Difference between revisions of "Acceptable Use Policy"

From PDP/Grid Wiki
Jump to navigationJump to search
Line 7: Line 7:
 
# <div class="NavFrame"><div class="NavHead">Respect the authorization restrictions set by Nikhef system administrators and users</div><div class="NavContent">Trying to circumvent effective or intended restrictions is not allowed (and unlawful as well). This includes, but is not limited to, accessing data not intended for the User, logging into a service or using an account you are not expressly authorized to access, probing the security of other networks, interfering with another users access to services, or trying to disrupt services or the network. You shall also refrain from trying to intercept or sniff network traffic that is not intended for you. If you find you have access to data or services you should not have access to, inform the Computer Security Incident Response Team through the help desk (helpdesk@nikhef.nl)</div></div>
 
# <div class="NavFrame"><div class="NavHead">Respect the authorization restrictions set by Nikhef system administrators and users</div><div class="NavContent">Trying to circumvent effective or intended restrictions is not allowed (and unlawful as well). This includes, but is not limited to, accessing data not intended for the User, logging into a service or using an account you are not expressly authorized to access, probing the security of other networks, interfering with another users access to services, or trying to disrupt services or the network. You shall also refrain from trying to intercept or sniff network traffic that is not intended for you. If you find you have access to data or services you should not have access to, inform the Computer Security Incident Response Team through the help desk (helpdesk@nikhef.nl)</div></div>
 
# <div class="NavFrame"><div class="NavHead">Respect intellectual property and confidentiality agreements</div><div class="NavContent">So do not publish, post, transmit or re-transmit, or put up on the web, items that violate the rights of any person, including rights protected by copyright, trade secret, patent or other intellectual property or similar laws or regulations including, but not limited to, the installation or distribution of "pirated" or other software products that are not appropriately licensed for your use. Except of course as permitted by applicable Dutch law -- keeping in mind the rest of this AUP.</div></div>
 
# <div class="NavFrame"><div class="NavHead">Respect intellectual property and confidentiality agreements</div><div class="NavContent">So do not publish, post, transmit or re-transmit, or put up on the web, items that violate the rights of any person, including rights protected by copyright, trade secret, patent or other intellectual property or similar laws or regulations including, but not limited to, the installation or distribution of "pirated" or other software products that are not appropriately licensed for your use. Except of course as permitted by applicable Dutch law -- keeping in mind the rest of this AUP.</div></div>
# <div class="NavFrame"><div class="NavHead">Protect your access keys (passwords, private keys, security tokens)</div><div class="NavContent">You are responsible for anything that is done under your account, so by sharing credentials you become responsible for the other persons behaviour. You can and should not be. Access keys are yours and yours only: so do not share your credentials with others. These include your single-sign-on (SSO) password, the passphrase for your certificate's key, the password that protects your SSH key pair. If you feel the need to share, there is always a proper solution. Also, any credential that grants to access to other services (at Nikhef or elsewhere) must be protected with at least a password or better.<br>If you thing your credentials have been stolen of sniffed, inform the help desk immediately and - if possible - change them from a trusted computer and location.<br>.If you have been given credentials for special services (such as a voip telephony roaming password, or access to a generic account) you must protect these accoring to the special instructions given to you.</div></div>
+
# <div class="NavFrame"><div class="NavHead">Protect your access keys (passwords, private keys, security tokens)</div><div class="NavContent">You are responsible for anything that is done under your account, so by sharing credentials you become responsible for the other persons behaviour. You can and should not be. Access keys are yours and yours only: so do not share your credentials with others. These include your single-sign-on (SSO) password, the passphrase for your certificate's key, the password that protects your SSH key pair. If you feel the need to share, there is always a proper solution. Also, any credential that grants to access to other services (at Nikhef or elsewhere) must be protected with at least a password or better.<br><b>If you think your credentials have been stolen of sniffed, inform the help desk immediately</b> and - if possible - change them from a trusted computer and location.<br>.If you have been given credentials for special services (such as a voip telephony roaming password, or access to a generic account) you must protect these accoring to the special instructions given to you.</div></div>
 
