Razi University Network User Security Policy – Version 5 (Revised 2026) - دفتر فناوری اطلاعات
Razi University Network User Security Policy – Version 5 (Revised 2026)
Revision Date: July 20, 2026
Responsible for Revision: Department of Information and Communication Technology (ICT), Razi University
Review Period: Every 6 months
1. Introduction
To protect user information, safeguard system data, and prevent cyber threats, this policy has been developed by the ICT Department of Razi University. Compliance with all provisions of this document is mandatory for all users connected to the university network, and any violation will result in disciplinary and legal consequences.
2. Definitions
Network Users: All faculty members, staff, students, and guests who connect to the university network via any device (computers, laptops, tablets, mobile phones, network printers, etc.). System Data: All data stored in university systems including organizational email, office automation, personnel decree system, Golestan (academic system), research systems, and library systems. Security Abuse: Any intentional or unintentional action that leads to privacy violation, data disclosure, unauthorized access, service disruption, or network intrusion. Personal Device (BYOD): Any electronic device owned by the user and used to connect to the university network. Security Incident: Any suspicious or confirmed event that compromises information or network security.
3. Security Policies
3.1 Password Management
Passwords must be at least 12 characters long and include a combination of uppercase letters, lowercase letters, numbers, and special characters (@ # $ % ^ & *). Use of common words, family names, birthdates, phone numbers, or password reuse across multiple systems is prohibited. Periodic password changes (e.g., every 30 days) are not mandatory; however, in case of disclosure, breach, or request from ICT, passwords must be changed immediately. Storing passwords in text files, writing them on paper, sharing with others, or any form of disclosure is prohibited. Use of a reputable password manager (approved by ICT) is permitted.
3.2 Information and Device Protection
When leaving your workstation, even briefly, lock your screen (Win+L on Windows / Ctrl+Cmd+Q on Mac). Installation of the university-approved antivirus (organizational licensed version) on all systems connected to the network is mandatory, and automatic updates must be enabled. All laptops and mobile devices must have Full Disk Encryption (e.g., BitLocker for Windows or FileVault for Mac). Use of external storage devices (USB flash drives, external hard drives, mobile phones) is only permitted with written approval from ICT and after security scanning. Installation of any software unrelated to official duties, cracked software, or hacking tools on university systems is strictly prohibited. System data and authentication tokens (e.g., one-time passwords, digital certificates) must never be shared with unauthorized individuals, even inadvertently.
3.3 Network Communications and Security
Use of organizational email for registration on non-university websites, personal services, or public sharing is prohibited. Use of personal VPNs to bypass filtering, hide traffic, or access prohibited services on the university network is not allowed. All communications with internal and external systems must use the secure HTTPS protocol (browsers must enforce secure connections). Adding, moving, or installing any network equipment (switches, routers, access points, hubs, new cabling) is only permitted with prior coordination and approval from ICT. Deployment of any software or hardware service that provides services to external users (e.g., web servers, FTP, email servers) is only allowed in the main data center with written approval from ICT.
3.4 Countering Cyber Threats and Reporting
Never click on links or attachments from unknown or suspicious emails. If in doubt, contact the sender to verify authenticity. Do not use unofficial messaging apps (Telegram, WhatsApp, Eita, Bale, etc.) to send confidential university information. Regularly (at least weekly) back up all sensitive data on office computers and store them in the secondary data center or a secure cloud space (approved by the university). Upon observing any suspicious activity (including unusual slowness, sudden pop-up ads, settings changes, unusual password requests), the user is required to report the matter to ICT within 24 hours via direct phone, support email, or ticketing system.
4. Accountability and Security Breach Follow-up
Any person connecting to the university network implicitly accepts this policy and is responsible for its full implementation. In case of violation, the matter will be reviewed by the University Information Security Committee and appropriate actions will be taken according to the type of violation. For employees: written warning, access restrictions, performance score reduction, temporary or permanent access revocation, and in serious cases legal action. For students: verbal warning, system access restrictions, deprivation of network services, and in case of repetition, referral to the Disciplinary Council. If damage is compensated and deficiencies are rectified, gradual restoration of access is possible with ICT approval.
5. Training and Awareness
All users are required to participate in cybersecurity training courses organized by the ICT Department at least once a year. A certificate of completion will be mandatory for network access renewal.
Conclusion and Support Contact
Strict adherence to these policies plays a key role in maintaining the confidentiality, availability, and integrity of university information. Your cooperation as users is the greatest barrier against cyber threats. For any questions, clarifications, or incident reports, please contact the Information Security Support Unit.
شناسه : 19271256

