


TABLE OF CONTENTS
| S. No. | Particulars | Page |
|---|---|---|
| 1 | Cover Page | 1 |
| 2 | Table of Contents | 2 |
| 3 | INFORMATION TECHNOLOGY POLICY | 3 |
| 4 | 1.1 IT Resources | 4 |
| 5 | 2.4 Network (Inter and Intra) Access policy | 5 |
| 6 | 2.2.5 Network Cable Connection: | 6 |
| 7 | 2.3.2 Data Loss Prevention: | 7 |
| 8 | 2.4.1 Internet via Wi-Fi: | 8 |
| 9 | 2.5. Email Account and usage policy | 9 |
| 10 | Policy Content | 10 |
| 11 | 2.6.2 Cyber Data: | 11 |
| 12 | 2.6.5 Prohibited Uses of Systems and Services | 12 |
| 13 | 2.6.5.8 Obtaining or attempting to obtain service by any means or device with intent | 13 |
| 14 | 3.2 Guidelines for CMC Engineers & Technicians: | 14 |
| 15 | 3.2.6 IT Policy Violation Incident: | 15 |
| 16 | Review and Approval | — |

INFORMATION TECHNOLOGY POLICY
1. Essential of IT Policy
IT policy establishes Organization-wide approaches and responsibilities for protecting the Confidentiality, Integrity, and Availability of the information assets that are accessed, created, managed, and/or controlled by the Institution in a legal way. This policy includes Data, Computers, Information system, Network Devices, Intellectual properties and other computing and communication devices. It also includes documents and orally communicated information on the Campus This policy establishes Organization-wide strategies and responsibilities for protecting the Confidentiality, Integrity, and Availability of the information assets that are accessed, created, managed, and/or controlled by the VTHT assets addressed by the policy include data, information systems, computers, network devices, intellectual property, as well as documents and verbally communicated information Intranet & Internet services have become most important resources in educational institutions & research organizations. Realizing the importance of these services, VTHT took initiative way back in 2015 and established basic network infrastructure in the campus. Over the last ten years, not only active users of the network facilities have increased many folds but also the web-based applications have increased. This is a welcome change in the Campus academic environment. Now, VTHT has about 1100 network connections covering more than 10 Blocks across the campus. Computer Maintenance Cell (CMC) is the department that has been given the responsibility of running the intranet& Internet services. CMC is running the Firewall security, Proxy, DHCP, DNS, web and application servers and managing the network of the campus. VTHT is getting its Internet bandwidth from Jio. Total bandwidth availability from ISP is 1000 Mbps (leased line) with redundant link. While educational institutions provide Internet access to their faculty, students and staff, they face certain constraints:
- Limited Internet bandwidth
- Limited infrastructure like computers, computer laboratories and Digital Libraries
- Limited financial resources in which faculty, students and staff should be provided with the network facilities and
- Limited technical manpower needed for network management.

Uncontrolled, uninterrupted and free web access can give rise to activities that are neither related to Teaching/learning processes nor governance of the organization. At the outset, we need to recognize the problems related to uncontrolled surfing by the users:
- Prolonged or intermittent surfing, affecting quality of work
- Heavy downloads that lead to choking of available bandwidth
- Exposure to legal liability and cases of sexual harassment due to harmful and embarrassing content.
- Confidential information being made public.
In order to secure the network, CMC has been taking appropriate steps by Installing firewalls, access controlling and installing virus checking and content filtering software at the gateway. However, in the absence of clearly defined IT policies, it is extremely difficult to convince users about the steps that are taken for managing the network. Users tend to feel that such restrictions are unwarranted, unjustified, and infringing the freedom of users. Without strong management policies, IT security measures will not be effective and not necessarily align with management objectives and desires. Hence, policies and guidelines form the foundation of the Institution’s security program. Effective policies are a sign of due diligence, often necessary in the event of an IT audit or litigation. Policies also serve as blueprints that help the institution implement security measures. An effective security policy is as necessary to a good information security program as a solid foundation to the building; hence VTHT proposes to have its own IT Policy that works as guidelines for using the Organization’s computing and communication facilities
1.1 IT Resources
This policy is applicable for the following categories’ infrastructure and other relevant IT resources
- Desktop / Server / Computing Facilities
- Network Devices and other IT and Network Communication equipment
- Internet facilities
- Email Facility in the Campus
- Institute Website / Web applications
- Network Security
- Reprographic Facilities (Printing/ Photocopying Facility)
- Biometric Devices
1.2 Stake holders – on Campus/ off campus
Students: Current UG,PG Students and Research scholars Employees: Permanent/Temporary/Contract Employees Faculty Members: All Teaching Faculty Staff Members: Administrative/ Accounting /Technical/ non-technical Higher Authorities and Officers: Principal /Deans /COE/ HOD’s Guests: Visiting Professors / Alumni / other Persons visit to the Institution
2. IT Policy Categories
The IT Policy may be classified in the following Categories:
2.1 Infrastructure Equipment / Device purchase
2.2 Hardware Assembling and infrastructure establishments
2.3 Software Installation and Licensing

2.4 Network (Inter and Intra) Access policy
2.5 Email Account and usage policy
2.6 Website policy
2.7 Electronic Surveillance Policy
2.8 Institution Database usage policy
2.9 Biometric Device Access
2.1. Infrastructure Equipment / Device purchase:
Any IT equipment (henceforth it may be mentioned as CMC equipment) purchase will be through getting minimum three different quotations with registered/trusted suppliers of VTHT and the same will be evaluated by CPC (Central Purchase Committee) Members along with concern Department/Division Internal Experts, all / top 3 suppliers will be called for CPC Meeting for Face to face interaction and Discussion about Terms and Conditions, then the CPC Committee will finalise a Supplier for Purchase Order request to the Purchase Department.
2.1.1 Supply of Goods:
All the Materials supplied by the Supplier should meet the standard best in class as well as per purchase Order and the same will be verified by Quantity Checking and Quality Checking. In case of non-tangible asset / service purchase/render, License key/ Account ID/ Connected Official Email ID along with warranty Certificate /Agreement will be received through online as well as document as per Indian Government Law. The same purchase should be updated to CMC with purchase and license details to the central Software registry before the purchase bill closing as per internal procedures
2.2. Hardware Assembling and infrastructure establishments
2.2.1 Individual Component:
Computer Maintenance Cell will receive the Hardware after Quantity Checking and will be assembled/deployed to the User area/place except Research Equipment. In case of complex assembly of hardware equipment, vendor/supplier support may be utilised.
2.2.2 User Space:
2.2.2.1 Student Space -Computer Labs, Language Labs, Research Labs, Class Rooms
2.2.2.2 Higher officials Space–Office of the Principal, Dean and HoD
2.2.2.3 Common Space: Library, Staff cabin, Purchase, Maintenance, Placement
Training, Knowledge Resource Centre, Seminar Hall, Club offices, Sports offices, NCC, Security, Accounts, warden Office, canteen and all Wi-Fi space
2.2.3 Warranty and Maintenance:
Computer Systems purchased for User space are preferably purchased with 3 Years standard onsite warranty. Post warranty period minor services/replacement of spares should be taken care by the concern department for Student space. CMC should attend all kind of service /spares replacement for Higher official’s space and common space (it includes all Wi-Fi coverage area, Projector and Surveillance equipment) All the computers should be properly shut down before the electrical switch is switched off. Users and other persons not related to maintenance should not switch ON/OFF MCB (Miniature Circuit Breaker) unless emergency.
2.2.4 Power Supply to Computers:

All Computers should be connected with Electrical Point strictly through online UPS System and Power supply to UPS should not be disconnected without prior notice to maintain the battery charged and the UPS should be properly connected with earth as per the manufacturer’s recommendations. UPS power supply to the computers should not be shared with other Electrical and Electronic equipment
2.2.5 Network Cable Connection:
All copper Network cables from network equipment to end devices should be properly shielded with Pipe/Trench and kept away at least 15cm from Electrical wire/devices. All cable terminals should be properly terminated with labels/numbers for identification purpose All Backbone cables may be equipped with Fiber or atleast 1000 BASE-T (Gigabyte Ethernet) as per ITU-Ethernet standard. In case of a very few users in a remote building, wireless point to point devices(Network Bridge) may be used as backbone.
2.2.6 File and Print Sharing:
File and print sharing facilities on the computer over the network should be installed only when it is absolutely required. When files are shared through network, they should be protected with password and with read only access rule.
2.2.7 Shifting Computer from One Location to another:
Computer system may be moved from one location to another with prior written intimation to the office of the registrar, as office of the registrar maintains a record of computer Asset Number. Such Asset Number follows the convention that it comprises building name abbreviation and room No. As and when any deviation (from the list maintained by office of the registrar) is found in any computer system, network connection would be disabled and the same will be informed to the user by email/phone, if the user is identified. When the end user meets the compliance and informs CMC through proper channel in writing/by email, connection will be restored.
2.2.8 Noncompliance:
VTHT faculty, staff, and students not complying with this computer hardware installation policy may leave themselves and others at risk of network related problems which could result in damaged or lost files, inoperable computer resulting in loss of productivity. An individual's noncompliant computer can have significant, adverse effects on other individuals, groups, departments, or even the whole Institution. Hence it is critical to bring all computers into compliance as soon as they are recognized not to be.
2.3. Software Installation and Licensing Policy
With respect to anti-piracy laws of the country, Institution IT policy does not allow any pirated/unauthorized or modified software installation on the Institution owned computers and the computers connected to the Institution campus network. In case of any such instances, Institution will hold the department/individual personally responsible for any pirated software installed on the computers located in their department/individual’s room
2.3.1 Operating System and its Updating

