2 pages memo due in 12 hours
Administrative Regulations
Subject/Topic: Electronic Communications and Internet Services
Topic Category: General
Department Lead: Department of Technology Services, Office of the CIO
Summary: To define the Internet Use Policies (IUP) for all Arlington County Government employees, contractors, consultants, constitutional employees, temporaries, and volunteers. These policies define access to and use of these services and ensure that their use is consistent with County policies, applicable laws, and the individual user’s job responsibilities. These resources are provided by the County to enhance the ability of the user to perform job duties, improve customer service, increase productivity, reduce paperwork and provide opportunities for professional growth through approved webinars and training.
1. Purpose: This policy is designed to protect the County’s computer networks and data assets against unauthorized and malicious use as well as to prevent potential misuse of County resources. These policies recognize that efficient use of these resources may:
• Enhance partnership, community involvement and the exchange of information and
ideas among citizens, businesses and local government.
• Provide information both internally and to the public about the activities and services
of the County.
• Improve the quality, productivity and general cost-effectiveness of the County’s work
force.
2. Scope: The scope of this policy is limited to electronic communications and internet services. This policy covers County “networked resources,” which for purposes of this policy includes the County’s email system, network, software, applications, databases, internet/intranet access, all computer systems, internally hosted or cloud-based, hardware, temporary or permanent files and any related systems or electronic devices authorized personally owned or leased by the County and/or made available to employees or other authorized users (as defined in Section 2) in their role as employees or authorized users.
Internet services include the following:
a. Internet access and usage. Internet access is defined as the ability to connect to the
Internet and to access the Internet.
b. Electronic Messages sent using the County’s domain as well as sent through the
Internet. This policy is applicable to e-mail, text messaging, social media posts, messages sent to list services, user groups and other Internet forums.
c. VPN – Use of Internet resources while connected through a Virtual
Private Network.
d. Installation of Network devices. Appliances such as routers, hubs, switches, wireless
access points, or other devices which facilitate authorized access to County servers, messaging systems or the Internet.
e. Social Media. This policy supplements the County’s regulations regarding social media use and maintenance of web sites.
f. Calendaring. The electronic systems provide a scheduling function whereby employees may schedule meetings with each other and non-County personnel. Calendaring capability also provides for the reservation of resources such as conference rooms and equipment.
3. Roles and Responsibilities:
The Chief Information Officer (CIO) and the various sponsor groups of his/her peers from the Executive Leadership Team and Constitutional Officers have managerial responsibility for the technology initiatives contained in this regulation. The CIO is responsible for reviewing and approving any exceptions to this policy.
Department of Technology and Information Services (DTS)
DTS is responsible for providing, administering, and insuring security and records management compliance of messaging services, as well as a secure Internet/Intranet connections.
County networked resources are intended for County government business purposes only. Therefore users (as defined in Section 2) must adhere to this policy. If in doubt, the burden of responsibility is on the user to inquire as to acceptable and unacceptable uses prior to accessing network resources. Questions concerning whether a particular use is acceptable or unacceptable should be referred to the department director, delegated representative or the DTS Service Desk.
Users are expected to know how to manage records in an electronic messaging system and to comply with County’s records retention policies. Questions related to records retention should be directed to the DTS Service Desk.
4. Ownership and Privacy.
All information created, generated, transmitted, and stored by users is the property of the County. It is not considered private. The County reserves the right to set or restrict permissions and accessibility rights to all data resources as it deems necessary. The Chief Information Security Officer (CISO) will authorize access to data stores upon written request.
5. Access and Monitoring.
There is no expectation of privacy when using County networked resources whether those resources are locally hosted or cloud-based. The County reserves the right to monitor and/or log all network activity with or without notice, including messaging and all web communications. The County will not monitor individual messaging or device tracking without proper approval following established County processes.
However, in the routine course of technology administration, the County undertakes construction, repair, operations and maintenance of messaging systems that may occasionally result in accessing random transmitted or stored messages. County servers also maintain logs of Internet activity, i.e., sites accessed by users and Internet traffic. County servers also maintain logs reflecting messaging traffic, i.e., to whom messages were sent and received; including external destinations. Monitoring of a specific activity, or an individual’s use, may be performed without consent or knowledge of the individual only under the following circumstances and only when authorized by the County Information Security Officer. By way of example, not limitation, monitoring and/or access may be authorized:
· If required by law or in defense of a charge, claim, notice of violation or lawsuit.
· When reasonably necessary to investigate a possible violation of a County Policy, breach of security or in support of a FOIA related request.
· When there is reasonable suspicion that a user has committed or is committing a crime.
· If there is a suspected violation of this policy, of any Administrative Regulation and/or to investigate claims made against the County, the CISO will notify the Office of the County Attorney.
