Fayetteville Policies and Procedures 900.0
Code of Computing Practices
- General Principles
- This code governs the use of computers, networks, email and other applications, and other computing resources at the University of Arkansas, Fayetteville. Collectively, such computing resources are provided by the University to enhance its mission of teaching, research, and public service and to provide access to local, national, and international facilities in achieving these goals. The University is committed to computing and network systems that effectively meet the needs of the institution’s mission.
- Individuals who are granted computing accounts or who use computing resources at the
University accept the responsibilities that accompany such access. Each user is expected
to comply with all applicable University policies and to use such accounts and resources
for educational, research, or administrative purposes; except as otherwise provided
in this code, activities unrelated to these purposes are prohibited.
- Use of computing resources in violation of the provisions set forth in this code may be addressed as indicated in Section V. of this policy and through established University procedures for student and employee misconduct.
- The University is committed to intellectual and academic freedom in connection with its computing and network resources. Computers and networks can provide access to resources on and off campus, including the ability to communicate with other users worldwide. Such open access is a privilege, much like access to books in the library, and requires that individual users act responsibly. Use of computing and network resources should always be legal and ethical, reflect academic honesty, and show restraint in the consumption of shared resources. It should demonstrate respect for intellectual property, ownership of data, system security mechanisms, respect for personal privacy, and freedom from intimidation and harassment.
- Use of University computing resources is subject to all applicable federal and state laws and regulations and University policies. These include, but are not limited to, the Family Education Rights and Privacy Act of 1974, 20 U.S.C. § 1232g; the Electronic Communications Privacy Act of 1986, 18 U.S.C. §§ 2510 et seq.; the Arkansas Freedom of Information Act, Ark. Code Ann. §§ 25-19-101 et seq.; state and federal computer fraud and cyber security requirements, such as 18 U.S.C. § 1030 and Ark. Code Ann. §§ 5-41-101 to -206 and 25-1-126; and federal export control provisions. Illegal reproduction of software and other intellectual property protected by U.S. copyright laws and by licensing agreements may result in civil and criminal sanctions.
- The University recognizes the value and potential of electronic communications and
publishing on the internet. Students, faculty, and staff have the opportunity to produce,
in a manner consistent with this code, individual World Wide Web pages through their
University accounts, subject to this and other applicable provisions of University
policy and applicable law.
- Administration of Computing Resources
- In General
- The University, in accordance with state and federal law and the policies of the institution, may control access to and use of its information and the networks, applications, and devices on which it is stored, processed, and transmitted.
- The University has the responsibility to: (a) develop, implement, maintain, and enforce appropriate security procedures to protect the confidentiality, integrity, and availability of individual and institutional information, however stored; and (b) uphold all copyrights, patents, licensing agreements, and rules of organizations that supply information resources.
- Responsibility for administering the University's computing resources and for the security of these resources rests with UITS and units designated in writing by IT Services.
- System Administrators
- A system administrator is any person designated, within any campus unit, to maintain, manage, and provide security for shared multi-user computing resources, including computers, networks, electronic or computing infrastructure, University-owned internet of things (IOT), and servers.
- System administrators shall perform their duties fairly, in cooperation with the user community and University administrators. They shall adhere to this code and all other pertinent University rules and regulations, shall respect the privacy of users to the greatest extent possible, and shall promptly refer disciplinary matters to appropriate University officials.
- Data Collection
- Given the nature of the technology, a wide range of information can be easily collected by University personnel using system software. For example, software may be configured to provide aggregate information on the number of users logged in, the number of users accessing certain software, etc.
- No information shall be routinely collected that is not required by system administrators in the direct performance of their duties, such as routine backup for system recovery or account remediation.
- Access to Electronic Files
- Users do not own accounts on University computers but are granted the privilege of use of the accounts they are issued for purposes of conducting university business, subject to all provisions of this policy. Use of University computing resources for storage or transmission of data does not alter any ownership interest of the user in that data. The University seeks to preserve security and privacy regarding computer communications and stored data, subject to all provisions of this policy and applicable law.
- University officials will access electronic files, including email files, only under
one or more of the following conditions, or as otherwise provided by University policy:
- The user consents in writing to such access.
- There is a valid search warrant, subpoena, or court order, or a request for electronic records that are open to public inspection under the Arkansas Freedom of Information Act.
- There exists an emergency situation in which the safety and/or well-being of person(s) may be affected or University property may be damaged or destroyed, or circumstances exist where an employee is unavailable to perform job duties and access is necessary for orderly conduct of University functions. Responsibility for authorizing access rests with the Associate Vice Chancellor for Information Technology Services or the Vice Chancellor for Finance and Administration.
- There exist reasonable grounds to believe that a violation of law or University policy is occurring or has occurred, or there are other pertinent University operational needs. Responsibility for authorizing access rests with the Associate Vice Chancellor for Information Technology Services or the Vice Chancellor for Finance and Administration, in consultation with the Office of the General Counsel.
- Access is necessary for maintenance of computers, networks, data, and storage systems; to maintain the integrity of the computer, network, or storage system; to comply with audit or assessment requirements of applicable security standards or as required by law; to protect the rights or property of the University or other users. Authorized personnel may routinely monitor and log usage data, such as network session connection times and end-points, CPU and disk utilization for each user, security audit trails, and network loading. In all cases, privacy shall be protected to the greatest extent possible.
- The Arkansas Freedom of Information Act
- The electronic files, including email files, of University employees are potentially subject to public inspection and copying under the Arkansas Freedom of Information Act ("FOIA"), Ark. Code Ann. §§ 25-19-101 et seq.
- The FOIA defines "public records" to include "data compilations in any form, required by law to be kept or otherwise kept, . . . which constitute a record of the performance or lack of performance of official functions which are or should be carried out by a public official or employee [or] a governmental agency. . . ." Ark. Code Ann. § 25-19-103(1). All records maintained in public offices or by public employees within the scope of their employment are presumed to be public records. Id. Various exceptions apply. See Ark. Code Ann.§ 25-19-105; Fayetteville Policies and Procedures 207.0.
- Education Records
- Records containing information directly related to a student are confidential and protected from public disclosure consistent with the Family Educational Rights & Privacy Act, 20 U.S.C. § 1232g, and the Arkansas Freedom of Information Act, Ark. Code. Ann. § 25-19-105(b)(2).
- No one shall access any such records, whether maintained electronically or otherwise,
or disclose or distribute their contents in any manner inconsistent with federal and
state law or University policies.
- In General
- Use of Computing Resources
- In General
This section does not cover every situation involving the proper or improper use of University computing resources; however, it does set forth some of the responsibilities that a user accepts as a condition of being granted authorization to use those resources and, as applicable, as a condition of employment. The purpose of this section is to establish general rules for the benefit of all users and encourage responsible use of computing resources. - Use Without Authorization Prohibited
- No one shall (a) connect with or otherwise use any University computer, modem, network, or other computing resource without proper authorization; (b) assist in, encourage, or conceal any unauthorized use, or attempted unauthorized use, of any University computer, modem, network, or other computing resource; or (c) misrepresent his or her identity or relationship to the University to obtain access to computing resources.
- Users shall use only those computing and network resources that have been authorized
for their use and must identify computing work with their own names or an approved
means of identification so that responsibility for the work can be determined and
users contacted, if necessary.
- Accounts
- Users shall use their accounts and other computing resources for the purposes for which they are established. Accounts and other University computing resources shall not be used for personal financial gain or benefit or for the benefit of organizations not related to the University, except: (a) in connection with scholarly pursuits, such as faculty publishing activities; or (b) as authorized in accordance with University policy on outside consulting for compensation. De minimis personal use by authorized users that otherwise complies with this policy and applicable law, that does not result in any measurable cost to the university, that complies with licensing restrictions, and that benefits the University by allowing personnel to avoid needless inconvenience, is not prohibited.
- Users shall not subvert restrictions associated with their accounts, such as quotas and levels of access.
- Users shall follow all applicable policies for accessing University computing resources.
- No one shall give any password or authentication device for any University computing resource to any unauthorized person, nor obtain any other person's password or authentication device by any unauthorized means. Users are responsible for the use of their computer accounts and shall not allow others access to their accounts, through sharing passwords, authentication devices, or otherwise. Users should take advantage of system-provided protection measures to prevent such access.
- When a user ceases being a member of the campus community or is assigned a new position
and/or different responsibilities within the University, his or her account and access
authorization shall be reviewed and revised to reflect the user’s new status. A user
shall not use facilities, accounts, access codes, privileges, or information for which
the user is not authorized.
- To the extent that continued access may be permitted for retirees or other users at the discretion of the University, such use is expressly subject to the user’s continuing obligation to abide by this Code of Computing Practices and other applicable University policies. Further, such users should at all times make clear they are not communicating on behalf of the University.
- Security and Related Matters
- No one shall (a) knowingly endanger or compromise the security of any University computer, network facility, or other computing resource or willfully interfere with others' authorized computer usage, (b) attempt to circumvent data protection schemes, uncover security loopholes, or decrypt secure data; (c) modify or reconfigure or attempt to modify or reconfigure any software or hardware of any University computer or network facility in any way, unless specific authorization has been obtained; or (d) use University computer resources and communication facilities to attempt unauthorized access to or use of any computer or network facility, no matter where located, or to interfere with others' legitimate use of any such computing resource.
