You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
You are viewing the article in preview mode. It is not live at the moment.
Internet Usage Policy
print icon

Purpose

  • In order to guarantee a secure and controlled Internet access in SSMC, the SSMCs are committed to preventing the occurrence of inappropriate, unethical, or unlawful behavior by any of the users of its computing systems and telecommunications networks.

Policy

  1. The purpose of this policy is to outline and educate users on both the acceptable and non-acceptable use of the Internet/Intranet within SSMC. When applied, the policy controls are intended to protect SSMC from potential legal liability should an Internet user contravene the laws of the country.
  2. SSMC 's business interests and legal and ethical obligations concerning the welfare and privacy of its customers and business partners mandate the responsibilities of this policy.
  3. This Internet usage policy and its strict enforcement is an important and necessary part of the overall usage strategy in SSMC s.
  4. SSMC employees and independent contractors and third parties associated with SSMC are specifically warned that personal criminal and/or civil action shall be taken by SSMC in the event of their breach of this policy.

Scope

The scope of this policy includes all usage of SSMC’s IT resources, including but not limited to, computer systems, email, the network, and the corporate Internet connection. The components outlined in this document focus on issues associated with the SSMC’s host computers, PCs, routers, terminal servers, and any other device that supports access to the Internet. The scope of this document does not include facility-specific usage policies, application usage, and non-Internet usage since they are covered in their respective policies. The Internet usage policy applies to all Internet users (individuals working for the SSMC’s including permanent full-time and part time employees, contract workers, temporary agency workers, business partners, and vendors) who access the Internet through the computing or networking resources. The SSMC’s Internet users are expected to be familiar with and to comply with this policy and are also required to use their common sense and exercise their good judgment while using Internet services. 5 TARGET AUDIENCE:

  1. Core Staff: IT Department Staff.
  2. Relevant staff: All Hospital staff including permanent full time and part time employees, contract workers, temporary agency workers, business partners and vendors, visitors, guest who access the internet through the networking resources.

6 RESPONSIBILITIES:

  1. IT Director: Ensure that procedure is implemented and adhered to all business units.
  2. CTO: approve eligibility and the internet access groups (Full access/Doctors access/restricted access etc.)
  3. Department Heads (HODs): Ensure procedure is followed by all staff in their department.
  4. Network Engineer: To configure the firewall and assign the Internet access as per the approved internet access group and monitor the usage and maintaining the browsing logs
  5. End Users: Users are expected to understand and adhere to the internet access and usage policy

Procedure

Internet Access

All IT Assets such as PCs, Laptops, Mobiles, and tablets belong to SSMC should follow the following standards.

  1. The COO of SSMC determines the access to SSMC internet. Each staff’s position requirements will be taken into consideration in determining the staff’s level of access and to define whether the staff is eligible to have full access/Doctors access/restricted access.
  2. Access to any job specific website is given to Doctor/Restricted access users with a prior approval from the IT Director/ CTO.
  3. An electronic log will be kept listing those individuals that have access and a list of the authorizations they have been granted.

Usage control

  1. Internet usage must be restricted to serve business requirements.
  2. Internet services and Public Email Services should not be used to disseminate private and confidential materials to external parties without prior approval from relevant chief officers or head of department.
  3. Under no circumstances, an employee of Sheikh Khalifa Hospitals is authorized to engage in any activity that is illegal under local or international law while utilizing Sheikh Khalifa Hospitals owned IT resources.
  4. The following list is by no means exhaustive, but attempts to provide list of activities which fall into the category of unacceptable use of Internet:
    1. Commercial use - any form of commercial use of the Internet is prohibited.
    2. Copyright violations - any use of the Internet that violates copyright laws is prohibited.
    3. Solicitation - the purchase or sale of personal items through advertising on the Internet is prohibited.
    4. Harassment - the use of the Internet to harass employees, vendors, customers, and others is prohibited.
    5. Political - the use of the Internet for political purposes is prohibited.
    6. Aliases - the use of aliases while using the Internet is prohibited.
    7. Anonymous messages are not to be sent.
    8. The misrepresentation of an employee's job title, job description, or position in the hospital is prohibited.
    9. Misinformation / Confidential Information - the release of untrue, distorted, or confidential information regarding hospital’s business is prohibited.
    10. Accessing the Internet for any illegal conduct, playing game, personal financial gain, private business activities, unethical purposes, creation of personal web pages, or any other improper reason is prohibited.
    11. Viewing, transmitting or storing of pornographic, indecent or otherwise offensive material is prohibited. SSMC retains the right to monitor, access, review, restrict or terminate your use of the Internet.
    12. Any use of Internet which is inconsistent with UAE Cybercrimes Law.
    13. Disclosure/sharing of accounts or passwords.
    14. Disclosure of any SSMC data, patient records, reports, confidential, proprietary, or other privileged information in any publicly accessible forum or in any web-based forums, applications or newsgroup postings
    15. Participation in chat sessions, and other related offerings on the Internet, where you do not indicate that the opinions expressed are your own and not necessarily those of SSMC.
    16. Deliberately circumventing security on any Internet site.
    17. The use of abusive, threatening or objectionable language in public or private messages.
    18. Actions that is likely to result in the loss of work or systems (e.g. chain letters, viruses).
    19. Use of the Internet in connection with any illegal, fraudulent or unethical activities.
    20. Any use of the Internet, which would be inconsistent with the general policies or standards of conduct of the SSMC.
    21. Actions that prove embarrassing to SSMC or detrimental to the reputation of the SSMC.

