Acceptable Use Standard (SFA 06-107.1.6)

Summary

Requirements for the responsible use of SFA technology, including mobile and endpoint devices and the security duties of managers and general users; applies to everyone with no exceptions and supports Policy 06-107.1.

Body

Quick Overview
  • This standard sets the rules for the acceptable use of SFA information resources: the mobile devices, laptops, media, systems, and data everyone uses to do their job.
  • It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
  • Unlike most standards, this one applies to everyone directly, including vendors and visitors, not just security staff.
  • These requirements are the minimum baseline SFA must meet; departments may add stricter rules, never weaker ones.
  • Meeting this standard is mandatory, and no exceptions are granted to the Acceptable Use Standard.

"Acceptable use" means using SFA's technology the right way: for university business, with the proper protections, and without putting data or people at risk. This standard spells out what everyone must do when handling mobile devices, laptops and endpoint devices, and removable media, plus the security and privacy duties that managers and general users each carry. It is the standard most people will encounter directly, because it governs everyday habits like locking your screen, reporting a lost laptop, keeping confidential information off personal devices, and flagging suspicious activity.

i
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources. Anyone who works within SFA IT facilities, including authorized vendors, visitors, or contingent workers, must follow it when using SFA information resources unless a contract says otherwise. In practice, that means:

  • All faculty and staff who use SFA computers, phones, accounts, or data.
  • Managers and supervisors, who carry extra responsibilities for their teams.
  • Vendors, contractors, and visitors using SFA systems or facilities.
  • Anyone storing or handling SFA data on a personal device (Bring Your Own Device).
i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • CISO & Office of Information Security: Develop, implement, maintain, and review the acceptable use procedures for mobile devices, endpoint devices, and the responsibilities of managers and users, working with Privacy Officers and IT teams.
  • Human Resources (HR): Onboard and offboard users, collect attestations, investigate suspected use violations, and handle disciplinary actions.
  • Privacy Officers (PO): Keep acceptable use practices aligned with current laws, ensure acceptable use terms are in third-party contracts, and guide legal disputes. (A Privacy Officer may also serve in a legal or compliance capacity.)
  • IT Management & Teams: Maintain and enforce acceptable use controls, monitor usage for possible violations, and report security concerns.
  • Users (including vendors): Attest to and follow the rules, protect the information they use, recognize the risks of their actions, and report possible violations.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into four areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.1.6.1.1) are shown so you can match them to the attached PDF.

1  Mobile Device Management  Phones, tablets & personal devices ⌄

SFA must manage the mobile devices that touch its data, whether the university owns them or you do.

  • Run a mobile device management program for SFA-provided devices that handle SFA data, covering how devices connect, how confidential data is secured, required protections such as encryption and Virtual Private Networks (VPN), usage monitoring, and proper use (06-107.1.6.1.1).
  • Define and document Bring Your Own Device (BYOD) controls for personally owned devices that handle SFA data. Remember: SFA data on your personal phone, computer, or accounts can still be subject to public information requests, subpoenas, court orders, litigation holds, and discovery (06-107.1.6.1.2).
Supporting document SFA 06-107.2.1 Access Management Standard.
2  User Endpoint Devices  Laptops, media & everyday habits ⌄

These are the day-to-day rules for laptops, portable devices, removable media, and printed material.

