The Management Institute for National Development
Acceptable Use Policy – Information & Communication Technology
Policy Owner: {policyOwner}
Effective Date: {effectiveDate}
Review Date: {reviewDate}
Version: {policyVersion}
1. Introduction
1.1 Purpose
This Acceptable Use Policy (“Policy”) establishes the requirements and standards governing the appropriate, responsible, secure, and lawful use of the Information and Communication Technology (“ICT”) resources of The Management Institute for National Development.
The Management Institute for National Development is an institution of higher education committed to teaching, learning, research, scholarship, innovation, and community outreach. The institution's ICT resources are provided, operated, and maintained to support these objectives and to facilitate the efficient delivery of academic, administrative, research, communication, and institutional services.
Users of The Management Institute for National Development's ICT resources may have access to confidential, sensitive, personal, financial, academic, research, and other institutional information, as well as external networks and systems. Users are therefore required to use these resources responsibly, ethically, securely, and in accordance with:
-
This Policy;
-
Other applicable The Management Institute for National Development policies, procedures, rules, and regulations;
-
Applicable contractual and licensing obligations;
-
Information security requirements;
-
The Data Protection Act, 2020 and applicable data protection requirements;
-
Applicable copyright and intellectual property laws;
-
Cybersecurity and computer misuse legislation; and
-
All other applicable laws and regulations of Jamaica.
Acceptable use means the responsible, reasonable, ethical, and authorized use of ICT resources while respecting the rights and privacy of others, protecting institutional information and systems, maintaining the integrity and availability of ICT resources, and complying with applicable laws and agreements.
1.2 Objectives
The objectives of this Policy are to:
-
Promote responsible and appropriate use of The Management Institute for National Development's ICT resources;
-
Protect institutional information and systems from unauthorized access, misuse, loss, damage, and disclosure;
-
Protect the confidentiality, integrity, and availability of personal and institutional information;
-
Support compliance with applicable data protection, cybersecurity, intellectual property, and other legal requirements;
-
Establish clear expectations regarding user responsibilities and acceptable behaviour;
-
Reduce cybersecurity risks, including phishing, malware, unauthorized access, data breaches, and other threats;
-
Establish appropriate controls for the use of institutional ICT resources; and
-
Provide a framework for addressing suspected or confirmed violations.
1.3 Scope
This Policy applies to all users of The Management Institute for National Development's ICT resources, regardless of their status or location.
This includes, but is not limited to:
-
Academic and administrative staff;
-
Students;
-
Researchers;
-
Contractors and consultants;
-
Volunteers and interns;
-
Vendors and service providers;
-
Visitors and temporary users;
-
Alumni or other authorized users; and
-
Any other person granted access to The Management Institute for National Development's ICT resources.
The Policy applies whether ICT resources are accessed from within or outside the institution, including through remote access, mobile devices, home networks, or other external locations.
1.4 Definition of ICT Resources
The Management Institute for National Development's ICT resources include all information technology, communication, computing, networking, information, and related services owned, leased, licensed, provided, operated, managed, or otherwise made available by or on behalf of The Management Institute for National Development, regardless of location.
These include, but are not limited to:
-
Servers and central computing facilities;
-
Desktop and laptop computers;
-
Tablets, mobile devices, and other computing devices;
-
Software and applications;
-
Enterprise and administrative information systems;
-
Student information systems;
-
Financial and accounting systems;
-
Human resource systems;
-
Learning management and teaching platforms;
-
Campus Area Networks (CAN);
-
Wide Area Networks (WAN);
-
Local Area Networks (LAN);
-
Wireless networks;
-
Internet and intranet services;
-
Email and collaboration platforms;
-
Internet access;
-
Web servers and websites;
-
Public computing facilities;
-
Voice and telecommunications systems;
-
Security and surveillance systems;
-
Cloud computing and storage services;
-
Institutional databases;
-
Institutional data and information;
-
Backup and disaster recovery systems;
-
Printers, scanners, storage devices, and other peripherals;
-
Information security systems and tools; and
-
Third-party systems and services provided for institutional use.
Access to The Management Institute for National Development's ICT resources is a privilege and is conditional upon compliance with this Policy and other applicable requirements.
2. Acceptable Use
ICT resources shall primarily be used to support the legitimate academic, administrative, research, operational, and institutional activities of The Management Institute for National Development.