Institution IT Policy encourages to use Open source operating systems such as Ubuntu, Fedora and software like Open office, Libre office, Sumatra pdf, 7zip Individual Users(officials) and respective Lab incharges wherever Microsoft Windows (7/8/10) operating system used had better ensure the operating system is up to date. That will ensure the bug free, vulnerability less system for smooth Learning and working experience. It is recommended to Concern officials confirm the license availability with CMC for installation other than open source/freeware.
2.3.2 Data Loss Prevention:
All official computers are installed with at least 2 hard disk partition. Mostly 1st partition is used for operating system and 2nd partition is for data storage. So even Operating system corrupted your data may be safe. However, there is no assurance for full data loss, hence users are advised to take copy of their data in to their pen drive/external Hard disk or cloud back up. The Institution cannot be responsible for the loss of the users’ data by Virus/other threads or hardware failure.
2.4. Network (Internet and Intranet) Access policy

As per UGC guidelines Internet leased line should be subscribed from ISP directly or through Authorised partners with failover backbone / additional subscription. Institution Local Area Network is divided into multiple Subnets for easy maintenance and better performance of the network with three tier architecture All users will be provided with Internet login credentials to access the internet through Institution network (both wired and Wireless). All Wired computers/Servers connected with Institutional network should be assigned with individual IP address by CMC. An IP address assigned for a particular computer system should not be used on any other computer even if the other computer belongs to the same individual and will be connected to the same port. IP addresses are given to the computers but not to the ports. IP address for each computer should be obtained separately from CMC. Trying and accessing remote desktop inside and outside from Institutional network is not advised unless there is official necessity. Use of any computer at end user location as a DHCP server to connect to more computers/communication devices through an individual switch/hub/wifi router and distributing IP addresses (public or private) should strictly be avoided, as it is considered absolute violation of IP address allocation policy of the organization. Similarly, configuration of proxy servers should also be avoided, as it may interfere with The service run by Institution or Authorised service provider. Even configuration of any computer with additional network interface card and connecting another computer to it is considered as proxy/DHCP configuration. Non-compliance to the IP address allocation policy will result in disconnecting the port From which such computer is connected to the network. Connection will be restored after Receiving written assurance of compliance from the concerned department/user. Accessing private Proxy tunnels, pirated videos and unlawful contents/ websites through Institution network is fully prohibited. In case if found, suitable action will be taken through higher officials, in extreme conditions details will be handed over to law enforcement agency as per IPC Act 2000.
2.4.1 Internet via Wi-Fi:
Stakeholders of this institution are allowed to use internet via their own Laptops with Pre shared credentials through institutions DHCP server. On special reasons internet may be provided without credential by MAC Address Binding with institutional server/ service provider server.
2.4.2 Network Device Access Policy:
Authorised CMC personal can access Network Switch/Rack fiber terminals for configuration maintenance purpose. Even though the Individual users have knowledge of the network communication, they are not advised to repair the same in order to maintain the configurations and logs
2.4.3 Logs

Log of each Inter network access record should be maintained at the server side at least for 3 months, if it is outsourcing the service provider should maintain the same.
2.5. Email Account and usage policy
Email is an official means for communication within this institute. Therefore, the Organization has the right to send communications to faculty, staff and students via email and the right to expect that those communications will be received and read in a timely fashion. You can access the email from on/off campus. Each student and faculty member may be assigned with at least one official email id; they can redirect the email to other email ID. All email access policy shall be under the Information Technology Act, 2000 While leaving the organization official users are advised to do the necessary backup / download of your data and further claims may not be accepted for losing of email service/data.
2.6. Website policy
2.6.1 Server Policies & Procedures:

