Acceptable Use

Policy number: 8.1

Policy section: Information Technology

Revised Date: August 19, 2026


1.  Definitions

Definitions of capitalized terms are set forth in Appendix A.

2.  Policy Statement

The University’s information technology Resources are a critical part of the University’s teaching and research missions supporting both academic and administrative units. In order to effectively deliver these services the University maintains this Acceptable Use policy to guide its use of University Resources. University Resources are the property of the University and are provided as a privilege to Users and must be used solely for University purposes and in a manner consistent with University policies and applicable law.  This policy governs the appropriate use of University Resources.  This Policy is intended to support broad, open access to University Resources while ensuring that use remains secure, ethical, lawful, and aligned with the University’s academic and administrative missions.

3.  Purpose

The purpose of this policy is to assure an information technology environment that supports and protects the University’s teaching, research and service missions, as well as its administrative functions. Along with the privilege of using the Resources of the University comes specific responsibilities for safeguarding University Data, complying with applicable laws and policies, and maintaining the integrity, security, and availability of University systems as outlined in this policy.

4.  Applicability

This policy applies to all Users and to all University Resources, whether managed by the Office of Information Technology ("OIT") or by another person or entity. This Policy applies to all University trustees, officers, faculty, staff, students, alumni, applicants, volunteers, contractors, vendors, and guests who access or use University Resources. This policy provides a minimum standard for Resource usage at the University and does not preclude creation and enforcement of additional or more specific policies for individual campus administrative or academic units. Policies existing elsewhere on campus must be consistent with this policy.

5.  Questions

The Chief Information Officer (CIO) or designee shall be responsible for the interpretation of this policy, the resolution of problems and conflicts with departmental policies, and the review of special situations. The CIO may grant exceptions to this policy and/or standards after a formal review as provided in accordance with University procedures and subject to appropriate documentation.

6.  Acceptable Use

  1. Each User may only use the computers, computer accounts, and computer files for which that User has been given specific authorization. Users must access University Resources only through their assigned credentials and only for authorized academic, administrative, or operational purposes.
  2. Users may not use another individual's account, attempt to capture or guess other Users' passwords, reverse engineer software or destroy data without authorization from the owner of the data or other appropriate University employee. Users must not use tools that are normally used to assess security or to attack computer systems or networks (e.g., password 'crackers,' vulnerability scanners, network sniffers, etc.) unless specifically authorized to do so by the Chief Information Security Officer (CISO). Users may not intercept, monitor, or attempt to access network traffic, communications, or data intended for other Users unless explicitly authorized by OIT for legitimate business or security purposes.
  3. Users must protect passwords and secure University Resources against unauthorized use or access. Users must work with OIT to configure hardware and software in a way that reasonably prevents unauthorized users from accessing the University’s Resources.
  4. Users must not attempt to bypass, defeat, or disable security controls, monitoring tools, authentication mechanisms, or access restrictions implemented on any Resource. Users must secure unattended sessions by locking or logging out of devices and must not leave confidential information exposed on screens or in shared environments.
  5. Users may not communicate any information concerning any personal identification number, account credentials, social security number, credit card number, financial account number, or other confidential information without the permission of its owner or the controlling authority of the Resource. Users must handle all sensitive or confidential University Data in accordance with applicable data classification, privacy, and security requirements.
  6. The University is bound by its contractual and license agreements respecting certain third party resources; Users must comply with all such agreements when using such resources. Users must not use University Resources in a manner that violates software licensing agreements, vendor terms of use, cloudservice agreements, or dataprotection requirements.
  7. Transmission of broadcast email is governed by this policy. Users may not transmit unsolicited content, including advertising third party materials or services. Users must not transmit unsolicited bulk messages (“spam”), junk email, chain letters, or mass advertising through University systems, nor may they send any content that is harassing, threatening, intimidating, obscene, indecent, lewd, lascivious, or otherwise unlawful.
  8. Users must abide by OIT policies and procedures and by all federal, state, and local laws, including copyright and other intellectual property laws, and must not conduct any activity that would jeopardize the University’s tax exempt status including engaging in partisan political activity that could imply University endorsement or that would constitute use for , for commercial purposes (unless otherwise authorized in writing by the President or a Vice President, after consultation with the Controller), for criminal purposes, or for personal economic gain unrelated to authorized University duties.
  9. The University does not assess additional charges for identity verification or credential issuance beyond standard tuition and fees . The identity credential used by the University includes an assigned eight-digit identification number (SMUID) combined with each student’s unique password. The cost of setting up and administering the SMUID/Password system is recovered through general tuition and fees. The University does not assess additional charges for students enrolled in distance education courses to use the SMUID/Password system.
  10. Users have no reasonable expectation of privacy when using University Resources. The University may access, monitor, review, or disclose information stored on or transmitted through University Resources when authorized by law, University policy, legitimate operational need, or security requirements.
  11. Users must store, transmit, and process University Data only in OITapproved systems consistent with University data classification and information security requirements. Users may not use unapproved cloud services, personal storage services, or external systems for University Data.
  12. Users must not disclose proprietary, unpublished, or confidential University research, intellectual property, or academic work without proper authorization.

