University of Southern Mississippi Information Security
infosec home | news | iTech
InfoSec Policy
AntiVirus
Reources
FAQs
DIY Check List
Policies Menu:
Acceptable Use Policy
Peer to Peer Policy
Password Policy
Student Email Policy
Secure Network Infrastructure Policy
THE UNIVERSITY OF SOUTHERN MISSISSIPPI
Information Technology
Peer to Peer File Sharing Policy

1. Overview
Peer-to-Peer (P2P) applications have become the most popular and controversial method through which digital files of various formats and types are traded, shared, and distributed across the Internet.
While the University of Southern Mississippi recognizes that there are legitimate uses for P2P applications, the university also understands that significant risks are implicit in the use of such applications.
The university does not seek to ban P2P file sharing from the campus network, and will continue to support academic freedom and any technologies that can be used to foster collaboration. However, Southern Miss must also protect its assets, its reputation, and its resources.
2. Purpose
This policy has been implemented in order to mitigate exposure of the University of Southern Mississippi to security risks and liabilities associated with the irresponsible use of P2P applications on university resources.
3. Scope
3.1 Resources

This policy shall apply to all computer workstations, laptops, servers, networked appliances, and any other device capable of participating in a P2P network if such device is owned by Southern Miss; or any device utilizing University network resources, even if that device is owned privately or by a third party.

3.2 Individuals

This policy applies to faculty, staff, students, contractors, consultants, temporaries, and other workers at Southern Miss, including all personnel affiliated with third parties at such time they are using any resource described under section 3.1.

4. Policy
4.1 Prohibited Activity
This policy strictly prohibits the distribution, downloading, uploading, or sharing of any material, software, data, document, sound, picture, or any other file that is:
  1. Specified as illegal by any federal or state law, statute, proclamation, order, or decree.
  2. Copyrighted and not authorized for distribution by the copyright owner.
  3. Considered to be proprietary, privileged, private, or otherwise vital to the operation of the university; including, but not limited to, personnel, student, financial, or strategic records and documents, or any material governed by federal and state regulations.
  4. Any virus or malware for the purpose of deployment or implementation with ill-intent.
Any P2P activity is strictly forbidden in the cases of:
  1. Computer labs.
  2. Computer workstations and other network devices readily accessible to multiple users.
  3. Computer workstations and other network devices used in daily operation by areas and departments heavily affected by federally mandated regulatory compliance.
  4. Laptops, computer workstations, and any other network capable device provided by iTech through equipment services.

Users of Southern Miss resources may not attempt to circumvent, bypass, defeat, or disrupt any device, method, or technology implemented by the university for the purpose of P2P mitigation.

4.2 Rights and Responsibilities
  1. Students, faculty, staff, contractors, consultants, temporaries, and other workers at Southern Miss shall bear legal/financial responsibility for events resulting from their own use of P2P applications.
  2. Individual departments, colleges, administrative areas, and other entities must respond in a timely and efficient manner to all inquiries and complaints that arise in regard to this policy.
  3. iTech and Southern Miss are required by federal law to report certain illegal activities to specified law enforcement agencies without notice to the user or the appropriate department.
4.3. Technology Mitigation
  1. iTech will implement and maintain a network appliance specifically designed to control and track P2P usage.
  2. P2P traffic will be limited in bandwidth, to ensure that network resources are available for all business- and education-related needs and processes.
  3. P2P traffic may be blocked for specific areas described under section 4.1.2 of this policy.
  4. Outbound P2P traffic positively identified as copyrighted material will be blocked.
  5. P2P traffic and usage information will be collected, and the collected information will be governed by the policies set forth in section 5 of this document.
5. Privacy
5.1 Information and Collection
  1. Logs detailing P2P traffic and usage on the Southern Miss network will be collected.
  2. Logs will contain IP addresses involved in data transfer, direction of transfer (if retrievable), metadata of file (if retrievable), time, protocol used, and amount of data transferred.
  3. Logs will not contain any personal identifying information.
  4. Logs will be kept for 6 weeks (42 days).
5.2 Information Use
  1. Logs will be subject to periodic review for enforcement of this policy.
  2. Information collected may be used in aggregate format for reporting purposes.
  3. Individual usage will not be actively or routinely monitored.
  4. Logs maybe used to investigate complaints or suspicious traffic patterns.
  5. Individual colleges, departments, functional or administrative areas, and entities of Southern Miss may request information about P2P usage pertinent to that area. This request may only be made by the dean, chair, department head, manager, or other leadership of the area requesting information.
  6. iTech will not release any information collected by the appliance to any entity external to Southern Miss unless compelled or obligated by law or court order, subpoena, warrant, or writ; with the exception of Audible Magic Corporation, which will receive data exclusively in aggregate format, with no personal identifying information, for purposes of internal statistical analysis.
6. Enforcement
6.1 Faculty, Staff, and Students

Any faculty, staff, or student found to have violated this policy may be subject to disciplinary action, up to and including suspension, expulsion, and/or termination of employment in accordance with procedures defined by Southern Miss administrative policies stated in the handbook governing that individual.

6.2 External Entities

Any external entity, contractor, consultant, or temporary worker found to have violated this policy may be held in breach of contract, and as such, may be subject to grievances or penalties allowed by such contract.

7. Definitions
  1. P2P (peer-to-peer), in the context of this policy, is defined as direct data communication between two or more network capable devices over the Internet or other network, usually for the purpose of sharing any data file (including, but not limited to: music, pictures, video, software, and documents).
  2. P2P network, in the context of this policy, is defined as a collection of distributed network-capable devices participating in P2P activity.
  3. Peer-to-Peer (P2P) application is defined as any application that allows a network-capable device to participate in one or more P2P networks.
  4. Sharing, in the context of this policy, describes the action and activity of making any data file available to one or more P2P networks.
  5. Logs are defined as collections of information, typically used to document activity and events.
  6. Uploading describes network trafficking of data files originating from the Southern Miss network and destined for an external network.
  7. Downloading describes network trafficking of data files originating form an external network and destined for the Southern Miss network.
  8. The Southern Miss network and networking resources describe all materials and devices owned by the University of Southern Mississippi and used to provide network connectivity to any network capable device. This includes all jacks, cable, hubs, wireless access points, switches, and routers.
8. Revision History
  1. 11/15/06 : Outline formating slightly changed to accomdate HTML formatting.
  2. 11/15/06 : Posted to website.
  3. 11/16/06 : Added link to Password policy.
  4. 04/23/08 : Modified policies menu.


Maintained by the Southern Miss InfoSec Team
Last modified: April 23, 2008 14:50 CDT | Questions or Comments?
URL: http://www.usm.edu/infosec/p2p-policy.php
The University of Southern Mississippi | AA/EOE/ADAI

USM Home Page InfoSec Home Page USM Home Page