The framework within which Ofgem business is conducted on Ofgem IT — protecting users, equipment, information and reputation. Please read in full before commencing your engagement.
Information technology resources, such as PCs, laptops, smartphones, and tablet devices offer new and exciting ways of working and engaging with our colleagues and citizens. However, we must also be aware that improper use can impact us, our colleagues, citizens, OFGEM's reputation and the public purse.
This Acceptable Use Policy (AUP) aims to protect all users of OFGEM equipment and minimise such risks by providing clarity on the behaviours expected and required by OFGEM and the consequences of breaching the AUP. It sets a framework within which to conduct OFGEM's business and explains how we can achieve compliance and evaluation of new business and technology requirements.
To ensure that users understand their responsibility for the appropriate use of OFGEM's information technology resources. Understanding this will help users to protect themselves and OFGEM's equipment, information and reputation.
The use of all OFGEM equipment and information (all information systems, hardware, software and channels of communication, including voice-telephony, social media, video, email, instant messaging, internet and intranet). Any information stored by OFGEM employees in OFGEM information systems for private use within the boundaries of Personal use of OFGEM IT is also subject to the provisions of this policy.
All OFGEM employees, agents, contractors, consultants and anyone else (referred to in this document as users) with access to OFGEM's information, information systems and equipment.
Use Ofgem IT in a sensible, professional way in accordance with the Civil Service Code.
Don't do anything on your device that could harm or embarrass Ofgem, its employees, suppliers, partners or citizens.
Only use Ofgem equipment to access Ofgem information. Don't use your own computers, phones or email accounts.
Report anything that you think may have breached this policy to SPaR.
Be responsible for your own actions and act responsibly and professionally, following the Civil Service Code and respecting the Department and fellow employees, suppliers, partners, citizens.
Use information, systems and equipment in line with OFGEM security and Information Management policies. OFGEM Security Policies and Standards apply to OFGEM suppliers and contractors where explicitly stated in the Security Schedule of the contract. OFGEM Standards are not a cross government requirement.
Immediately report any breach of this Acceptable Use Policy to your line manager.
Never undertake illegal activity, or any activity that would be harmful to OFGEM's reputation or jeopardise staff and/or citizen data, on OFGEM technology.
Understand that both business and personal use will be monitored.
Be aware that you can use whistleblowing procedures to raise a concern if you believe that someone is misusing OFGEM information or electronic equipment.
Undertake regular education and awareness on security and using OFGEM information systems and equipment, including the annual Responsible For Information training, in order to be able to understand, recognise and report threats, risks and incidents. Complete all mandatory IT training, and any other training relevant to your job role.
Protect login credentials (usernames and passwords).
Create secure passwords by following guidance below.
Do not logon to any OFGEM systems using another user's credentials.
Lock the screen when you are away from your device.
Log out of all electronic devices connected to OFGEM's internal network when you have finished for the day. Switch off mobile devices when not working unless you need to be contactable for business purposes including out of hours escalations and/or contingency reasons.
Use a password that is easy for you to remember, but hard for someone else to guess. Stringing three words together is a good way of doing this. You can add numbers and symbols as well if you want. An example might be: red house monkey or 74 red house monkey?!
Do not use words that are specific to you and therefore easy for a hacker to guess or find out — such as birthdays, child's name, pet's name, sports team, musician, band etc.
Some of our systems (such as myHR) have legacy requirements for passwords using a complex combination of letters, numbers and symbols. We are working to update these to support our new guidance but, in the meantime, please comply with the requirements of the system.
Employees are personally responsible for protecting their passwords. You must not share passwords with friends, colleagues, family or unsolicited callers, even if they claim to be an official.
If you need to share a password with someone (e.g. if you are sending a password protected file by email) please share the password by separate means such as text message or telephone.
If you think someone knows your password, please change it as soon as you can.
Try not to write passwords down but, if you do, keep them in a secure place (e.g. a file on your H Drive or iPhone, a password manager or a piece of paper in a locked cupboard).
Protect personal and sensitive information.
Ensure that all information is created, used, shared and disposed of in line with business need and in compliance with security policies and any Information Asset Inventory guidance.
Do not attempt to access personal data unless there's a valid business need that is appropriate to your job role.
Do not provide information in response to callers or e-mails whose identity they cannot verify.
Be careful not to be overheard or overlooked in public areas when conducting OFGEM business.
Apply the Government Classification policy appropriately to document headers and email subject lines in relation to the OFFICIAL-SENSITIVE handling caveat. Where Ofgem staff are sharing sensitive information beyond Ofgem's own systems, the information should be password protected or encrypted to limit the risk of exposure.
