2026 - 2027 Student Handbook

Computer and Information Systems Policy

Purpose and Scope

Baptist University of Florida is a multi-campus, residential, and online Christian university. In this policy, “University” refers collectively to Baptist University of Florida (BUF) in Graceville, Florida; BUF Global in Orlando and Miami, Florida; the University’s online and remote programs and services; and other authorized University operations.

The University provides information and technology resources to support teaching, learning, library services, residential life, administration, ministry, communication, research, and University operations. These resources must be used securely, ethically, responsibly, and lawfully in a manner consistent with integrity, stewardship, respect, accountability, and the Christian mission of the University.

This policy applies to all students who access or use University information or technology resources, including students attending at University locations, residential students, and students participating through online or remote programs. Employees, vendors, contractors, visitors, and other users are governed by the University-wide Information Technology, Cybersecurity, and Acceptable Use Policy and other applicable requirements. Covered resources include University accounts, information, computers, mobile devices, networks, wireless systems, email, applications, databases, cloud and hosted services, library technology, shared computers, audiovisual systems, and personally owned devices used to access University resources.

Accounts, Authentication, Access, and Student Identity

Access to University systems is provided only for authorized academic, employment, administrative, ministry, service, research, residential, library, or contractual purposes. Access may be limited, changed, suspended, or removed when responsibilities change, access is no longer needed, security risk increases, or misuse is suspected.

  • Users must use their own authorized accounts and may not share passwords, passphrases, authentication codes, recovery codes, security keys, or approval prompts.
  • Multifactor authentication (MFA) is required for designated systems. Users must not approve an MFA request they did not initiate and must promptly report unexpected prompts.
  • Users must protect credentials, provide accurate account-recovery information, and follow current password, identity-verification, and account-security requirements.
  • Users may access only information and systems needed for a legitimate academic, business, legal, or contractual purpose. Technical access alone does not create authorization.

The University verifies that the student who registers for a course or program is the same student who participates, completes the academic work, and receives the associated credit or credential. Verification ordinarily uses a unique University account and secure credentials and may also include MFA, proctored examinations, presentation of identification, video or in-person verification, secure assessment tools, or other reasonable methods. Students may not share accounts, allow another person to participate or submit work under their identity, or act under another student’s identity.

Student identity-verification processes will be administered in a manner intended to protect privacy. Education records and personally identifiable student information will be handled in accordance with the Family Educational Rights and Privacy Act (FERPA), applicable law, and University policy. Any projected additional charge specifically associated with student identity verification in an online, distance, or correspondence course or program will be disclosed in writing at registration or enrollment.

Protection and Handling of University Information

University information must be protected according to its sensitivity, legal and contractual requirements, operational importance, and the harm that could result from unauthorized access, disclosure, alteration, loss, or destruction. Sensitive information includes student education records, applicant and employee information, financial-aid and financial information, health or accommodation information, Social Security numbers, payment information, passwords, authentication secrets, and security configurations.

  • Users must access only the information needed for authorized responsibilities and verify recipients before sharing information.
  • University records must be stored and shared through approved systems. Sensitive University information may not be placed in personal email, personal cloud storage, unapproved applications, public or unapproved artificial intelligence systems, or other unauthorized locations.
  • Important University records must not exist only on a local device, removable drive, or personal service. Users must follow retention, legal-hold, backup, and secure-disposal instructions.

This policy does not determine ownership of faculty scholarship, student work, course materials, research, intellectual property, or third-party content. Ownership is governed by applicable law, agreements, and other University policies.

Devices, Software, Networks, and Remote Access

Devices used to access University systems must be reasonably secure, supported, and appropriate for the information being handled. University-owned technology may be inventoried, configured, updated, monitored, protected, repaired, backed up, restored, isolated, restricted, or remotely secured by authorized Information Technology personnel when reasonably necessary.

  • Required updates, endpoint protection, screen locks, encryption, firewalls, filtering, device-management software, and other safeguards must remain enabled and current.
  • Users may not disable, remove, bypass, or interfere with University security, monitoring, filtering, backup, encryption, endpoint-management, or compliance controls.
  • Only authorized and properly licensed software, applications, browser extensions, devices, cloud services, and integrations may be used for University business or University information.
  • The University may restrict a personally owned device’s access to University systems when the device creates a security or operational risk. When University-approved device-management tools are used, the University may remove University-managed accounts or University information when access ends or security requires it. The University will not intentionally erase unrelated personal content.
  • Remote access must use approved methods and required MFA. Users must protect devices and information when learning or working from home, traveling, or using public networks.
  • Unauthorized routers, wireless access points, switches, bridges, extenders, servers, or network-monitoring equipment may not be connected to University networks. Server rooms, network closets, telecommunications spaces, and other restricted technology areas may be entered only by authorized personnel.

