Objective
These Terms of Use are intended to define the policy for the proper use of the website, email, and electronic services. They also aim to reduce cybersecurity risks associated with the use of the Islamic University’s systems and assets and to protect them from external and internal threats by maintaining the confidentiality, integrity, and availability of information.
Scope and Applicability
These Terms cover the proper use of the website, email, and electronic services and apply to all Islamic University personnel.
Terms of Use
1. General Provisions
- Information must be handled according to its designated classification and in compliance with the Islamic University’s Data Classification Policy and Data and Information Protection Policy, in a manner that ensures the confidentiality, integrity, and availability of information.
- It is prohibited to violate the rights of any person or company protected by copyright, patents, other intellectual property rights, or similar laws and regulations, including, but not limited to, installing unauthorized or illegal software.
- Using passwords belonging to other users, including those of managers or subordinates, is prohibited.
- Publishing information related to the Islamic University through media outlets or social media platforms without prior authorization is prohibited.
- University systems and assets must not be used for personal benefit, personal business, or any purpose unrelated to the University’s activities and operations.
- Any activity intended to bypass the University’s security controls, including antivirus, firewall, and anti-malware protections, is prohibited without prior authorization and must comply with the procedures approved by the University.
- The Cybersecurity Department must be notified in the event of information loss, leakage, or theft.
2. Protection of Computer Devices
- Any activity that may affect the efficiency or integrity of systems is prohibited without prior authorization from the Cybersecurity Department, including activities that enable users to obtain elevated privileges or permissions.
3. Internet and Software Use
- The Cybersecurity Department must be notified of any suspicious websites that should be blocked, or websites that may have been incorrectly blocked and should be made accessible.
- Intellectual property rights must not be infringed when downloading information or documents for work-related purposes.
- The use of unlicensed software or other unauthorized intellectual property is prohibited.
- A secure and authorized web browser must be used to access the internal network or the Internet.
- The use of technologies that bypass the proxy or firewall to access the Internet is prohibited.
- The Cybersecurity Department must be notified when a cybersecurity risk is suspected. Users must also exercise caution when security warnings appear while browsing the Internet or internal networks.
- Conducting security scans to identify vulnerabilities, including penetration testing or monitoring the networks and systems of the Islamic University or external entities, is prohibited without prior authorization from the Cybersecurity Department.
- The use of file-sharing websites is prohibited without prior authorization from the Cybersecurity Department.
4. Email and Communication Systems Use
- Email must not be used for purposes unrelated to work and must be used in accordance with applicable cybersecurity policies and standards.
- Exchanging messages containing inappropriate or unacceptable content is prohibited, including messages exchanged with internal and external parties.
- Encryption technologies must be used when sending sensitive information via email or communication systems.
- The Islamic University email address must not be registered on websites unrelated to work.
- The Cybersecurity Department must be notified when an email message is suspected of potentially causing harm to the University’s systems.
- The Islamic University reserves the right to access and disclose the contents of email messages after obtaining the necessary authorizations in accordance with applicable procedures and regulations.
- Suspicious or unexpected emails or attachments must not be opened, even if they appear to originate from trusted sources.
5. Password Use
- Secure passwords must be selected and protected. Passwords used for University accounts must be different from those used for personal accounts, such as personal email or social media accounts.
- Passwords must not be shared by any means, including email, telephone calls, or written notes. They must not be disclosed to any other party, including colleagues or employees of the Deanship of Information Technology.
- The password must be changed when a new password is provided to the user by the system administrator.
Inquiries, Complaints, and Contact Information
If you have any inquiry, complaint, or request regarding your rights in relation to the processing of your personal data, or regarding the provisions of the Acceptable Use Policy in general, you may contact the Islamic University Cybersecurity Department through the following channels:
Responsible Department: Islamic University – Cybersecurity Department
Address: Islamic University, Madinah, P.O. Box 170
Telephone: 920022042
Email:
contact@iu.edu.sa
Extension: 8333