- No one shall attempt to access, interfere with, alter, copy, or destroy programs or files that belong to other users or to the University without prior authorization, nor shall anyone use University computing resources for unauthorized monitoring of information technology infrastructure, systems, or electronic communications.
- No one shall create, run, install, or distribute or allow the distribution of a computer virus, Trojan Horse, or other destructive program, email, or data via any University computer or network facility, regardless of whether demonstrable harm results.
- Users shall not place confidential information in computing resources without protecting it appropriately. The University cannot guarantee the privacy of computer files, email, or other information stored or transmitted by computer; moreover, the University may access such information in accordance with Part II of this code. Persons who have access to confidential or sensitive information shall disclose it only to the extent authorized by the Family Educational Rights & Privacy Act, the Arkansas Freedom of Information Act, and other applicable laws and University policy, and only in connection with official University business.
- Users shall not perform any act that will interfere with the normal operation of computing resources and shall not intentionally waste or overload such resources.
- Users shall comply with FPP 225.1, the University’s Website Privacy policy.
- The University strictly prohibits any use of computing resources to create, upload,
access, link, share, or distribute content that depicts or promotes the sexual exploitation
or abuse of children, involves predatory behavior toward children, or otherwise endangers
children.
- Intellectual Property
- No one shall copy, install, use, or distribute through University computing resources any photographs, logos, images, graphics, graphic elements, audio, video, software, html markup, data files, or other information in violation of U.S. copyright, trademark, or patent laws or applicable licensing agreements. It is the user's responsibility to become familiar with the terms and requirements of any such laws or agreements. This subsection does not apply to any material that is in the public domain.
- Users should be aware that the unauthorized peer-to-peer sharing of copyrighted works
such as music, pictures, games, computer applications, and movies is a violation of
this code. It is also illegal and may carry significant money and/or criminal sanctions.
It is the responsibility of the user who is downloading or uploading files to make
certain that they are not copyrighted works or that the user has the permission of
the copyright holder.
- User Communications
- Users assume full responsibility for messages that they transmit through University computing resources.
- No one shall use the University's computing resources to transmit fraudulent, defamatory, or obscene messages, or any material prohibited by law or University policy, or to engage in private business activity, unless specifically authorized in conjunction with official University initiatives.
- No one shall use the University's computing and network resources to: (a) harass or threaten another person, including but not limited to, by conveying obscene language or images or threats of bodily harm; (b) repeatedly contact another person to harass, whether or not any actual message is communicated, and the recipient has expressed a desire for the contact to cease; (c) repeatedly contact another person regarding a matter for which one does not have a legal right to communicate (such as debt collection), once the recipient has provided reasonable notice that he or she desires such contact to cease; (d) disrupt or damage the academic, research, administrative, or related pursuits of another person; or (e) invade the privacy, academic or otherwise, of another person or threaten such an invasion.
- Unless otherwise authorized by law, consistent with UASP 285.1 and Arkansas Code §
25-1-128, no University technology resources shall be used:
- By a current or former employee:
- To express a personal political opinion to an elected official unless the opinion is within the scope of the employee’s regular job duties or the opinion is requested by an elected official or public entity or to engage in lobbying an elected official on a personal opinion if the employee is not designated by the Chancellor to do so.
- In violation of Board of Trustees Policy 465.1 and UA System Policy 465.1 concerning employee political activity.
- By any user to engage in illegal activities or activities otherwise prohibited by federal law or state law, or to intentionally override or avoid the security and system integrity procedures of the campus.
- By a current or former employee:
- User communications shall comply with Board of Trustees Policy 100.7, University Name and Trademarks.
- Users shall comply with this code as well as the policies of newsgroups, lists, and other channels through which they disseminate messages.
- Users shall not (a) initiate or propagate electronic chain letters or petitions not
directly connected to University business matters; (b) engage in spamming, phishing
or other similar uninvited mass mailings to newsgroups, mailing lists, or individuals;
(c) forge communications to make them appear to originate from another person, e.g.,
spoofing; or (d) engage activities that place extraordinary demands on university
resources that deny or impair services to other users.
- Priority in Use of Computing Facilities
- In University libraries and general-access computer labs, or in any other environment in which users must share computing resources, priority shall be given to users engaged in activities directly related to the University's mission, e.g., completing course assignments or engaging in research. The libraries and computer labs may adopt unit- or facility-specific policies to implement this policy and to encourage cooperation among users of the same equipment.