Residential, Library, Shared, and Guest Technology Use

Students living in University housing may use University-provided networks for legitimate academic, personal, communication, and recreational purposes, subject to this policy, housing requirements, copyright law, and reasonable security and performance limits. Devices that create a security risk, interfere with network performance, consume unreasonable resources, or disrupt service may be restricted, isolated, or disconnected.

Computers, printers, scanners, wireless services, databases, and other technology provided through University libraries or shared facilities must be used according to applicable rules, license agreements, and access restrictions. Users of shared computers must sign out when finished, must not save credentials or sensitive information on the device, and may not install software or change configurations without authorization.

Guest and visitor access is a privilege and may be limited, monitored, suspended, or withdrawn. University credentials may not be shared with guests or visitors.

Email, Communications, Cloud Services, Vendors, and Artificial Intelligence

University accounts and approved systems should be used for official University business. Users must exercise care when sending messages, sharing files, creating collaboration links, hosting online meetings, or communicating with external recipients.

  • Unexpected requests involving money, banking information, gift cards, credentials, records, account changes, or other sensitive actions must be independently verified through a trusted method.
  • Suspected phishing, impersonation, malicious links or attachments, and unauthorized account activity must be reported promptly. Users may not intentionally bypass email-security or filtering controls.
  • Automatic forwarding of University email to personal accounts, misleading sender identities, unauthorized bulk messaging, and transmission of sensitive information through unapproved methods are prohibited.
  • New software, cloud services, integrations, and vendor systems used for University business or information require appropriate University review and approval. Vendor access must be authorized, limited, and removed when no longer needed.
  • Sensitive University information may not be entered into public or unapproved AI systems. AI-generated material must be reviewed for accuracy, privacy, bias, copyright, and appropriateness. Academic use of AI remains subject to faculty direction and academic-integrity requirements.
When expressing personal views through a University account or service, users must not imply University endorsement or authority unless authorized to speak on the University’s behalf.

Monitoring Privacy and Security Incident Reporting

The University respects appropriate privacy while retaining responsibility to operate, secure, maintain, support, investigate, and comply with legal obligations involving University systems. Users should not expect activity conducted through University systems, University networks, or University-owned devices to be completely private.

Authorized personnel may access, review, preserve, disclose, or monitor accounts, devices, communications, files, logs, network traffic, and system activity when reasonably necessary for cybersecurity, system administration, support, fraud prevention, backup, recovery, continuity, records management, audit, legal compliance, authorized investigations, or protection of people, property, and University operations. Access and monitoring must be limited to legitimate University purposes and information must be shared only with persons who have a legitimate need to know.

Actual or suspected security incidents must be reported promptly to helpdesk@buf.edu or through another method published by the Information Technology Department. Report unexpected MFA prompts, suspected password theft, phishing, malware, unauthorized access, accidental disclosure, lost or stolen devices containing University information, outages, equipment damage, and unusual conditions affecting campus infrastructure. Users must preserve relevant information and cooperate with authorized responders.

The University may immediately reset credentials, revoke sessions, disable accounts, isolate devices, block traffic, preserve records, restrict access, or temporarily interrupt services when reasonably necessary to protect people, information, evidence, systems, or University operations.

Acceptable Use and Prohibited Conduct

University technology resources are primarily provided for authorized University purposes. Reasonable personal and recreational use is permitted when it does not interfere with responsibilities or operations, create material cost or risk, consume excessive resources, expose University information, violate law or policy, or involve unauthorized commercial activity.

Users may not use University information or technology resources to:

  • Access, alter, disclose, copy, intercept, monitor, capture, or destroy information or systems without authorization.
  • Share accounts, impersonate another person, forge communications, misrepresent authority, commit fraud, or conceal identity for an improper purpose.
  • Create, introduce, distribute, or assist malware; disrupt systems or networks; evade safeguards; or interfere with another person’s access, academic work, or responsibilities.
  • Perform vulnerability scanning, penetration testing, packet capture, network discovery, password testing, port scanning, or similar security activity without written authorization from the Director of Information Technology or an authorized designee.
  • Evade authorized charges, licensing restrictions, quotas, access limits, or other controls.
  • Harass, threaten, discriminate, exploit, stalk, defame, abuse, or distribute unlawful, obscene, pornographic, sexually exploitative, or otherwise prohibited material, except when specifically authorized for a legitimate academic, legal, security, or administrative purpose.
  • Infringe copyright, software licenses, intellectual-property rights, privacy rights, library-resource terms, contractual restrictions, or applicable export-control requirements.
  • Send spam, chain letters, pyramid schemes, unauthorized mass messages, or repeated unwanted communications.
  • Use University technology for unauthorized commercial activity, private business, unauthorized fundraising, gambling, cryptomining, or partisan political campaign activity conducted on behalf of the University without authorization. This provision does not prohibit lawful personal expression that complies with other University policies and does not imply University endorsement.
  • Remove, move, damage, tamper with, or obstruct University-owned computer, network, audiovisual, communications, or security equipment without authorization.
  • Use technology in a manner inconsistent with the University’s Christian mission, applicable handbooks, academic-integrity requirements, student conduct standards, or law.