7. Artificial Intelligence Tools and Automated Systems

The University supports the responsible use of Artificial Intelligence (AI) tools to enhance teaching, learning, research, and administrative activities. The use of AI must be consistent with University policies, applicable laws, and standards for data protection, academic integrity, and ethical conduct.

  1. Users may not input, upload, or disclose Restricted, Confidential, Sensitive, or otherwise protected University Data into any external Artificial Intelligence Tool unless the tool has been reviewed in accordance with the University’s Software Evaluation & Acquisition Guide and subject to a security review, appropriate contractual protections, and applicable University dataclassification requirements.
  2. Users must use only OITapproved AI platforms when processing, storing, or generating University Data. Users are expected to work with OIT to identify appropriate tools for these purposes. Personal AI accounts, free-tier services, or consumer-grade AI tools must not be used for University Data, including Research Data, unless explicitly authorized.
  3. Users must not rely solely on Artificial Intelligence Tools to make decisions with legal, financial, academic, personnel, safety, or compliance implications without appropriate authorization and meaningful human oversight. This does not preclude the use of Artificial Intelligence Tools in instructional settings, including grading and assessment, where consistent with course design and academic standards.
  4. Users are responsible for verifying the accuracy, appropriateness, and legality of any output generated by Artificial Intelligence Tools before relying upon, publishing, transmitting, or incorporating such output into academic, administrative, or research activities. AIgenerated content may not be represented as authoritative or factual without appropriate human review. Users must also comply with all applicable copyright, intellectual property, research integrity, and export control requirements, and must not include copyrighted, proprietary, or unpublished research materials without appropriate authorization.
  5. Users must not use Artificial Intelligence Tools to engage in academic dishonesty, including but not limited to: generating assignments, examinations, or assessments in violation of University academic integrity policies; fabricating citations; or creating falsified data or research outcomes. This provision does not apply where the use of Artificial Intelligence is explicitly permitted or required by the instructor, program, or research protocol.
  6. Users must not use Artificial Intelligence Tools to produce or disseminate content that is harassing, threatening, discriminatory, defamatory, obscene, misleading, or otherwise unlawful; nor may Users use AI to impersonate others or misrepresent their identity or authority.
  7. The University may update, restrict, or prohibit the use of specific Artificial Intelligence Tools that pose unacceptable security, privacy, regulatory, or operational risks. OIT may block access to unapproved AI systems when necessary to protect University interests.
  8. Users must comply with the University’s current OIT Artificial Intelligence Guidance, which provides detailed and regularly updated requirements for the appropriate use of Artificial Intelligence Tools. The OIT AI Guidance is intended to support safe, effective, and responsible use of AI and will evolve as technologies and institutional practices mature. The most current version of the OIT AI Guidance is available at: https://www.smu.edu/oit/ai

8.  Acquisition and Deployment of Equipment and Software

Any purchase of a Resource, whether stand-alone or interconnected with other University Resources on campus, must take into account standards developed by OIT. OIT will make the standards available to the SMU community. OIT implements and maintains University site licenses for software to ensure that University users receive favorable pricing and support terms. All acquisitions of hardware, software, cloud services, or other technology resources must comply with OIT procurement standards, security requirements, and vendorreview processes prior to purchase or deployment. Unauthorized or nonstandard acquisitions may not be supported on University networks or systems.