· To comply with the requirements of the Virginia Freedom of Information Act and the Virginia Public Records Act.
· To comply with any Litigation Hold requirements or legal discovery requests.
· To resolve a technical problem.
6. Acceptable Uses:
1. Network resources shall be used:
a. In the pursuit of County goals, objectives and activities. Official County business conducted via networked resources and electronic communications shall comply with all statutory requirements;
b. When electronic communications are the most efficient and/or effective means of accomplishing the County's business;
c. For County work-related job responsibilities, research, activities and/or information gathering;
d. Using utility and applications software that accomplish tasks and fulfill job functions that are under provided under a license issued to the County;
e. To facilitate communication and collaboration between staff and/or other appropriate entities or persons; and/or
f. To support the professional activities or projects of users (e.g. electronic scheduling of meetings, electronic calendars, project management software, address books and completion of work related forms electronically) that support the user’s official County responsibilities and job duties.
2. Incidental and reasonable personal use is permitted so long as it does not interfere with the conduct of a user's work, the effective delivery of services, incur cost to the County, generate more than incidental traffic or networked resources, and/or conflict with Unacceptable Uses (stated in Section 9). This limited personal use of County networked resources is best accomplished during breaks and lunch time or to address critical personal matters.
3. When using electronic communications provided by Arlington County, employees are representing the County government and should conduct themselves as County government representatives at all times. Electronic messaging is considered an official communication of County government. In addition:
Only signature lines that provide an employee’s name, title, physical address and contact information should be appended to any email sent in furtherance of County business or sent through County networked resources.
“Tag-lines” that are unrelated to the users work functions are not permitted.
4. Care must be taken when handling confidential information. Confidential information contains Personally Identifiable Information (PII) including financial information, proprietary information, social security numbers, credit card or bank account numbers; health records and personally identifiable health information. Such information should be sent via encrypted messaging and stored encrypted when at rest. If sent internally, such messaging should be limited to a “need to know” basis and sent in accordance with department procedures in effect at the time of transmittal. All such messaging should be marked “confidential” and no Personal Identifiable Information (PII) should be included in the subject line of email or posting in social media applications.
5. Use of network resources must conform to the County’s anti-harassment and discrimination policies as stipulated in Administrative Regulation 2.7 addressing Personnel Rules.
7. Unacceptable Uses:
Unacceptable uses include, but are not limited to, the following:
a. Interference with the security or operation of County networked resources including, but not limited to, sabotage of or vandalizing any County or Internet hardware, software, network or data file.
b. Deliberate introduction or distribution of computer viruses, malware, or spy ware such as keystroke logging tools.
c. Use of network resources beyond the uses outlined in Section 8 or copying, sale or distribution of networked resources.
d. Alteration of County-provided Internet access configurations in any way except as authorized in writing by the director of DTS.
e. Unauthorized use of copyright protected works including software, electronic files (including, but not limited to, messages, e-mail, text files, image files, database files, sound files and music files), movies or data or making available copies of such works or files using County government-provided electronic communications services. Permission from the owner for the use, distribution or copying of such information must be properly documented.
f. Except as may be necessary for the performance of the user's job, access to, generation, transmission, receipt or storage of information that is abusive, discriminatory, harassing, associated with gambling or has sexually explicit content as set forth in Virginia Code Section 2.1-804 as amended.
g. Unauthorized access to County data intended for internal operations in support of non-county activities related to outside employment or personal gain.
h. Unauthorized access to materials, systems or files that are restricted by law or County policy.
i. Release or distribution of confidential information required by law or policy.
j. Representation of oneself with an anonymous or fictitious name or hosting a personal web site on a County server.
k Transmission of chain messages.
l. Transmission of global (meaning to all users) or mass (appropriate number of users to be defined by agency head) e-mails, even when the content is related to County business must be authorized by the Communications Office (County Managers Office). Department directors, or designees, may authorize employees to send messages related to County business to all members of a work or organizational group, or team that exceeds 50 users.
m. Any activities unrelated to County business in the pursuit of profit or gain for the user or on behalf of any other individual or organization.
n. Unauthorized access of County data intended for internal operations or any use of this data for political activities such as, but not limited to, solicitation of funds, or endorsement or advocacy of any particular candidate or political party.
o. Storage of County data on third-party (SaaS or cloud) applications (including, but not limited to, file storage and sharing services such as Dropbox) without prior approval from DTS.
p. Storage of County data on personal devices or media, if the device or media does not have Mobile Device Management software installed and activated.
q. Storage of official County records in applications that have not been approved by the Chief Records Management Officer, or storage of official County records on media that is not backed up on a routine basis.
r. Violating the rights of others by publishing or displaying any information that is defamatory, obscene, known to be false, inaccurate, abusive, profane, sexually oriented, threatening, racially offensive, and considered to be bullying or otherwise biased, discriminatory or illegal or otherwise insensitive forms of humor.