Copyright, Illegal File Sharing, and Peer-to-Peer Activity

Students must comply with copyright law, software and database licenses, library-resource terms, course-material restrictions, and the intellectual-property rights of others. Unauthorized downloading, uploading, copying, streaming, sharing, reproduction, or distribution of copyrighted material is prohibited. This includes unauthorized peer-to-peer file sharing and using University technology to make copyrighted material available to others without permission or other lawful authority.

Violations may result in loss of technology or network privileges, University disciplinary action, and civil or criminal liability. Under federal law, civil statutory damages generally range from $750 to $30,000 for each work infringed and may reach $150,000 for each work when infringement is willful. Criminal penalties may include fines and imprisonment. Federal law controls, and the consequences applicable to a particular matter depend on the facts and law in effect at the time.

The University will maintain measures required by applicable law to address unauthorized distribution of copyrighted material and will make information about University copyright policies, sanctions, federal penalties, and lawful alternatives available to students. Lawful alternatives may include University-licensed library databases, authorized stores and subscription services, open educational resources, Creative Commons materials used according to their licenses, public-domain works, and works used with permission. Enrolled students will receive required copyright information and notices at least annually.

Student Violations, Protective Actions, and Sanctions

Suspected student violations may be referred to the Provost or an authorized designee and may be handled as an academic, student-conduct, housing, or other disciplinary matter. Information Technology may take immediate technical action before a disciplinary determination when reasonably necessary to protect people, information, evidence, systems, networks, or University operations. Final disciplinary decisions will be made through the applicable University process.

Depending on the circumstances, actions or sanctions may include:

  • Credential resets, session revocation, temporary account suspension, device isolation, access restrictions, or preservation of relevant records and evidence.
  • A warning, educational conference, required cybersecurity or copyright training, or other corrective instruction.
  • Restitution, replacement, repair, or reimbursement for loss, damage, unauthorized charges, or recovery costs when permitted by University policy and law.
  • Temporary or permanent restriction, suspension, or revocation of technology, network, residence-hall network, library, device, or account privileges.
  • Academic consequences when conduct involves identity misrepresentation, unauthorized assistance, academic dishonesty, or interference with an academic activity.
  • Student-conduct sanctions, including probation, suspension, dismissal, or other sanctions authorized by the Student Handbook.
  • Referral to legal counsel, law enforcement, a service provider, a rights holder, or another appropriate authority when required or warranted, subject to FERPA and other applicable privacy requirements.

Sanctions are not required to follow a particular sequence and may be combined according to the nature, intent, impact, prior conduct, cooperation, and risk involved. University action does not prevent separate civil or criminal liability.

Online Services and Privacy

Students using University websites, applications, and third-party services are subject to the applicable University privacy notices and service terms. Student education records are handled in accordance with FERPA and University policy. Questions concerning student education records should be directed to the Office of the Registrar, and suspected technology-security issues should be reported to helpdesk@buf.edu.

Distribution, Acknowledgment, and Administration

The University will publish and distribute this policy through appropriate University media. Students are responsible for complying with this policy, applicable handbooks, housing and library rules, academic-integrity requirements, and other requirements applicable to their access. The University may require electronic or written acknowledgment and appropriate security or privacy training.

The Director of Information Technology, or an authorized designee, administers this policy and may issue supporting standards, procedures, technical requirements, and user guidance. Exceptions must be documented, supported by a legitimate academic or business need, reviewed for risk, limited in scope and duration, and approved by the Director of Information Technology together with the appropriate University authority or data owner.

The University may revise this policy through its established review and approval processes when legal, accreditation, operational, campus, technology, or cybersecurity requirements change. Material changes will be communicated through appropriate University channels. The most current formally approved and published version controls. This policy should be reviewed at least annually and after significant changes.