Acceptable Use of Technology

Acceptable Use of Technology

1. Purpose

This policy establishes clear expectations for the acceptable use of Cincinnati State-owned, managed, or connected technology resources. Its purpose is to:

  • Protect the confidentiality, integrity, and availability of institutional data and systems
  • Support effective teaching, learning, and business operations
  • Reduce legal, security, and operational risk
  • Ensure compliance with applicable federal and Ohio laws and institutional policies
  • Set transparent expectations for users of College technology resources

This policy operates under the Information Security Governance Policy.

2. Scope

This policy applies to all individuals who access or use Cincinnati State technology resources, including but not limited to:

  • Employees (full-time, part-time, adjunct, temporary, student workers)
  • Students
  • Contractors, vendors, consultants, business partners, and volunteers
  • Guests and affiliates granted access

This policy applies regardless of location and covers both on-campus and remote use.

3. Technology Resources Covered

Cincinnati State technology resources include, but are not limited to:

  • Computers, mobile devices, tablets, and peripherals
  • Networks (wired, wireless, VPN)
  • Cloud services and platforms (including email, collaboration tools, storage, learning systems, and AI-enabled services)
  • Servers, databases, applications, and virtual environments
  • Internet access and network-connected services
  • Accounts, credentials, and authentication mechanisms

Technology resources may be College-owned, personally owned but connected to College systems, or third-party services authorized for College use.

4. Acceptable Use Principles

Users are expected to:

  • Use technology resources primarily for legitimate College business, academic, instructional, research, or approved operational purposes
  • Act ethically, responsibly, and professionally when using technology
  • Comply with all applicable laws, regulations, contracts, and College policies
  • Protect College data, systems, and credentials from misuse or unauthorized access
  • Use emerging technologies, including artificial intelligence, in a manner consistent with institutional governance and ethics requirements

Access to technology resources is a privilege, not a right, and may be modified or revoked at any time.

5. Prohibited Activities

The following activities are prohibited when using Cincinnati State technology resources:

5.1 Illegal, Harmful, or Abusive Use

  • Violating local, state, or federal law, including Ohio law
  • Harassment, intimidation, threats, or abusive behavior
  • Discrimination or hostile conduct directed at individuals or groups
  • Creation, transmission, or storage of content that is obscene, sexually explicit, or otherwise inappropriate for an academic or professional environment

5.2 Security Violations

  • Attempting to gain unauthorized access to systems, accounts, or data
  • Sharing passwords or authentication credentials
  • Circumventing security controls or monitoring mechanisms
  • Introducing malware, ransomware, spyware, or other malicious code
  • Conducting network scanning, sniffing, or denial-of-service activities without explicit authorization

5.3 Misuse of Resources

  • Using resources for personal commercial gain or external business activities
  • Excessive personal use that interferes with job performance, academic activity, or system availability
  • Unauthorized mass emailing, spamming, solicitation, or automated messaging
  • Misrepresenting identity or impersonating others
  • Falsifying system records, logs, or communications

5.4 Data Misuse

  • Accessing data without a legitimate business or academic need
  • Disclosing confidential, sensitive, or restricted data to unauthorized individuals
  • Storing institutional data on unauthorized systems or services
  • Posting non-public institutional information to public websites, AI tools, or social media platforms

6. Confidential, Regulated, and Student Information

Users must:

  • Handle confidential, sensitive, and regulated data in accordance with the College’s Information Security Policy and data classification standards
  • Protect student education records in compliance with the Family Educational Rights and Privacy Act (FERPA)
  • Use only approved systems and safeguards when transmitting, processing, or storing sensitive or regulated information
  • Exercise caution when using email, collaboration platforms, AI-enabled tools, or messaging systems
  • Report suspected data exposure, loss, misuse, or improper disclosure immediately

Electronic communications and data created using College resources are subject to legal discovery and public disclosure obligations.

7. Personal Use

Limited incidental personal use of College technology resources is permitted provided that:

  • It does not interfere with job performance, academic responsibilities, or system operations
  • It does not consume excessive resources
  • It complies with this policy, other College policies, and applicable laws
  • It does not involve prohibited activities or personal commercial purposes

Personal use may be restricted or revoked at any time.