The following is a list of software and configurations that we have installed to secure, optimize our server. The following software is not resource intensive We've configured server scanning tool to find most types of exploits (backdoors, suspicious files, md5 hash comparisons, and is over 99% accurate in detecting such exploits. We've scanned your system reported that your system is clean. CSF Firewall is installed and configured only to allow traffic on the ports that are used by the standard cpanel configuration. LFD comes with CSF and is a brute force detection utility to block any IP Addresses of users that fail authentication too many times. IMPORTANT: If you are using any non-standard ports, please let us know so that we can open them System Configuration File host.conf has been secured to prevent DNS lookup poisoning. It also provides protection against spoofs System Configuration File nsswitch.conf has been secured . We have also optimized it to perform DNS lookups more efficiently. System Configuration File sysctl.conf has been secured to help prevent the TCP/IP stack from syn-flood attacks. It is also configured to prevent other various and similar network abuse. /tmp and /var/tmp have been secured to prevent the execution of malicious scripts Custom server configuration added to monitor the mysql activity realtime SPRI has been installed now. This program changes the priority of different processes in accordance to their level of importance. You should see at least a 5-20% decrease in the average load level of your server on average unused programs which have been disabled from the OS of the server. This reduces the chance of being compromised through software exploits on old or deprecated programs. Telnet has been disabled to prevent insecure transmissions of data and passwords, and SSH must be used instead of Telnet, and it should function the same way. SSH has been hardened by restricting the SSH Protocol to SSH 2, and changing port to a non-standard one. To help prevent outgoing spam, we recommend lowering the hourly mail limit for all accounts and disabling the unauthenticated mail functions such as form mail php mail scripts, this would require any scripts that send mail to use SMTP authentication with an email username/password. This is much more secure and increases the mail deliverability/ acceptance rates, but it will block any scripts that send mail the old fashion way with send mail. If you would like this done, please let us know. ConfigServer Explorer has been installed into WHM with root level permissions. This allows system root files to be edited in an emergency situation when SSH is not accessible. !!IMPORTANT!! This simulates SSH access, treat it as such, do not use it unless you are familiar with SSH. Moreover, do not execute any commands you are not fluent with. As with SSH, damage can be done if this program is not used properly. If you are unfamiliar with SSH, do NOT use this program. It should be left in case of such an emergency. Again, this file can only be accessed through WHM while being logged in as root. Your FTP server software has been updated and tweaked to increase the security of FTP connections to the server.

2.6.2 Cyber Data:
2.6.2.1 system will be hacker proof Can we guarantee your system will be hacker proof?No, NOBODY can! It is 100% impossible to make a server hacker proof, that's a fact. This is even more impossible when vulnerable freeware scripts are so commonly used (forums, bb's, guestbooks, formmails). Nevertheless, even multibillion dollar company's such as banks, government computers, credit card companies, have had server's compromised. We consider our security hardening procedures to make your system hacker resistant. The software we install secures the system without adversely effecting or hindering the normal operations of your server. Please note that over 99% of hacks come from insecure php scripts. These insecurities in php scripts come from the programming code, and therefore there is absolutely no way search to find "all" insecure scripts. Remote based hacks are extremely rare. If there is no weak passwords, and no insecure php scripts, you have a very rare chance of ever being hacked. So as long as you and your users keep all of your scripts up to date, and remove any unused scripts and remove any insecure scripts, then the chances of being hacked through the most common method is greatly reduced. If you feel your users do not know how to check or are not responsible enough to keep their scripts secure, we can harden php further by disabling functions that are commonly used in exploits, but please note that since the same functions are also used legitimately so disabling them will also interfere with a lot of scripts that require them. If you would like this done.
2.6.2.2 Support Data:
In order to provide the Services to you, We may collect information from you including but not limited to: (a) IP addresses, usernames and passwords necessary to login to SSH, WebHost Manager and the Server’s root directory; (b) The usernames and passwords necessary to login into any affected accounts including email accounts, cPanel accounts, MySQL accounts and other accounts (c) Other information that you voluntarily supply or that we requests in order to resolve your Incident .
2.6.3 Security:
The security of your Personal Information is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. We also recommend making backups on a regular basis when backups are finished, they must be manually reviewed and checked on a regular basis to ensure they are up to date and working properly
2.6.4 Acceptable use policy

This Acceptable Use Policy document, including the following list of Prohibited Activities, is an integral part of your Hosting Agreement with us. If you engage in any of the activities prohibited by this AUP document, wereserve the right suspend or terminate your account. Our Acceptable Use Policy (the “Policy”) for our Services is designed to help protect us, our customers, and the Internet community in general from irresponsible or, in some cases, illegal activities. The Policy is a nonexclusive list of the actions prohibited by us.
2.6.5 Prohibited Uses of Systems and Services
2.6.5.1 Transmission, distribution or storage of any material in violation of any
applicable law or regulation is prohibited. This includes, without limitation, material protected by copyright, trademark, trade secret or other intellectual property right used without proper authorisation, and material that is obscene, defamatory, constitutes an illegal threat, or violates export control laws.
2.6.5.2 Unacceptable practices include but are not limited to
• Drug dealing • Piracy/Pirating • Violation of copyright law • Illegal gambling/Lottery sites • Illegal arms trafficking • Stalking or violating state or federal law. • Attempting without authorization to access a computer system • Threatening bodily harm or damage to individuals or groups • Interfere with or disrupt the Services or servers or networks connected to the Services, or disobey any requirements, procedures, policies or regulations of networks connected to the Service
2.6.5.3 Sending Unsolicited Bulk Email (“UBE”, “spam”). The sending of any form
of Unsolicited Bulk Email through our servers is prohibited. Likewise, the sending of UBE from another service provider advertising a web site, email address or utilizing any resource hosted on our servers, is prohibited. our accounts or services may not be used to solicit customers from, or collect replies to, messages sent from another Internet Service Provider where those messages violate this Policy or that of the other provider. ANY form of spamming activity (e.g. mail spam, Usenet spam, pop- up spam, selling/buying spamware, and so on) conducted ANYWHERE on the Internet
2.6.5.4 Advertising, transmitting, or otherwise making available any software,
program, product, or service that is designed to violate this AUP or the AUP of any other Internet Service Provider, which includes, but is not limited to, the facilitation of the means to send
2.6.5.5 Unsolicited Bulk Email, initiation of pinging, flooding, mail-bombing,
denial of service attacks.
2.6.5.6 Operating an account on behalf of, or in connection with, or reselling any
service to, persons or firms listed in the Spamhaus Register of Known Spam Operations (ROKSO) database at www.spamhaus.org/rokso.
2.6.5.7 Unauthorized attempts by a user to gain access to any account or computer

resource not belonging to that user (e.g., “cracking”). our reserves the right to report illegal activities to any and all regulatory, administrative, and/or governmental authorities for prosecution.
2.6.5.8 Obtaining or attempting to obtain service by any means or device with intent
to avoid payment.
2.6.5.9 Unauthorized access, alteration, destruction, or any attempt thereof, of any
information of any our customers or end-users by any means or device.
2.6.5.10 Knowingly engage in any activities designed to harass, or that will cause a
denial-of service (e.g., synchronized number sequence attacks) to any other user whether on our network or on another provider’s network.
2.7 Electronic Surveillance System
Institution owned Closed Circuit Television (CCTV) may be installed in all common area of the Institution and its Hostel Premises for additional monitoring purpose. No claim in any aspect based on CCTV is acceptable.
2.8. Institution Database Usage Policy
Data collected through the above may be used/shared to Government / trusted 3rd party service providers (eg.: bankers for fee update) on essentials. However, online payment credentials, debit/credit card details will not be saved and shared by the institution. This Policy relates to the databases maintained by the Institution administration under The Institution eGovernance. Data is a vital and important institution resource for providing useful information. Its use must be protected even when the data may not be confidential 2. 8.1 Database Ownership: VTHT is the data owner of all the data generated in the institution 2. 8.2 Custodians of Data: Individual Sections or departments generate portions of data that constitute institution’s database. They may have custodianship responsibilities for portions of that data. 2. 8.3 Data Administrators: Data administration activities outlined may be delegated to some of the Officials in that department by the data Custodian This may be monitored by the head of the institution.
2.9 Biometric Device Access
The Institution has set up Biometric Devices for Attendance and (or) Access Purpose in the Institution and other related premises, and all Employees and Staff should enrol their Biometric Identity with the Institution and the same will not be shared with any other party except Government Agencies in case of any specific official requirement. Any persons with Disability, wounds or any communicable disease can use biometric device only with Prior permission from higher officials The Institution has the rights to remove Biometric Identity from device at any time without prior Notice. The institution cannot be held responsible if any person’s Biometric attendance data is not updated / received in the machine properly. 3.Computer Maintenance Cell Organization’s IT Team is internally named as CMC(Computer Maintenance Cell) to avoid conflicts with Academic IT department
3.1 Responsibilities of Computer Maintenance Cell:

- Maintaining Computer and its peripherals in Office space and Common space
- Maintaining Layer 2 Network along with Passive Network Components
- Maintaining Biometric devices and generating reports to the Salary/Attendance Process
- Maintaining Electronic Surveillance System
- Maintaining Projectors at All Digital Classrooms
- Installation of Operating system in all Institution-Purchased Computers and Software Installation at Office and Common Space
- Maintaining the record of All telephones / Cellular lines/connections and its functional details and co ordinating with concern Service Providers
- Cooperating with Internet Service Provider and Annual Contract Vendors for IT Products and supports.
- Establishing Network Connections every year if Sufficient funds are allotted for the same
- Upgrading new Technologies wherever required
- While New Blocks are constructed, planning and Implementing Network and Surveillance system are also carried out.
- Maintaining the record of Hardware and Software Details Centrally
3.2 Guidelines for CMC Engineers & Technicians:
3.2.1 Receiving Complaints:
CMC in charge or representative on behalf may receive a Complaint about Network, Computer, Printer and Projector related issues. Such issues can be informed via Phone/Email/Letter.
3.2.2 Deputing Work:
CMC in charge or Designated person will Depute an internal Service engineer /team based on the nature of the complaint received from user. The service engineer /team should resolve the work within a reasonable time In case the work has time constraint or if it is not solved by internal engineers, they may get outside support after obtaining permission from the higher officials.
3.2.3 Hardware Service:
Service Engineer should service only Institution purchased Hardware. While attending the service they should verify the hardware warranty status and they are not allowed to open any device under warranty without CMC in charge’s knowledge If the devices are to be replaced with spare parts, that should be properly received from CMC Stores by authorising in Stock register and the faulty spare should be returned to CMC office, marked with Institution Asset number and removed date on the spare. The Engineer should ensure that the Hardware Driver is downloaded from OEM website before installing it in the computers. For warranty service /non warranty service the spare purchased/added details should be updated in “Computer History Book”.
3.2.4 Software Service:
Service engineers may encourage the users to use Open source software and discourage them from Using/installing any Piracy and unauthorised software for any purpose. They should strictly refrain from obliging such request. Incase of Operating system reinstallation, they should note down network address details, list of software installed details in their service receipt and the same should be reinstalled with updated/upgraded one.
3.2.5 Network service:

If any passive components are newly added/replaced, source/destination details should be marked and the same should be immediately reported and updated in the Building Network Drawing. All switch Configuration details should be preserved for restoration purpose.
3.2.6 IT Policy Violation Incident:
If any institutional IT policy is violated by any Application/ individual/department, it should be brought to the notice of CMC in charge and Institution Authorities immediately. Co-ordination with Other Department / Contractors: With the knowledge of CMC in charge, Engineers shall coordinate with Service providers and other related internal departments for official work.
3.2.7 Responsibility:
The Head-Admin and Maintenance (H-A&M) of the campus is the overall responsibility for this policy. Questions concerning the policy may be directed to the Institution’s CMC in charge or H-A&M. The Head-A&M will review the policy on a Bi - Annual Basis and respond to formal complaints resulting from the implementation of this policy. Violations of this policy will result in appropriate disciplinary measures in accordance with the Institution’s code of conduct
4. Disclaimer:
It is individual’s risk if any loss caused to your Device/application due to this IT policy.

REVIEW AND APPROVAL
14. REVIEW AND AMENDMENT
The policy owner shall review this document at the stated cycle or earlier due to changes in law, regulation, institutional structure, technology, risk, audit findings or stakeholder requirements. Amendments shall take effect only after approval by the competent authority.
15. REFERENCES
- AICTE Approval Process Handbook and Faculty Norms, as amended from time to time
- UGC, DOTE TN, Anna University and autonomous academic regulations, as applicable
- Institutional Strategic Plan 2025–2030, IQAC procedures and approved committee minutes
- National Education Policy 2020 and institutional HR/Appraisal policies
16. APPROVAL AND SIGNATURES
| Prepared / Coordinated by | Reviewed by | Approved by |
|---|---|---|
| Name & Signature | Name & Signature | Name & Signature |