# <div class="NavFrame"><div class="NavHead">Report suspected security breaches and misuse</div><div class="NavContent">When you discover vulnerabilities, witness abuse, or see other forms of non-acceptable use, you should report these incidents to the Nikhef Computer Security Incident Response Team through the help desk (helpdesk@nikhef.nl). Of course, you should not attempt to exploit such vulnerabilities to circumvent security controls or harm Nikhef, it's services, staff or reputation in any way - such attempts in itself are a violation of this Acceptable Use Policy.</div></div>
 
# <div class="NavFrame"><div class="NavHead">Report suspected security breaches and misuse</div><div class="NavContent">When you discover vulnerabilities, witness abuse, or see other forms of non-acceptable use, you should report these incidents to the Nikhef Computer Security Incident Response Team through the help desk (helpdesk@nikhef.nl). Of course, you should not attempt to exploit such vulnerabilities to circumvent security controls or harm Nikhef, it's services, staff or reputation in any way - such attempts in itself are a violation of this Acceptable Use Policy.</div></div>
 
# <div class="NavFrame"><div class="NavHead">Do no harm to Nikhef, it's services, staff or reputation</div><div class="NavContent">Harm is more easily done than repaired! Data is easily deleted or modified but hard or impossible to recover. A rash document (as well as of course offensive material) put up on your home page is quickly indexed by search engines and will never disappear from the web again. Confidential data accidentally disclosed will never be a secret again. A defamatory remark will live forever in cyberspace. An infected home laptop or smartphone will quickly poison other systems at Nikhef and many person months will be wasted to recover from the incident. So do no harm.</div></div>
 
# <div class="NavFrame"><div class="NavHead">Do no harm to Nikhef, it's services, staff or reputation</div><div class="NavContent">Harm is more easily done than repaired! Data is easily deleted or modified but hard or impossible to recover. A rash document (as well as of course offensive material) put up on your home page is quickly indexed by search engines and will never disappear from the web again. Confidential data accidentally disclosed will never be a secret again. A defamatory remark will live forever in cyberspace. An infected home laptop or smartphone will quickly poison other systems at Nikhef and many person months will be wasted to recover from the incident. So do no harm.</div></div>

Revision as of 08:09, 27 April 2011

Acceptable Use

This Acceptable Use Policy governs the use of the Nikhef networking and computer services; all users of these services are expected to understand and comply to these rules.

Legalese

Liability

In no event will Nikhef be liable to any user or third party for any direct, indirect, special or other consequential damages for actions taken pursuant to this AUP, including, but not limited to, any lost profits, business interruption, loss of programs or other data, or otherwise, even if Nikhef was advised of the possibility of such damages.

Complaints

Complaints regarding violations of this AUP, as well as concerns regarding objectionable material sent from or distributed via Nikhef, will be accepted via e-mail at abuse@nikhef.nl, so long as a valid return address is included. Nikhef must be able to independently verify each instance of abuse: for objectionable email each complaint must include the COMPLETE TEXT OF THE OBJECTIONAL MESSAGE, INCLUDING ALL HEADERS. Please do NOT send excerpted parts of a message; sending a copy of the entire message, including headers, helps to prevent misunderstandings based on incomplete information, or information used out of context. Full headers demonstrate which path the message has taken, and enable us to determine whether any part of the message has been forged. This information is vital to our investigation. If you consider material located on Nikhef resources (e.g. published via its web site) to infringe on your rights, provide the complete URL, the time you visited this URL, and complete and sufficient evidence as to why you consider such a publication would infringe on your rights under Dutch Law.

Responsibility

Nikhef is not responsible for the content of email communications sent by its users, not for information published on user personal home pages. This responsibility rests with the user. At its sole discretion, Nikhef reserves the right to remove materials from its servers and to terminate access to services for the user that Nikhef determines has violated this AUP.

Modifications

Nikhef retains the right to modify the AUP at any time. Such modifications shall become effective at the moment they are adopted by Nikhef and will apply to all users, current and future.