Authorization

  1. Internet access request must go through proper authorization and approval process.
  2. Only authorized SSMC staff may represent the hospital in business forums and discussions groups.
  3. Any new Internet web site (or significant changes to an existing site) shall be subject to approval by the IT Director before publication.
  4. The only authorized means of accessing the Internet for company purposes is through the SSMC IT sponsored network, firewall and approved service provider.
  5. Accessing the Internet through any commercial service provider or by any other method (dial-up or direct TCP/IP connection) while on SSMC network is prohibited. Any non-authorized access to Internet by the above means might lead to disciplinary actions.
  6. End users are personally responsible for all activities originating from the use of Internet account/and or system. This includes responsibility for all messages, commands, programs, software or files that they originate or willfully accept via the Internet.

Unauthorized usage:

The following actions shall constitute unacceptable use of the corporate network. This list is not exhaustive but is included to provide a frame of reference for types of activities that are deemed unacceptable. The user may not use the corporate network and/or systems to:

  1. The SSMC has software and systems in place that monitor and record all Internet usage.
  2. Our security systems are capable of recording each World Wide Web site visit and each email message into and out of our internal networks, and we reserve the right to do so at any time. No employee shall have any expectation of privacy as to his or her Internet usage. The IT Department will review Internet activity and analyze usage patterns and may choose to publicize this data to assure that SSMC internet resources are devoted to maintaining the highest levels of productivity.
  3. SSMC reserve the right to inspect any file stored in private areas of our network to assure compliance with the policy.
  4. The display of any kind of Pornographic document on any SSMC system is a violation of our policy. In addition, the pornographic explicit material may not be archived, stored, distributed, edited, or recorded using SSMC network or computing resources.
  5. The SSMC uses a centralized firewall to identify inappropriate or sexually explicit Internet sites. We may block access from within our networks to all such sites that we know of. If you find yourself connected accidentally to a site that contains sexually explicit or offensive material, you must disconnect from that site immediately.
  6. No employee may use SSMC facilities to download or distribute pirated software or data.
  7. No employee may use the SSMC Internet facilities to propagate any virus, worm, Trojan horse, or trap-door program code.
  8. Peer-to-Peer (P2P) networking is not allowed on the corporate network under any circumstance.
  9. Streaming media can use many network resources and thus must be used carefully. Streaming media is allowed for job-related functions only.
  10. Use of non-company-supplied remote desktop software and/or services (such as GoToMyPC, etc.) is prohibited.
  11. No company-owned or company-provided computer systems may be knowingly used for activities that are considered illegal under local emirates, federal, or international law. Such actions may include but are not limited to, the following:
    1. Unauthorized Port Scanning
    2. Unauthorized Network Hacking
    3. Unauthorized Packet Sniffing
    4. Unauthorized Packet Spoofing
    5. Unauthorized Denial of Service
    6. Unauthorized Wireless Hacking
    7. Any act that may be considered an attempt to gain unauthorized access to or escalate privileges on computer or other electronic system

Monitoring of computer and Internet usage:

The SSMC has the right to monitor, log and archive all aspects of its computer system including, but not limited to, monitoring Internet sites visited by Users, monitoring chat and newsgroups, monitoring file downloads, and all communications sent and received by users via Email, IM & Chat & Social Networking.

Download or File transfer controls:

  1. The users are not allowed to download or upload any software from / to the Internet without prior approval from IT director and management. Any software download or upload should be based on business requirement.
  2. Only IT approved software can be downloaded. Exceptions require individual business heads and ITD’s / COO’s approval. Trial versions of software must be deleted immediately after the expiry of trial period.
  3. Shareware and Freeware must not be downloaded and installed without proper approval from ITD/COO. Exceptions require individual business heads and ITD/COO approval.
  4. No SSMC confidential materials can be uploaded to any publicly accessible Internet computer without prior approval from ITD. Please refer to IT Security policy for the classification of confidential data.
  5. Viewing / downloading of non-business related information - the accessing, viewing, downloading, or any other method for retrieving non-business related information is prohibited. This includes, but is not limited to, personal business, entertainment sites or pornographic sites.