Do not attempt to access, amend, damage, delete or disseminate another person's files, emails, communications or data without the appropriate authority.
Do not attempt to compromise or gain unauthorised access to OFGEM IT, telephony or content, or prevent legitimate access to it.
Users are personally accountable for what they do online and with OFGEM technology.
Appropriate personal use of IT resources, such as access to the internet, is permitted and you must use proper judgement to assess what is appropriate.
You must ensure that all personal information stored is appropriate i.e. legal, appropriate and compliant with this policy.
The ability to store personal information on OFGEM owned devices and systems is a privilege and OFGEM has a right to require the data is removed should this data interfere with business activity or use.
You must ensure activities do not damage the reputation of OFGEM, its employees and citizens including accessing, storing, transmitting or distributing links to material that could embarrass or compromise OFGEM, is obtained in violation of copyright, can be considered harassment, or is offensive, indecent or obscene.
You must follow the Civil Service Code and must not use OFGEM systems to: trade or canvass support for any organisation; send messages promoting religious, political or other non-business causes; use applications to circumvent security controls; or download software except where permitted from an official source.
Only use appropriate language in messages, emails, faxes and recordings. Threatening, derogatory, abusive, indecent, obscene, racist, sexist or otherwise offensive content is a disciplinary matter.
Do not materially alter or change the meaning of a third party's message when forwarding it unless authorised. Be vigilant to phishing emails and know how to spot them and, if in doubt, report suspicious emails.
Internal emails are potentially disclosable under the Freedom of Information Act 2000, the Environmental Information Regulations 2004, and subject access requests under the GDPR. Care should be taken in how emails are set out to not cause embarrassment to Ofgem or give rise to an allegation of libel.
Only use your OFGEM email address to register or create accounts for OFGEM business related activities and linked organisational activity (e.g. OFGEM discount schemes, CSL, Civil Service Jobs).
When logging onto external websites for personal use (e.g. for retail or internet banking purposes), OFGEM staff must use their personal email addresses.
Only access appropriate content using OFGEM technology and not intentionally visit sites or news groups that are obscene, indecent or advocate illegal activity.
Report any access to a site that should be blocked to their line manager or the IT Service Desk.
Contact the IT Service Desk with requests to unblock a website and do not attempt to bypass OFGEM web filters.
Use social media appropriately by making themselves aware of the Social Media Guidance. Do not put OFGEM information including anything that is sensitive or personal onto online forums, blogs or social networking sites unless authorised to do so.
Be aware that their social media content may be available for anyone to see, indexed by Google and archived for posterity.
Only use systems, applications, software and devices which are approved, procured and configuration managed by OFGEM when undertaking official business, and apply OFGEM standards and guidance in their use.
Only use approved OFGEM devices connected to OFGEM network(s). Do not use your personal email accounts to process Ofgem business information.
OFGEM permits connecting OFGEM devices by WiFi or Ethernet to the internet. Only connect your Ofgem device to Captive Portals provided by reputable organisations such as train operators, airlines and major hotel or coffee shop chains.
In some exceptional circumstances, it may be necessary for staff to use personal email accounts or personal devices to process OFGEM information. These circumstances are limited to: business continuity incidents where normal business systems are unavailable, or a pressing business requirement cleared by a line manager.
Ensure no official information is stored on devices without OFGEM security controls, unless explicitly allowed in exceptional circumstances.
Raise all software requests through the IT Service Desk.
OFGEM employees and contractors travelling outside the UK and wishing to take OFGEM devices may do so. However, the following countries are considered high threat and devices must not be taken to these:
Be responsible for keeping all portable devices assigned to them safe and secure and immediately report any loss or damage of their equipment to their line manager.
Protect OFGEM equipment appropriately when travelling. Laptops must always be carried as hand luggage.
Never leave a portable device in sight in parked vehicles. Return all OFGEM equipment when leaving OFGEM. Line Managers must complete all appropriate exit procedures with leavers.
If for any reason users are unable to comply with this policy or require use of technology which is outside its scope, this should be discussed with their line manager in the first instance and then the IT Service Desk who can provide advice on escalation/exception routes.
All requests to use new software not currently approved by OFGEM must be subject to approval through the IT Service Desk.
Line managers are responsible for ensuring that users understand their responsibilities and consequences as defined in this policy and continue to meet its requirements for the duration of their employment with OFGEM.
All instances of non-compliance should be reported as potential Data Breaches. Where there are instances of deliberate non-compliance, disciplinary action may be considered in line with Ofgem procedures.
Instances of accidental non-compliance will be investigated and may, where appropriate, be considered under relevant disciplinary procedures.
When line managers are considering disciplinary action in relation to these matters, they should always consult with their HR Business Partner.