Limited personal use may be permitted where expressly allowed by The Management Institute for National Development, provided that such use:
-
Is lawful;
-
Does not interfere with institutional operations;
-
Does not adversely affect system performance or network availability;
-
Does not interfere with the user's academic or employment responsibilities;
-
Does not expose The Management Institute for National Development to unnecessary security, legal, financial, or reputational risk;
-
Does not consume excessive institutional resources;
-
Does not violate this Policy or another institutional policy; and
-
Does not involve the processing, storage, or transmission of inappropriate or unauthorized information.
The Management Institute for National Development reserves the right to restrict or prohibit personal use where it determines that such use creates unacceptable risk or adversely affects institutional operations.
3. User Responsibilities
All users are responsible for using ICT resources appropriately and for taking reasonable steps to protect the security of institutional systems and information.
Users shall:
-
Use ICT resources only for authorized purposes;
-
Protect their usernames, passwords, PINs, authentication tokens, and other credentials;
-
Never knowingly share authentication credentials with another person;
-
Use strong passwords and comply with institutional password requirements;
-
Use multi-factor authentication where required;
-
Lock or secure devices when left unattended;
-
Protect institutional information from unauthorized access, disclosure, alteration, loss, or destruction;
-
Follow approved procedures when handling confidential or personal information;
-
Verify unexpected requests for sensitive information before responding;
-
Promptly report suspected security incidents, phishing attempts, unauthorized access, lost devices, or accidental disclosure of information;
-
Install software only where authorized;
-
Keep institutionally managed devices and software appropriately updated;
-
Comply with software licensing and copyright requirements;
-
Use institutional systems in accordance with their assigned permissions;
-
Respect the privacy, security, and rights of other users; and
-
Cooperate with authorized investigations concerning ICT security or policy violations.
Users must not assume that access to information or a system means that they are authorized to use, copy, modify, disclose, or distribute that information.
4. Protection of Personal and Confidential Information
Users who have access to personal, confidential, sensitive, academic, financial, employee, student, applicant, research, or other protected information must handle that information in accordance with applicable law and The Management Institute for National Development's policies and procedures.
Users shall:
-
Access personal or confidential information only where there is a legitimate institutional need and appropriate authorization;
-
Use personal information only for authorized purposes;
-
Not disclose personal or confidential information to unauthorized persons;
-
Take reasonable steps to prevent accidental disclosure;
-
Use approved systems and methods for storing and transmitting sensitive information;
-
Avoid storing sensitive institutional information on unauthorized personal devices or services;
-
Verify recipients before sending sensitive information;
-
Secure physical and electronic records appropriately; and
-
Report suspected or actual data breaches promptly.
Users must comply with the Data Protection Act, 2020 and applicable institutional data protection policies when processing personal information.
5. Account and Credential Security
Individual user accounts are assigned for the exclusive use of the authorized user unless otherwise approved.
Users shall:
-
Keep passwords and authentication credentials confidential;
-
Not use another person's account;
-
Not permit another person to use their account;
-
Not attempt to obtain another user's password or credentials;
-
Not circumvent authentication controls;
-
Use multi-factor authentication where provided or required;
-
Immediately report suspected credential compromise; and
-
Change compromised credentials as soon as reasonably possible.
Users are accountable for activity conducted through their accounts, subject to applicable investigation procedures and circumstances outside their reasonable control.
Shared accounts should be avoided where technically feasible and may only be used where specifically authorized.
6. Acceptable Use of Email and Electronic Communications
Institutional email and collaboration systems must be used responsibly and professionally.
Users must not:
-
Send malicious, threatening, harassing, fraudulent, defamatory, or unlawful communications;
-
Send unsolicited bulk messages or spam;
-
Send messages intended to disrupt or overload systems;
-
Impersonate another person;
-
Falsify email headers or other communication information;
-
Distribute malware or malicious links;
-
Send confidential or personal information to unauthorized recipients; or
-
Use institutional communication systems to conduct unauthorized commercial activities.
Users should exercise particular caution with email attachments, hyperlinks, unexpected payment requests, password requests, and other communications that may be associated with phishing or social engineering.
7. Internet and Network Use
Internet and network access provided by The Management Institute for National Development must be used responsibly and lawfully.