Web Browser Controls:

  1. Only the approved web browsers, appropriately secured by the IT shall be installed on all the systems. Only approved web browser should be used by all the users.
  2. Enabling and disabling of features and other functionality in the web browser by end users shall be disabled.
  3. On the web browser, the Internet Zone (default zone for all sites) shall be configured to high security, whereby Active-X controls and plug-ins are disabled.
  4. The IT Helpdesk can specifically enable the add-ons that are necessary. The trusted sites zone on the web browser shall be configured to medium security as this zone includes the sites that are considered safe to visit.
  5. In case there are additional sites that are deemed safe and free of malicious content, such sites shall be specifically configured in this zone.
  6. Web browser shall be configured to block Pop-up windows. Internet setting in the browser shall be set to high using the privacy settings.
  7. In case any sites fail to function under such a setting, the IT Helpdesk shall specifically allow them.
  8. In order to restrict monitoring of web browsing habits and attempts to gather personal information enabling of third party browser extensions shall be disabled.
  9. Controls shall be configured to warn users whenever a website tries to install any add-ons. Password and other user information shall not be cached in the web browser for business applications.
  10. The AutoComplete feature which enables remembering of web address, forms and even passwords in the web browser shall be disabled.
  11. The principle of least privilege shall be followed while configuring settings in the web browser.
  12. Users shall be informed to exercise caution while browsing websites, downloading unsolicited material, sharing files or entering chat-rooms.

Blocking Sites with Inappropriate Content:

The SSMC has the right to utilize hardware and software that makes it possible to identify and block access to Internet sites containing sexually explicit or other material deemed inappropriate in the workplace.

Blocking Sites with Non-productive Content:

The SSMC has the right to utilize hardware and software that makes it possible to identify and block access to Internet sites containing non-work-related content such as (but not limited to) Drug Abuse; Hacking; Illegal or Unethical; Discrimination; Violence; Proxy Avoidance; Plagiarism; Child Abuse; Alternative Beliefs; Adult Materials; Advocacy Organizations; Gambling; Extremist Groups; Nudity and Risqué; Pornography; Weapons; Sexual Content; Sex Education; Alcohol; Tobacco; Lingerie and Swimsuit; Sports; Hunting; War Games; Online Gaming; Freeware and Software Downloads; File Sharing and Offsite Storage; Streaming Media; Peer-to-peer File Sharing; Internet Radio or TV; Internet Telephony; Online Shopping; Malicious Websites; Phishing; SPAM; Advertising; Brokerage and Trading; Web-Based Personal Email; Entertainment; Arts and Culture; Job Search; News and Media; Social Networking; Political Organizations; Reference; Religion; Travel; Personal Vehicles; Dynamic Content; Folklore; Web Chat; Instant Messaging or IM; Newsgroups and Message Boards; Digital Postcards; Real Estate; Restaurant or Dining; Personal Websites or Blogs; Content Servers; Domain Parking; Personal Privacy; Finance and Banking; Search Engines and Portals; Web Hosting; Secure Sites; or Web-based Applications

Instant messaging tools:

Instant Messaging or social media or any other similar tool MUST be removed from user’s desktops unless otherwise it’s installed for business needs. End users should only use approved SSMC standard Instant Messaging tools upon their business needs.

Non-Compliance:

  1. Violations of the Internet usage Policy will be documented and can lead to revocation of system privileges and/or disciplinary action up to and including termination.
  2. The SSMC management may at its discretion seek legal remedies for damages incurred as a result of any violation.
  3. The SSMC may also be required by law to report certain illegal activities to the proper enforcement agencies.
  4. Before access to the Internet via SSMC network is approved, the potential Internet user is required to read this Internet usage policy and sign the IT acceptable usage policy.

Usage Threats

Internet connectivity presents the SSMC with new risks that must be addressed to safeguard the facility’s vital information assets. These risks include:

  1. Inappropriate Use of Resources:

Access to the Internet by personnel that is inconsistent with business needs results in the misuse of resources. These activities may adversely affect productivity due to time spent using or "surfing" the Internet. Additionally, the SSMC may face loss of reputation and possible legal action through other types of misuse.

  1. Misleading or False Information:

Request & Approval Procedures:

As part of the Internet access request process, the employee is required to read both this Internet usage Policy and the Information Security Policy. The user must then sign the statements that he/she understands and agrees to comply with the policies.

References and Cross References

  1. The UAE federal law No 5 on Cyber security law issued on 2012 and the amendment issued in May in 2016 for the same law.
  2. Internet guidelines by Telecommunication Regulatory Authority in the UAE
  3. Joint Commission International: Joint Commission International Accreditation for Hospitals Fifth Edition. USA: Joint Commission Resources; 2017. MOI Chapter

Definitions

Firewall: is a network security system that monitors and controls the incoming and outgoing network traffic based on predetermined security rules. A firewall typically establishes a barrier between a trusted, secure internal network and another outside network.

Instant Messaging: A text-based computer application that allows two or more Internet-connected users to "chat" in real time.

Peer-to-Peer (P2P) File Sharing: A distributed network of users who share files by directly connecting to the users' computers over the Internet rather than through a central server.

Streaming Media: Information, typically audio and/or video, that can be heard or viewed as it is being delivered, which allows the user to start playing a clip before the entire download has completed.

Proxy: is a server (a computer system or an application) that acts as an intermediary for requests from a client seeking resources from other servers.

Feedback
0 out of 0 found this helpful

scroll to top icon