9.  Business Continuity

  1. Departments responsible for critical information technology services must maintain a business continuity plan which accounts for computer facilities, equipment, staffing, and Resource needs. University Resources must follow OITapproved backup procedures and recovery methods to ensure continuity of operations.
  2. All backup media (e.g. removable backup media) stored outside University data centers must be encrypted, both at rest and in motion, to reduce risk of interception by unauthorized parties and must be stored at a distance sufficiently far from the primary data location to ensure that a regional disaster will not disrupt access to both the primary and backup data simultaneously. When backup media is retired, it must be destroyed according to OIT’s security standards. Departments must also ensure that disaster recovery plans are reviewed and updated periodically in coordination with OIT.

10.  Email

Emails sent or received by Users in the course of conducting University business are University Data. Users must use University-provided email accounts for conducting University business, rather than personal email accounts. Emails containing confidential information must be encrypted using OITapproved tools and processes, consistent with University information security requirements. Automatic forwarding of University email to nonUniversity accounts is prohibited unless expressly authorized by OIT. Users must not send unsolicited bulk messages (“spam”), forge headers, or impersonate others in email. Bulk messaging must follow the University’s broadcast email requirements (see Section 17).  Suspected phishing or malicious email should be reported to OIT per University security guidance.

11. Guest Access

Access to the campus network by a guest shall be coordinated through a University sponsor. The sponsor is responsible for take responsibility for the actions of the guest while they are using University Resources. Staff or faculty at service desks (library reference desk, computer help desk, or event support staff) shall not generally sponsor guests unless they have invited the guest to campus or are asked to sponsor the guest by an eligible sponsor. Guests must use only OITapproved guest access methods and may be granted limited, temporary access based on University security requirements. Guest access may be terminated at any time for security or policy violations.

12. Mobile Equipment

It is the responsibility of anyone who utilizes the SMU network for the purpose of accessing or processing University Data using Mobile Equipment to take appropriate measures at all times to safeguard that information. All University employees must ensure they are taking every reasonable precaution against accidental or intentional data compromise by implementing a PIN, passcode, biometric lock, or equivalent security control to access the Mobile Equipment. Mobile Equipment used to access University Data must comply with OIT security requirements, including encryption where applicable, timely installation of security updates, and prevention of unauthorized access. Users must promptly report the loss or theft of any Mobile Equipment that contains or can access University Data. Mobile Equipment must also meet the applicable technical and configuration requirements set forth in the University’s Information Security Policy and related OIT security standards.

13. Remote Access and Virtual Private Network (VPN)

University employees who work remotely must ensure that the computer used to access University Resources meets all OIT security standards. Users must use a VPN when accessing University Resources from an insecure network or when accessing a Resource containing confidential information. Users may not use nonUniversity VPNs, remoteaccess services, or similar tunneling tools to access University Resources unless expressly authorized by OIT. All VPN and remoteaccess sessions are subject to security monitoring and logging in accordance with University policy, and Users have no expectation of privacy when connected through the University’s VPN. Devices used for remote access must be kept uptodate and reasonably secured against unauthorized access.

14. Cloud or Hosted Computing

University departments and schools may only use OIT-approved cloud services for storage and/or processing of University Data. All cloud or hosted services must comply with University dataclassification requirements, contract and security review processes, and any technical controls required by OIT prior to use. University Data may not be stored, transmitted, or processed in personal cloud accounts or unapproved external services.

