Educause Security Discussion mailing list archives

Re: Security/Privacy Awareness click through


From: Harry Hoffman <hhoffman () IP-SOLUTIONS NET>
Date: Mon, 11 Mar 2013 17:26:27 -0400

The obvious, IANAL statement first.

Can you really hold your users "legally" liable for activity under their
name/identity?

I was unaware of anyone actually doing this. Most, that I know of link
the userid/person for the purpose of enforcing AUPs, which I thought was
a bit different then a legally binding contract.

Cheers,
Harry

On 03/11/2013 05:06 PM, Jacobson, Dick wrote:
I sent this to the Policy  Discussion list last week  and received only one reply.  Any more examples are appreciated.


For several years we have had an awareness "quiz" in place that individuals needed to complete before gaining access 
to our IT services.  I have been asked to come up with verbiage that would accompany a click-through that would still 
allow us to hold our users legally responsible for IT activity under their name/identity.  There appears to be a big 
rush on this so I am asking what some of you use at your institutions.



Thanks in advance for your help






Current thread: