Internet Access and Usage Policy
Hakkari University’s Internet Access and Usage Policy defines the principles for lawful, ethical and secure internet use, protection of network resources, user responsibilities and information security.
Internet Access and Usage Policy
1. Purpose
This policy has been established to promote the lawful, ethical and secure use of the internet service provided at Hakkari University, to prevent inappropriate and unauthorized access, and to protect the University’s legal obligations, network security, efficient use of network resources, capacity management and institutional reputation.
2. Scope
Within the scope of the TS EN ISO/IEC 27001 Information Security Management System of the Department of Information Technologies, this policy applies to Hakkari University academic and administrative staff, students, guests and external stakeholders who access the internet through all campuses and networks of Hakkari University.
3. Definitions and Abbreviations
3.1. Information Security: Protection of the confidentiality, integrity and availability of information.
3.2. Information Security Management System (ISMS): A risk-based management system for establishing, implementing, operating, monitoring, reviewing, maintaining and improving information security.
3.3. Information: Data that is necessary for the continuity of Hakkari University processes, has value and therefore needs to be appropriately protected.
3.4. Information Assets: All assets within Hakkari University that have significance for information security under the TS EN ISO/IEC 27001 Information Security Management System.
3.5. University: Hakkari University.
3.6. Rector: Rector of Hakkari University.
3.7. Quality Management Representative: The Hakkari University employee responsible for ensuring the establishment, implementation and continuity of the processes required by the Quality Management System; reporting to senior management on system performance and opportunities for improvement; promoting awareness of requirements among employees; planning and implementing changes; and maintaining the integrity of the Quality Management System.
3.8. Head of Department: Head of the Hakkari University Department of Information Technologies.
3.9. User: Hakkari University academic and administrative units, academic and administrative staff, students, student clubs and external stakeholders.
3.10. VPN (Virtual Private Network): A network technology that protects data and improves privacy by providing a secure and encrypted connection over the Internet.
3.11. DNS (Domain Name System): A system that enables communication between devices and servers on the Internet by translating domain names into IP addresses.
3.12. Internet: The global network that enables information sharing, communication and interaction between computers and other digital devices.
3.13. Access: Connection to Internet content.
3.14. E-Mail: Messages sent and received electronically over the Internet.
3.15. Proxy: An intermediary server that routes internet traffic through another server.
3.16. Server: A computer or software system that provides data, services or resources to clients, generally over a network.
3.17. Audit Trail (Log): System-generated records created when the status, changes or digital activities relating to an information asset are recorded over time.
3.18. ULAKBİM: The Turkish Academic Network and Information Center affiliated with TÜBİTAK.
3.19. ULAKNET: The National Academic Network established within the framework of applicable Turkish legislation to meet the electronic communication and infrastructure needs of education and research institutions.
4. Responsibilities
4.1. Information Security Management System Commission: Responsible for preparing and updating this policy.
4.2. Rector: Responsible for approving and putting this policy into effect.
4.3. Quality Management Representative: Responsible for controlling this policy in accordance with the Document Control Procedure, assigning and monitoring document and revision information, and ensuring that it is included in the current document list.
4.4. Head of Department: Responsible for ensuring the control and applicability of this policy.
4.5. User: Individually responsible for all internet use carried out within the framework of this policy.
5. General Provisions
The University Internet Access Service consists of wired and wireless network access provided to academic and administrative staff, students, guests and external stakeholders. This service is provided through TÜBİTAK ULAKNET within the framework of applicable legislation and policies.
Internet access and user activity logs generated through the University network are retained electronically in accordance with Law No. 5651 and related regulations. Such records may include information such as username, IP address, connection start and end times, and protocol type, and are stored with integrity verification mechanisms.
Log records are securely retained for at least two years so that they may be submitted to competent judicial or administrative authorities when legally required. Personal data protection principles and Law No. 6698 on the Protection of Personal Data are observed throughout this process.
Access to log records is restricted to authorized personnel of the Hakkari University Department of Information Technologies. These records may not be removed from the institution or shared with third parties and may only be provided to authorized authorities for legal proceedings or audits.
Users are subject to an appropriate authentication method when accessing the University internet service. Anonymous access is not permitted.
The University internet service should primarily be used for education, training, scientific and technological research and development, and access to or dissemination of scientific, technological and cultural information.
Users must not interfere with network infrastructure, including network switches, wireless access devices, network cables or network outlets, modify their settings, install unauthorized devices or create unauthorized wireless access points.
Users are responsible for the websites and systems they access through the University network and should remain cautious against deceptive or misleading online content.
The University is not responsible for problems arising from users’ personal transactions conducted over the Internet, such as banking, online shopping or personal e-mail services.
Prohibited Uses
The University Internet Access Service must not be used:
- Directly or indirectly for unauthorized commercial purposes.
- To access prohibited or inappropriate content.
- To reuse institutional passwords, critical institutional information, usernames or institutional e-mail credentials for personal social media, e-commerce, forum or similar services.
- To prevent or disrupt other users’ internet access or access to network resources.
- To attack network resources.
- To access resources without authorization or monitor, investigate or record another user’s traffic or information.
- To consume bandwidth in a manner that negatively affects other users.
- To produce, host or transmit content contrary to applicable laws and institutional rules.
- To send unsolicited or spam messages.
- To make unauthorized VPN, Proxy or DNS changes.
- To engage in activities contrary to the laws of the Republic of Türkiye or University regulations.
- To download or share content in violation of copyright.
Non-Compliance
If users violate one or more provisions of this policy, depending on the nature and severity of the violation:
- The user may be warned in writing or by SMS.
- University internet access may be suspended temporarily or indefinitely.
- Academic or administrative investigation procedures may be initiated.
- Matters not sufficiently covered by this policy may be evaluated by the relevant University authorities.
- Applicable information security incident, network security, risk management and threat intelligence procedures may be applied.
- Where required under Law No. 5651 and related regulations, relevant access logs may be submitted to judicial authorities.
6. Reference Documents
- Document Control Procedure
- ULAKNET Usage Policy
- Audit Trail Records Procedure
- Network Security and Management Procedure
- Information Security Incident Procedure
- Risk Management Procedure
- Threat Intelligence Procedure
- Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications
- Law No. 6698 on the Protection of Personal Data