15. Third Party Access

The CISO must assess and approve all third-party vendors that host or access University Data. Contracts with third parties will include provisions relating to information security as required by the CISO. Third parties will be expected to protect University Resources and University Data with security at least equal to the security described in this policy, in University Policy 8.2, Information Security, or otherwise required by the CISO. Third parties may access University Data or Resources only for authorized business purposes and only for the duration necessary to perform contracted services. Thirdparty access must be provisioned through OITapproved methods and must follow University dataclassification, privacy, and security requirements. Third parties must promptly report any actual or suspected security incidents involving University Data to OIT. Unauthorized thirdparty access or use is strictly prohibited.

16. Wireless Access

All wireless access points within the University must be approved and centrally managed by OIT. Non-sanctioned installations of wireless equipment or use of unauthorized equipment on campus premises is prohibited. All wireless networks managed by the University will require authentication via a University ID or will provide a means for guests to register. Users may not deploy personal hotspots, routers, wireless repeaters, or any device that interferes with the University’s wireless network. Use of the University’s wireless network is subject to monitoring and security controls implemented by OIT. Wireless access may be limited, modified, or disabled as necessary to maintain network performance or security.

17. Broadcast Email Messages on Campus

  1. It is University policy to regulate messages broadcast to the campus via email to assure that such messages are of overall importance to the entire community. Any community member or campus group wishing to send broadcast mail messages should review the requirements listed below.
  2. There are two options for delivering broadcast messages:
    1. One is through the four main bulk distribution lists which include all undergraduate students, all graduate students, all faculty and all staff. Messages distributed through these main bulk lists will be reviewed by the Vice President for Development and External Affairs or their designee prior to distribution and should contain content that is mandatory for the entire campus to know.
    2. The second is through departmental lists created from the four main distributions lists. All students, faculty or staff may opt out of these departmental lists on an annual basis. All offices wishing to send broadcast email messages to campus can do so through these lists created specifically for their needs. Messages distributed through these departmental lists are done at the discretion of the department.
  3. Users must not use standard University email systems to send broadcast or mass emails outside of the approved processes described in this section. Unapproved broadcast messages may be blocked or removed to preserve system performance and reduce misuse.
  4. Broadcast emails must comply with all University policies, including privacy, acceptable use, antiharassment, information security, and copyright requirements.

18. Privacy

Educational Records, Protected Health Information, Personally Identifiable Information, Financial Information, and University Data must be protected as provided in University Policies 1.11, Privacy of Health Information (HIPAA), 1.10, Privacy of Education Records (FERPA), 8.2, Information Security, and 4.4, Collection of Funds. Student information must be protected whether the student is physically present on campus, enrolled in a distance education or correspondence course, or is a continuing education student. Users should have no expectation of privacy when using University Resources, except as required by law or specific University policy. The University may access, monitor, or disclose information stored on or transmitted through University Resources when authorized by law, necessary to support operations, or required to protect University systems, data, or users. Such access will be conducted in accordance with applicable policies and legal requirements.

19. Exceptions

University employees who are unable to comply with this policy must request an exception. Exceptions to this policy must be approved by the CIO based on academic or business need. Anyone wishing to purchase services outside of the University approved solution(s) must submit a copy of the proposed contract with the service provider, including, but not limited to the applicable privacy policy, to the University’s Senior Contracts Administrator for review by OIT and other appropriate University departments prior to purchase. A security review of the service must be conducted and meet or exceed industry standards for the use requested. The CIO will review exceptions annually for continued application and notify the exception holder of any concerns.

All exception requests must be documented, reviewed, and retained in accordance with University procedures. Exceptions may be modified or revoked if security, legal, or operational risks change. Users operating under an approved exception must still take reasonable measures to protect University Data and must comply with all other applicable University policies. Unauthorized use of unapproved tools, systems, or services is prohibited.