Users must not:
-
Attempt to bypass network security controls;
-
Scan or probe networks without authorization;
-
Intercept network traffic without authorization;
-
Introduce unauthorized devices into institutional networks;
-
Conduct denial-of-service or similar attacks;
-
Use institutional networks to facilitate unlawful activities;
-
Deliberately consume excessive network resources;
-
Operate unauthorized servers or network services; or
-
Attempt to gain unauthorized access to internal or external systems.
8. Prohibited and Unacceptable Use
Use of The Management Institute for National Development's ICT resources is unacceptable where it:
-
Conflicts with the legitimate aims and objectives of The Management Institute for National Development;
-
Violates this Policy or another institutional policy;
-
Violates applicable laws or regulations;
-
Breaches contractual or licensing obligations;
-
Could expose The Management Institute for National Development to legal, financial, operational, security, or reputational risk;
-
Infringes the rights of another person or organization;
-
Involves unauthorized access, use, modification, destruction, or disclosure of information or systems; or
-
Otherwise constitutes misuse of institutional ICT resources.
Examples include, but are not limited to:
8.1 Unauthorized Access
-
Attempting to access systems, accounts, files, databases, or information without authorization;
-
Circumventing access controls;
-
Using another person's credentials;
-
Escalating privileges without authorization; or
-
Attempting to gain access to systems outside the user's authorized responsibilities.
8.2 Malware and Cyber Attacks
Users must not introduce, develop, distribute, or knowingly facilitate malware, including:
Users must not conduct unauthorized penetration testing, vulnerability scanning, denial-of-service attacks, password attacks, or other activities intended to compromise ICT systems.
8.3 Disruption of Services
Users must not intentionally interfere with or degrade ICT services, including through:
-
Spamming;
-
Network flooding;
-
Jamming;
-
Deliberate system crashes;
-
Unauthorized resource-intensive activities; or
-
Other activities that adversely affect system availability or performance.
8.4 Data Misuse
Users must not:
-
Access personal or confidential information without authorization;
-
Copy or remove institutional information without authorization;
-
Alter or delete records without authorization;
-
Disclose protected information to unauthorized persons;
-
Upload institutional information to unauthorized cloud or AI services; or
-
Use institutional information for unauthorized purposes.
8.5 Fraud, Impersonation and Misrepresentation
ICT resources must not be used to:
-
Commit fraud;
-
Conduct phishing or social engineering;
-
Impersonate another person;
-
Falsify electronic records;
-
Misrepresent the institution;
-
Forge electronic communications; or
-
Facilitate identity theft or other unlawful activity.
8.6 Harassment and Offensive Material
ICT resources must not be used to create, transmit, access, store, or distribute material that is unlawful, threatening, discriminatory, harassing, sexually explicit, abusive, or otherwise inappropriate, except where access is legitimately required for approved academic, research, legal, or institutional purposes.
8.7 Unauthorized Commercial Activities
Institutional ICT resources must not be used to conduct personal commercial activities, private businesses, or other activities unrelated to institutional responsibilities unless expressly authorized in writing by The Management Institute for National Development.
8.8 Copyright and Intellectual Property
Users must respect copyright, trademarks, licenses, patents, and other intellectual property rights.
Users must not use institutional ICT resources to illegally download, reproduce, distribute, or share copyrighted material or licensed software.
9. Artificial Intelligence and Emerging Technologies
Users must exercise caution when using generative artificial intelligence (“AI”), automated tools, or other emerging technologies with institutional resources or information.
Users must not enter personal, confidential, sensitive, proprietary, or otherwise restricted institutional information into public or unauthorized AI systems unless such use has been expressly approved by The Management Institute for National Development.
AI-generated information must be reviewed for accuracy, reliability, bias, privacy implications, intellectual property concerns, and appropriateness before being used for institutional purposes.
Where required by institutional policy, users must disclose the use of AI in academic, research, administrative, or other institutional work.
10. Personal Devices and Remote Access
Where personal devices are permitted to access institutional ICT resources, users are responsible for ensuring that such devices are appropriately secured.
Where required, personal devices must:
-
Use supported operating systems;
-
Have current security updates;
-
Use appropriate anti-malware protection;
-
Use screen locks and authentication;
-
Use approved security controls;
-
Not be shared with unauthorized persons when accessing institutional information; and
-
Comply with applicable institutional remote-access requirements.
