networks or systems of Najran University without obtaining prior approval, and in accordance with the mobile device security policy (BYOD).
  • 1-11. It is prohibited to engage in any activity that exceeds approved protection controls, such as installing malicious software or bypassing antivirus and firewall systems, unless prior approval and authorization are obtained from the Cyber Security Administration.
  • 1-12. The Cybersecurity Management retains the right to monitor employees of the University’s systems, networks, and personal accounts, and to review them periodically to ensure compliance with cybersecurity policies and standards.
  • 1-13. Prohibits the hosting of individuals not authorized to access sensitive areas without obtaining prior approval.
  • 1-14. Must wear the identification card in all facilities of Najran University.
  • 1-15. Must notify the Cybersecurity Administration immediately in case of loss, theft, or damage to information.
  • Asset and Device Protection
    • 2-1. Prohibits the use of external storage media (such as USB drives and portable storage devices) without obtaining prior approval from the Cyber Security Administration.
  • 2-2. Prohibits any activity that affects the efficiency of systems and technical assets, including actions that prevent users from obtaining higher authorities or privileges without prior approval from the Cybersecurity Department.
  • 2-3. Please ensure the device (your laptop or desktop) is secured before leaving the office; this involves locking the screen or signing out (Sign out or Lock) at the end of your working hours or for short absences.
  • 2-4. Prohibits leaving classified information (paper or electronic) in easily accessible places where unauthorized individuals may view it.
  • 2-5. Prohibits the installation of any external tools (hardware or software) on the computer without obtaining prior approval from the Cyber Security Administration.2-6. Must be reported to the Cybersecurity Department immediately upon suspicion of any activity or behavior that may cause damage to university of Najran’s computers or its technical assets.
  • Acceptable Use of the Network, Software and Internet
    • 3-1. Cyber Security Administration should be notified when suspicious websites or links are detected; this also applies if documents relating to functional operations relate to intellectual property infringement risks.
    3-2. Prohibits the use of any unauthorized software or copyrighted materials, patents, or intellectual property without legal authorization.3-3. Only approved browsers should be used to access the internal network or Internet; unauthorized browsers are not permitted.3-4. Prohibits the use of technologies that allow bypassing network intermediaries (Proxies) or firewalls to access the Internet, including virtual private network (VPN) software.
  • 3-5. Prohibits the downloading or installation of any software or tools that violate university policies or applicable regulations from the university network or internet without obtaining prior approval from the Cyber Security Administration.
  • 3-6. Prohibits the use of the University network or Internet to download or share unauthorized files or media.
  • 3-7. Handle emails with caution; and if there is suspicion of a cybersecurity risk (such as a virus or phishing) report to the Cybersecurity Administration immediately.
  • 3-8. Security audits and penetration testing must be conducted to identify vulnerabilities; this includes conducting tests by licensed external parties after obtaining prior approval from the Cyber Security Administration.
  • 3-9. Prohibits the use of file sharing websites or cloud storage services without obtaining prior approval from the Cybersecurity Administration.
  • 3-10. Prohibits visiting any suspicious site or one related to hacking techniques or the consumption of illegal substances.
  • Acceptable Use of Email and Communication Systems
    • 4-1. The use of the University's email, telephone, fax, or electronic fax is prohibited for activities unrelated to work, and must comply with cybersecurity policies and their standards.
    4-2. Prohibits the trading of messages containing inappropriate or unacceptable content with internal or external parties.4-3. When sending sensitive information via email, you must adhere to approved security methods to ensure encryption and protection.4-4. You should not register the email address of Najran University on any website that is unrelated to work duties.4-5. Must notify the Cybersecurity Management immediately upon discovering any content in emails that may cause damage to assets or systems.4-6. The Cybersecurity Administration reserves the right to examine the contents of university email messages to verify that the user has obtained the necessary approvals and in accordance with the applicable procedures.4-7. Prohibits the opening of suspicious or untrusted emails and attached files under any circumstances.
  • Visual and Audio Meetings
    • 5-1. It is prohibited to hold visual or audio (Video/Voice) conferences without prior authorization via the internet.
  • 5-2. It prohibits conducting communications or holding meetings on programs or devices not approved by the university for official purposes.
  • Passwords and Account Security
    • 6-1. Strong and secure passwords must be chosen, and passwords for University systems and assets should be kept away from others. Passwords for University systems may not be used to access personal accounts or vice versa.
    • 6-2. You must change your password the first time when a new password is provided to you by an administrative staff member, and it must be changed periodically according to university policies.
  •