s. E-mail or social media discussions involving any subject that interferes with work or where items are debated at length.
t. Unreasonable work time surfing the Internet, as determined by the employee’s job functions and the task involved.
u. Misrepresenting one’s position in the County for activities unrelated to official County business.
v. Using County networked resources for private consulting or personal gain.
w. Uses that violate County warranties or terms of use for County-provided devices or software.
x. Forwarding (bulk or individually) of County official email accounts to personal email accounts without prior authorization from the CISO.
y. The use of or installation of routers, hubs, switches, wireless access points, Internet of Things (IoT) devices, etc., without authorization from DTS.
z. Use of technology to capture and record video and/or audio content where privacy is presumed or where such use has not been authorized.
8. Compliance with Copyright, Licensing and Terms of Use:
Users are required to honor copyright laws of any materials and all site or software terms of use and licensing restrictions. Software piracy is both a crime and a violation of County policies. Illegally reproducing software may be subject to criminal and civil penalties as well as disciplinary action. In no instance shall any user disassemble, reverse engineer or otherwise reproduce any software or code provided by the County. Further, all software must be used strictly in accordance with its license agreement, including any restrictions on the number of users.
Please be aware that many copyright and licensing restrictions do not allow a person to store copies of a program on multiple machines, distribute copies to others via disks or Internet or to alter the content of the software unless permission has been granted under the license agreement. Most times, supervisory permission is also required by the County. If copyrighted material is downloaded, it must be with permission of the owner and its use must be strictly within the agreement as posted by the owner, author or otherwise in accordance with current copyright law.
9. Virus protection:
The County’s standard anti-virus software must be installed on County PCs prior to accessing County networked resources. DTS is responsible for the installation of virus protection software on PCs that departments purchase. In the event updates do not occur successfully, users must contact the DTS HELP DESK (ext. “4357”) to open a trouble ticket so that the updating process can be re-established.
Any virus detected must be reported to the DTS HELP DESK.
10. Security:
County users are responsible for their Email and Social Media accounts. To ensure security compliance, users are prohibited from using another person’s user ID, password, files, systems, even if that person has neglected to safeguard his/her user ID. Users are specifically prohibited from messaging under another user’s name or spoofing another individual’s identity.
Employees, contractors, or vendors responsible for connecting outside networks to the County’s network are liable for any damages which may occur as a result of the connection. Safeguards such as Firewall protection, VPN, Data Loss Prevention, Encryption, and other security technologies must be provisioned and authorized by DTS. DTS must be notified prior to any connection between a non-county and county-network. Every department that uses the County’s Internet gateway must be authorized and registered through DTS. Every “device” or “host” connecting to the Internet must have a unique identifier assigned by DTS.
Internet security protocols can be compromised. Users should assume that all transmissions over the Internet via e-mail, the Web, or other media, such as file transfer protocol (FTP), are publicly available, and individuals other than the intended recipient(s) can intercept such information (reference Section 8.4).
When working remotely users must ensure their telework device have updated anti-virus and firewall software operating on their telework device.
When using wireless routers for telework users must activate password protected access as well as transmission encryption (example WPA2).
When using Mobile Devices (such as iPhones, iPads, etc.) the user must ensure the device has DTS enabled Mobile Device Management (MDM) installed and activated. If any smart device (County or BYOD), which contains County information is lost or stolen the user must notify DTS Service Desk within 24 hours (Reference DTS MDM policy).
Password protection of all electronic devices is required. All users shall be required to change network access passwords in a manner and time as determined by DTS. Passwords are not to be shared or otherwise distributed by any user except as authorized. Passwords must be changed every 90 days without exception.
Contractors who may have access to County Confidential Information shall be required to sign the County’s Nondisclosure of Data and Security Agreement prior to commencing work under any County contract.
The provision of new applications must comply with DTS Information Governance requirements as defined by the CISO and Chief Records Management Officer (CRMO).
.
11. Access violations:
It is a violation for any user, including the system administrator, security administrator, supervisors and department directors to access any e-mail system, files or communications that do not belong to them except for authorized business purposes or as noted in Section 7. The County reserves the right to monitor access in order to ascertain whether unauthorized access has been attempted.
12. Failure to comply:
Employees who fail to comply with this policy may be subject to disciplinary action that could result in cancellation of system access, disciplinary action up to and including termination of employment and/or criminal prosecution.
13. Policies specific to Internet access and usage:
a. Integrity of Information. When using information from an Internet site for County business decisions, employees should verify the integrity of that information, i.e., that the site is updated on a regular basis (the lack of revision date might indicate out-of-date information) and that it is a valid provider of the information. Just because it is there does not mean that it is accurate or valid.