- Use of electronic messaging systems for non-course work is not permitted in libraries
and general-access computer labs when others are waiting to use the equipment.
- Home Pages, Lists, and Newsgroups
- The University recognizes the value and potential of electronic communications and publishing on the internet. Students, faculty, and staff may produce, in a manner consistent with this code, individual World Wide Web pages through their University accounts. Such pages are maintained by the user rather than the University. However, users must refrain from communications that are defamatory, that infringe on the intellectual property rights of third parties, or that violate University policies regarding discrimination and harassment.
- Any personal web page or other personal collection of electronic material that is accessible to others must include the following disclaimer: "The information, views, and opinions expressed on individual web pages are strictly those of their authors and are not statements on behalf of the University of Arkansas.”
- Academic and administrative departments, registered campus organizations, and other entities may apply to the Department of Information Technology Services for an "information provider" account to create a home page on the University of Arkansas web server. Publication guidelines and link requests are made through University Relations.
- The following individuals or groups may be eligible to establish a listserv list using University computing resources: (a) faculty or staff members, with the written approval of the appropriate department head; and (b) registered student organizations, i.e., student groups that are formally registered with the Campus Activities Center.
- Approval for a list or newsgroup must be obtained from the appropriate system administrator.
If resources are available, such approval shall be granted unless the proposed list
or newsgroup (a) duplicates an existing list or newsgroup or (b) appears to serve
a purpose unrelated to the University's mission. The University neither controls the
content of lists and newsgroups nor assumes any responsibility for their content.
- Use of Non-University Computing Resources for University Business.
- Due to considerations of compliance, security, and privacy, to the extent University
computing resources (such as email accounts and storage resources) have been furnished,
University faculty, staff, and others performing work on behalf of the University
(such as graduate assistants and teaching assistants) are expected to use such resources
to conduct University business. Highly sensitive and restricted data should be stored
on University owned or controlled resources and should not be stored on personal resources.
However, users are required to comply with University requests for access to and
copies of records when access or disclosure would be required or allowed under this
policy, regardless of whether such records reside on University computing resources.
- Due to considerations of compliance, security, and privacy, to the extent University
computing resources (such as email accounts and storage resources) have been furnished,
University faculty, staff, and others performing work on behalf of the University
(such as graduate assistants and teaching assistants) are expected to use such resources
to conduct University business. Highly sensitive and restricted data should be stored
on University owned or controlled resources and should not be stored on personal resources.
However, users are required to comply with University requests for access to and
copies of records when access or disclosure would be required or allowed under this
policy, regardless of whether such records reside on University computing resources.
- In General
- Reporting and Addressing Suspected Violations
Anyone who has reason to believe that another person has violated this policy shall report the matter promptly to the Office of the CISO (Chief Information Security Officer) and/or their supervisor or department head. Failure to report a suspected violation is a violation of this policy. After a suspected violation of this policy has been reported or discovered, the issue will be handled as soon as possible to mitigate any harm to the university and its affiliates. - Enforcement
Violation of this policy or related local, state, or federal laws may result in temporary or permanent loss of access to University computing and network privileges and disciplinary action up to and including termination.
Use or access restrictions due to violations of this or other university policies or to protect the safety or integrity of the University network or computing resources are within the discretion of UITS or the appropriate academic or administrative unit.
Suspected violations by employees shall be referred to the appropriate administrative unit for review and disciplinary action. Faculty disciplinary action shall be taken in consultation with the Office of the Provost. Staff disciplinary action shall be taken in consultation with Human Resources. Violations by students shall be referred for action under the applicable student code of conduct.
Violations by other authorized network users shall be reviewed for possible action by the Associate Vice Chancellor for Information Technology Services in consultation with the Provost and Vice Chancellor for Finance and Administration.
Actions which may constitute violations of applicable law or regulations may also be referred to law enforcement authorities.
Permanent use restrictions or loss of access may be appealed in writing to the Vice Chancellor for Student Affairs, the Vice Chancellor for Finance and Administration, or the Provost, or their designee, as appropriate, with the appeal determination being final. - Exemptions
Exemptions from this policy must be approved. Any questions about the contents of this policy or the applicability of this policy to a particular situation should be referred to the Office of the CISO. Please see the Exemption policy. - References
See the Arkansas General Assembly website to view the Arkansas Code. See the UA System web site for UA Board of Trustees and UA System Policies.
Revised August 17, 2026
Previously listed as Fayetteville Policies and Procedures 201.0
Revised February, 2011
Revised September 2009
Revised April 2002
Revised March 1998
Revised August 1994
April 28, 1993