8. Monitoring, Privacy, and Public Records

Cincinnati State reserves the right to monitor, access, log, and review the use of its technology resources for legitimate institutional purposes, including:

  • Security and system integrity
  • Legal, regulatory, and audit compliance
  • Investigations and policy enforcement
  • Public records, litigation, and retention obligations

As a public institution, Cincinnati State is subject to the Ohio Public Records Act and other applicable disclosure requirements. Users should have no expectation of personal privacy when using College technology resources. Information created, sent, received, processed, or stored using College systems may be monitored, retained, or disclosed as permitted or required by law.

9. Artificial Intelligence and Emerging Technologies

Use of artificial intelligence, automated decision tools, and emerging technologies must comply with the College’s AI Governance and AI Transparency policies. Users must not:

  • Input confidential, sensitive, or regulated data into unapproved AI systems
  • Use AI tools in a manner that creates legal, ethical, academic integrity, or reputational risk for the College
  • Represent AI-generated content as human-generated where disclosure is required by policy

10. Intellectual Property

Users must respect intellectual property rights, including copyrights, trademarks, and licensing agreements. Unauthorized copying, distribution, modification, or use of protected material using College resources is prohibited unless permitted by law, license, or institutional agreement.

11. Reporting and Incident Response

Users are expected to promptly report:

  • Suspected security incidents or policy violations
  • Lost or stolen devices containing College data
  • Phishing attempts, social engineering, or suspicious system activity

Reports should be made to Information Technology Services or through designated institutional reporting channels.

12. Violations and Enforcement

Violations of this policy may result in one or more of the following:

  • Revocation or limitation of access to technology resources
  • Disciplinary action in accordance with College policies, handbooks, and applicable agreements
  • Referral to law enforcement or regulatory authorities where appropriate

Consequences apply regardless of whether the violation was intentional or inadvertent.

13. Policy Maintenance and Related Policies

This policy is reviewed periodically and updated as necessary to reflect changes in technology, law, and institutional priorities. Continued use of College technology resources constitutes acceptance of the current version of this policy.

This policy should be read in conjunction with, but is not limited to:

  • Information Security Governance Policy
  • Artificial Intelligence Governance Policy
  • Artificial Intelligence Transparency & Responsible Use Policy
  • Use of Artificial Intelligence Policy (in this Catalog)
  • Records Retention and Public Records Policies
  • Student, Faculty, and Employee Codes of Conduct

Additional information about technology-related policies and procedures is available in the Information Technology Services section of the College intranet (MyCState). Students and employees must login to MyCState to access this information.

Student Recording and Distribution of Course Lectures and Materials

Students may not photograph, record (using audio or video technology), duplicate, reproduce, transmit, distribute, or upload or share via internet or website environments any class lectures, discussion, and/or other course materials, unless written permission has been obtained in advance from the instructor.

In the case of class discussions and/or presentations, permission must also be obtained from all students in the class and any guest speakers, if applicable. All participants must be informed in advance that activities will be recorded.

Students should review the course syllabus for instructions regarding the instructor’s policy on class recordings. Unless directly authorized by the syllabus, any student wishing to record classroom activities must discuss this issue with the instructor and obtain written permission.

Any photograph or recording of class activities and/or materials is authorized solely for use as an educational resource by an individual student or, when permission is granted, with other students enrolled in the same class. Photographs and/or recordings may not be publicly exchanged, distributed, shared, or broadcast for any purpose.

Permission to allow a photograph or recording is not a transfer of any copyrights.

Violation of this policy may subject a student to disciplinary action under the College’s Student Code of Conduct.

Exception: it is not a violation of this policy for a student determined by the Office of Disability Services to be entitled to educational accommodations to exercise any rights protected under Section 504 of the Rehabilitation Act of 1973 and the Americans with Disabilities Act of 1990, including needed recording or adaptations of classroom lectures, discussions, and/or course materials for personal research and study. However, all other restrictions on other use and/or distribution apply in such cases.