The County has no control or responsibility for content on an external server not managed by DTS.
b. Web-based Applications. The use of free web-based applications must be approved by DTS.
· Employees are responsible for any County content stored and must ensure that the information is protected and conforms to all County policies.
· Employees are responsible for ensuring that the County information that is used or posted is authorized to be released to the public and any content created by the user is retained in accordance with the County’s record management policies. Both record retention and information security standards apply to non-county hosted Web sites.
· Sensitive or Confidential information requires pre-approval before posting or use in an web-based application and includes but is not limited to Personally Identifiable Health information (ePHI), dates of birth, Social Security Numbers (SSN); Critical Infrastructure (CI) information such as drinking water, sewage pipe, fiber, underground power grid routes, internal disaster recovery plans; and also includes but is not limited to information that in any manner that describes, locates or indexes anything about an individual including, but not limited to, his/her (hereinafter “his”) real or personal property holdings, and his education, financial transactions, medical history, ancestry, religion, political ideology, criminal or employment record, Social Security Number, tax status or payments, date of birth, address, phone number or that affords a basis of inferring personal characteristics, such as finger and voice prints, photographs, or things done by or to such individual, and the record of his presence, registration, or membership in an organization or activity, or admission to an institution or other sensitive information and should not be content that is associated with free WEB based applications which often times retain or track the content.
· Free web tools that help develop presentation materials are not in the control of DTS are not authorized for use by employees.
c. Commercial Internet accounts. All access to the Internet, for County purposes or on County equipment, will be provided through the County’s Internet access facilities. Commercial subscription accounts (e.g., COMCAST, AOL, etc.) are not authorized.
d. Streaming media. Certain features of the Internet, such as streaming audio and video, can saturate the County’s Internet connection, and are only to be used for County business.
e. File Transfer Protocol (FTP). A user should not FTP to any system on which they do not have an account, or that does not allow anonymous FTP services. Downloaded files may contain viruses. Observe the County’s policy with respect to scanning files for viruses. Observe any posted restrictions on the FTP server.
f. Telnet. Users should not Telnet (a program that allows the user to access distant computers via TCP/IP connections) to machines on which they do not have an account, or where there is no guest account. Users should observe any posted restrictions when they Telnet to another machine.
g. Remote Access. Users who are authorized to Telework must use the DTS provided Remote Access (RA) method. Other remote access services are not authorized for use. Services such as “LOGMEIN”, “GOTOMYPC”, VNC, and Team Viewer, etc., are not under the control of DTS and thus have less than optimal security and are not permitted to be used in conjunction with County networked resources.
14. Electronic Communications:
Employees provided with County account(s) are to protect their account information by excluding unnecessary exposure of the County email address (not to be published in public media, newspapers, social media applications, websites, etc.). The account is for County business, subject to any limitations outlined in this policy. Electronic communications (e-mail, voice mail, social media, texting, etc.) are subject to the provisions of the Virginia Freedom of Information Act and Virginia Public Records Act and the requirements below:
a. Respond appropriately to messages and follow proper etiquette when fashioning email correspondence.
b. Be aware of email security best practices.
c. Ensure the e-communication is sent to the person/s for which it was intended by
confirming that you have the correct contact information. Use the “reply all” feature carefully.
d. Respond appropriately to Freedom of Information Act (FOIA) requests.
e. Protect e-communications from unauthorized release to third parties.
Sensitive information should be protected through encryption.
f. Utilize official County-issued accounts for communications regarding
transaction of County business.
15. Records Management:
a. Management of Electronic Records
All public records created, stored, or received on County information systems are to be retained in accordance with the provisions of these guidelines and as described in the Virginia Public Records Act (§ 42.1-76 et seq.) and the Library of Virginia (LVA) Records Retention & Disposition Schedules . Additional guidance and policies regarding the management of county records can be found on the Records and Information Management site on ACCommons.
b. Retention of Electronic Communication Records
By default, records generated in electronic communication systems are retained as “Correspondence”, under General Records Retention & Disposition Schedule 19 for localities. Electronic Communication systems include, but are not limited to, e-mail and social media applications.
Electronic Communication systems are not designed to be records management systems. Records other than routine “Correspondence” are not to be stored in electronic communications systems. All Arlington County staff members and contractors are responsible for ensuring that records are retained for the appropriate retention period pursuant to LVA requirements. It is the responsibility of each staff member to determine if records require longer retention by reviewing the appropriate LVA retention schedules and moving the record into a County approved records management system.
16. Related Information:
Separate County policies address Security, Records Management, the County’s web site and public Internet use through Libraries. These policies include (but are not limited to) the DTS Mobile Device Use and Management Policy, Administrative Regulations on Social Media Policy and Guidelines, Use of County Video Systems, and Records and Information Management.
9