Users accessing institutional systems remotely must use approved methods and must not attempt to circumvent security controls.
11. Physical Security of ICT Resources
Users must take reasonable precautions to protect ICT equipment and information from theft, loss, damage, or unauthorized access.
Institutional equipment must not be removed from designated locations without authorization where such authorization is required.
Lost or stolen institutional devices must be reported to The Management Institute for National Development immediately.
12. Monitoring and Privacy
ICT resources are institutional resources and may be monitored, logged, audited, or reviewed for legitimate purposes, including:
-
Maintaining security;
-
Detecting and investigating unauthorized access or misuse;
-
Protecting institutional systems and information;
-
Troubleshooting and maintaining ICT services;
-
Ensuring compliance with institutional policies;
-
Meeting legal or regulatory obligations; and
-
Investigating suspected misconduct or security incidents.
Monitoring will be conducted in accordance with applicable law and institutional policies.
Users should not assume that information created, stored, transmitted, or processed using institutional ICT resources is completely private.
Any access to user information by authorized personnel should be limited to legitimate institutional, security, operational, investigative, or legal purposes and carried out in accordance with applicable requirements.
13. Data Protection
The Management Institute for National Development is committed to protecting personal information processed through its ICT resources.
All users who process personal information on behalf of The Management Institute for National Development must:
-
Process information only for authorized purposes;
-
Follow applicable data protection requirements;
-
Apply appropriate security measures;
-
Maintain confidentiality;
-
Not disclose personal information without authorization;
-
Report suspected personal data breaches promptly; and
-
Follow instructions issued by the institution's Data Protection Officer and authorized ICT personnel.
Additional requirements may be established under The Management Institute for National Development's Privacy Notice, Data Protection Policy, Information Security Policy, and related procedures.
14. Reporting Security Incidents
Users must immediately report suspected or actual ICT security incidents.
Examples include:
-
Lost or stolen devices;
-
Suspected account compromise;
-
Phishing emails;
-
Malware infections;
-
Unauthorized access;
-
Accidental disclosure of personal or confidential information;
-
Suspicious system activity;
-
Unauthorized changes to data;
-
Data breaches; and
-
Other suspected violations of information security.
Reports should be made through the institution's designated ICT/security reporting channel:
ICT Support: {ictSupportEmail}
Telephone: {ictSupportPhone}
Users should not attempt to conceal, delete, modify, or otherwise interfere with evidence relating to a suspected security incident.
15. Software and Licensing
Users must not install, copy, distribute, or use software on institutional ICT resources unless appropriately licensed and authorized.
Unauthorized software may introduce security vulnerabilities, licensing violations, or other risks to the institution.
Users must comply with software license agreements and institutional software installation procedures.
16. Use of Institutional Information
Institutional information remains the property or responsibility of The Management Institute for National Development, as applicable.
Users must not copy, transfer, publish, sell, disclose, destroy, or otherwise use institutional information outside their authorized responsibilities.
When a user's employment, enrolment, contract, or other authorization ends, access to institutional systems may be revoked and institutional information and equipment must be returned in accordance with institutional procedures.
17. Third-Party and Cloud Services
Users must not use unauthorized third-party applications, cloud storage services, file-sharing platforms, messaging applications, or other external services to store or process institutional information.
Before using a third-party service for institutional information, users must obtain the required institutional approval and ensure that appropriate security, privacy, contractual, and data protection requirements have been satisfied.
18. Enforcement and Disciplinary Action
Access to The Management Institute for National Development's ICT resources is a privilege and not an unrestricted right.
Where there is evidence of unacceptable use or a violation of this Policy, The Management Institute for National Development may take appropriate action, including:
-
Restricting or suspending access;
-
Disabling or terminating accounts;
-
Removing unauthorized software or content;
-
Securing or isolating affected systems;
-
Conducting an authorized investigation;
-
Requiring corrective action or security training;
-
Referring the matter for disciplinary proceedings;
-
Reporting the matter to law enforcement or regulatory authorities where appropriate; and/or
-
Taking legal action where warranted.
Disciplinary action will be handled in accordance with applicable The Management Institute for National Development statutes, regulations, policies, employment procedures, student regulations, contracts, and applicable law.