20. Consequences of Misuse of University Resources

  1. Immediate consequences of suspected or actual policy violation required to prevent or deter further misuse may include account locking, network access loss, and quota restrictions. Suspected violations must be reported to the OIT Help Desk at 214-768-4357 or by email at help@smu.edu. OIT may also temporarily suspend access to specific University Resources or services as necessary to protect University systems or data.
  2. In addition, employees found to be in violation of this policy or University Policy 8.2, Information Security, may be subject to discipline in accordance with University Policies 2.1, Standards of Professional Ethics for Faculty and Academic Freedom, 2.17, Procedural Standards for Faculty Sanctions and Dismissals, 7.23, Personal Conduct, 7.24, Corrective Action for Staff, and 7.28, Dishonest, Fraudulent and Illegal Practices, as applicable, up to and including termination of employment with the University. Violations may also result in revocation of access to specific University Resources, mandatory retraining, or other corrective measures.
  3. Third parties, including vendors and guests, in violation of University Policies may be subject to reduced service or denied service, or otherwise restricted in their ability to conduct business with the University. The University may suspend or terminate thirdparty access immediately if continued access poses security, operational, or legal risk.
  4. Students found to be in violation of this policy may be subject to discipline in accordance with the SMU Student Code of Conduct. Student access to University Resources may also be restricted pending investigation.
  5. Some cases may warrant investigation by law enforcement agencies and subject individuals to civil and criminal liabilities. The University may preserve, review, and provide relevant logs, records, or evidence to law enforcement or regulatory authorities as permitted or required by law.

Appendix A: Definitions

“Artificial Intelligence Tools” include external or internal systems that generate, analyze, or transform content, predictions, or decisions using machine learning, natural language processing, generative models, or other automated computational methods. This includes, but is not limited to, generative AI tools, large language models, chatbot systems, image or audio generation tools, and automated decisionmaking systems.

“CIO” refers to the Chief Information Officer of the University.

“CISO” refers to the Chief Information Security Officer of the University.

"Computer Facilities" refers to laboratories, computing centers, public access areas, and other repositories of University-provided information technology equipment.

“Mobile Equipment” refers to cellular telephones, smart phones, data cards, hotspot devices, tablets, accessories and other telecommunications equipment requiring access to a telecommunications service provider network.

"Storage Media" refers to any device that has the ability to store data, including but not limited to optical discs, flash drives, tape drives, and internal or external hard drives.

“Research Data”: Information collected, created, received, maintained, or used in the conduct of research or other scholarly activities. Research Data incorporates restricted, sensitive, or regulated information—including proprietary University information, trade secrets, Controlled Unclassified Information (CUI), or export-controlled information.

“University Data” refers to critical data necessary to the University’s operation and other information created by or for the University, or by or for University trustees, officers, employees, students, alumni, applicants, volunteers, donors, guests, customers or contractors engaged in University-sponsored activities.

“University Resources” refers to the University’s computing, communications, and other information technology systems and includes all hardware, software (including data and documentation), local area networks, internet systems, and applications and data stored on such information technology systems and any other electronic device or service that can store, transmit, or receive information. University Resources include, but are not limited to, servers, computers, personal computers, workstations, laptops, mainframes, minicomputers, Mobile Equipment, land line telephones, wireless devices, media players, storage media, computer networks, connections to network services such as the Internet and web pages, subscriptions to external computer services, networking devices, and any associated peripherals and software, regardless of whether used for educational, research, service, administrative or other purposes.

“User” refers to any person who installs, develops, maintains, administers, or uses Resources, whether for educational, research, service, administrative or other University purposes, including, but not limited to, University trustees, officers, employees, students, alumni, applicants, volunteers, donors, guests, customers, contractors engaged in University-sponsored activities, and information technology system administrators.


Revised: August 19, 2026

Adopted: March 6, 2015

The official University Policy Manual is housed in the Office of the University Secretary. The University Secretary is responsible for maintaining new and updated policies and for maintaining this website. Should the official University Policy Manual conflict with any internal policies, procedures, departmental administrative rules, or guidelines, that may be contained in manuals provided by schools, departments, or divisions within the University, the official University Policy Manual controls.