  • Report lost or stolen SFA devices, media, or anything holding SFA data immediately to security staff, Privacy Officers, and law enforcement as needed. If a lost device was unencrypted, report it to SFA Administration within 7 calendar days (06-107.1.6.2.1).
  • Do not use unapproved portable devices in IT facilities that handle confidential data without documented management approval. Where limited use is approved, connecting to classified systems is prohibited, modems and wireless interfaces are prohibited, and the devices may be randomly inspected (06-107.1.6.2.2).
  • Limit the use of portable and removable media, keeping it protected from unauthorized access and physically secured when not in use (06-107.1.6.2.3).
  • Get documented approval from the CISO or their designee before storing confidential data on portable or removable media. Personal or external drives may not hold SFA confidential data without authorization and proper encryption (06-107.1.6.2.4).
  • Lock your screen on SFA-provided devices whenever they are left unattended, and set screens to lock automatically after no more than 15 minutes of inactivity (06-107.1.6.2.5).
  • Store devices, media, and paper copies securely when unattended, in locked cabinets, desks, safes, or furniture, so unauthorized people cannot access or view them (06-107.1.6.2.6).
  • Position screens in public and shared spaces so confidential information cannot be seen by others, and erase or dispose of confidential material (whiteboards, notes) when it is no longer needed (06-107.1.6.2.7).
Supporting document SFA 06-107.2.6 Incident Management Standard.
3  Management Information Security & Privacy Responsibilities  Extra duties for supervisors ⌄

Managers and supervisors carry additional responsibilities for the people they oversee.

  • Build information security and privacy responsibilities into your team members' roles and performance objectives, and communicate those responsibilities clearly (06-107.1.6.3.1).
  • Track completion of required security and privacy training for your team, and help them finish it on time (06-107.1.6.3.2).
  • Escalate any security or privacy issues found in your work area or reported by your team, following SFA's defined processes (06-107.1.6.3.3).
Supporting documents SFA 06-107.1.3 Personnel and Third Party Security Standard · SFA 06-107.1.4 Awareness and Training Standard · SFA 06-107.2.6 Incident Management Standard.
4  General Users Information Security & Privacy Responsibilities  What every user must do ⌄

These are the core responsibilities that apply to everyone who uses SFA information resources.

  • Attest that you understand your security and privacy responsibilities during onboarding or when you change roles, and re-attest at least every 24 months (for example, through annual training or the Acceptable Use Policy) (06-107.1.6.4.1).
  • Follow all legal, regulatory, contractual, and privacy requirements as reflected in SFA's policies, standards, and procedures (06-107.1.6.4.2).
  • Report unusual or suspicious events immediately, including suspected misuse or unauthorized access, malware, website defacement, physical damage to IT facilities, or anything else that could jeopardize security (06-107.1.6.4.3).
  • Use SFA systems and assets for their intended business purpose. Incidental personal use is allowed within reason, but never to run an outside business, for political lobbying or campaigning, or to handle sexually explicit material. Keep incidental storage nominal (under 5% of your mailbox), make clear that personal posts do not represent SFA, and never use prohibited technologies from the Texas DIR list (06-107.1.6.4.4).
!
Important
The Acceptable Use Standard allows no exceptions. Unlike other SFA standards, exceptions are never granted to these requirements. Every user must comply in full.
Supporting documents UT System Acceptable Use Policy (AUP) · SFA 06-107.2.6 Incident Management Standard · Texas Department of Information Resources Prohibited Technologies.

Conformance & Exceptions

Conformance to this standard is mandatory. All requirements are effective as of the standard's publication, and conformance is required immediately unless otherwise indicated. Because this is the Acceptable Use Standard, the normal exception process does not apply here: exceptions are never granted to these requirements.

!
Important
No exceptions are granted to the Acceptable Use Standard. Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

The requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, for example AC-3, AC-19, AC-19(04), AC-19(05), AC-20(01), AC-20(02), AT-3, PL-4, PM-9, PS-2, and SI-4.
  • TAC 202, for example 202.7, 202.71, 202.72, and 202.73.
  • Texas DIR Security Controls Catalog and the DIR Prohibited Technologies list.
  • NIST 800-171 and NIST CSF where relevant.
  • Privacy and sector frameworks: HIPAA, GLBA, GDPR, and FERPA.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy

Related standards:

Other references:

  • Texas Department of Information Resources Prohibited Technologies
  • UT System Incident Tracking Tool
  • SFA 06-107 Controls Crosswalk Reference

Responsible office: Office of Information Security  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173927
Created
Thu 7/16/26 2:23 PM
Modified
Thu 7/16/26 5:58 PM

Related Articles

Related Articles (2)

Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.