Nothing in this Policy prevents The Management Institute for National Development from taking immediate measures necessary to protect its systems, users, information, or operations.
19. Policy Exceptions
Exceptions to this Policy may be granted only through an appropriate authorization process.
Any exception must be documented and should identify:
-
The reason for the exception;
-
The systems or information affected;
-
The duration of the exception;
-
The risks associated with the exception; and
-
Any compensating security controls.
20. Policy Review and Amendment
The Management Institute for National Development may review and amend this Policy periodically to reflect changes in technology, institutional operations, cybersecurity threats, legal requirements, and regulatory obligations.
The current approved version of the Policy will be made available to the The Management Institute for National Development community.
Users are responsible for complying with the current version of the Policy.
21. User Acceptance and Security Responsibility
All users of The Management Institute for National Development's ICT resources are required to acknowledge this Policy, whether by signing a physical document, electronically accepting the Policy, or otherwise providing an approved form of acknowledgement.
By accepting this Policy, I acknowledge and agree that:
-
I understand that The Management Institute for National Development's ICT resources are provided to support its academic, research, administrative, operational, and institutional activities.
-
I will use The Management Institute for National Development's ICT resources responsibly, ethically, securely, and lawfully.
-
I will comply with this Acceptable Use Policy and all other applicable The Management Institute for National Development policies, procedures, rules, regulations, and security requirements.
-
I will protect my usernames, passwords, PINs, authentication tokens, and other credentials and will not knowingly disclose them to unauthorized persons.
-
I understand that I am responsible for activity performed through my assigned account, subject to applicable circumstances and institutional investigation procedures.
-
I will not attempt to access systems, applications, accounts, information, or resources for which I have not been authorized.
-
I will protect institutional, confidential, personal, academic, financial, research, and other sensitive information from unauthorized access, use, disclosure, modification, loss, or destruction.
-
I will comply with applicable data protection requirements, including the Data Protection Act, 2020, when processing personal information on behalf of The Management Institute for National Development.
-
I will immediately report suspected security incidents, unauthorized access, compromised credentials, lost or stolen devices, phishing attempts, and suspected data breaches through the appropriate institutional channels.
-
I will not knowingly introduce malware, conduct unauthorized security testing, disrupt services, or otherwise compromise the confidentiality, integrity, or availability of The Management Institute for National Development's ICT resources.
-
I will respect copyright, intellectual property, software licensing, privacy, and other legal rights.
-
I understand that institutional ICT resources may be subject to authorized monitoring, logging, auditing, or investigation for legitimate security, operational, legal, compliance, and institutional purposes, in accordance with applicable law and institutional policies.
-
I understand that I should not have an expectation of absolute privacy when using institutional ICT resources, subject to applicable privacy and data protection requirements.
-
I will not use unauthorized third-party applications, cloud services, AI platforms, file-sharing services, or other external systems to process or store institutional or protected information where such use has not been approved.
-
I understand that The Management Institute for National Development may restrict, suspend, or terminate my access to ICT resources where necessary to protect institutional systems, information, users, or operations.
-
I understand that violations of this Policy may result in disciplinary action and/or legal action, as applicable.
-
I understand that The Management Institute for National Development may update this Policy from time to time and that I am responsible for complying with the current approved version.
-
I acknowledge that I have read and understood this Acceptable Use Policy and agree to comply with its requirements.
User Acknowledgement
I acknowledge that I have read, understood, and agree to comply with the The Management Institute for National Development Acceptable Use Policy – Information & Communication Technology and accept the responsibilities associated with my use of the institution's ICT resources.
Name: {userName}
User ID: {userID}
Role/Department: {userRole}
Date: {acceptanceDate}
Electronic Acceptance: {acceptanceStatus}
Related Policies and Documents
This Policy should be read together with applicable The Management Institute for National Development policies and procedures, including:
-
Data Protection and Privacy Policy;
-
Information Security Policy;
-
Password and Authentication Policy;
-
Remote Access Policy;
-
Incident Response Policy;
-
ICT Asset Management Policy;
-
Records Retention Policy;
-
Cybersecurity Policy;
-
Student and Staff Disciplinary Regulations; and
-
Any other policies governing the use of institutional information and technology.
Policy Owner: {policyOwner}
Data Protection Officer: {dpoName}
ICT Department: {ictDepartment}
Contact: {ictSupportEmail}