Bulletin Board - Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

Important Information

During the comment process you are connected to a database.  The session that connects you to the database may time-out due to inactivity.  The following tips will help you to avoid losing your comments or corrupting your entries:

  1. Do not jump between web pages/applications while logging comments.
  2. Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
  3. Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
  4. Do not exit the process until you have completed all three stages.

IT Appropriate Use Procedure

Section 1 - Summary

(1) This Procedure describes the standards and processes related to appropriate use of Victoria University (VU) Information Technology (IT), including proper use of email and internet, internal mailing lists, cloud storage services and personal devices connected to the VU environment.  

Top of Page

Section 2 - Scope

(2) This Procedure applies to:

  1. All VU staff, students, Council members and members of its Committees, visitors, contractors and third-party service providers both onshore and offshore connecting to IT computing facilities, services, systems, networks and accounts, either on VU premises or remotely.
  2. All information that is owned and/or operated by VU and/or registered in any Domain Name System (DNS) domain owned by VU.
  3. IT equipment and devices that are present on VU premises but may not be owned or operated by VU, including personal or third-party/contractor devices.
  4. Information outsourced or hosted by external/third-party service providers, if that information resides in a VU domain or appears to be owned by VU.
Top of Page

Section 3 - Policy/Regulation

(3) IT Appropriate Use Policy

Top of Page

Section 4 - Procedures

Part A -  Summary of Roles and Responsibilities

Roles Responsibilities
IT users (staff, students and other authorised users) Use VU IT facilities and services, including email services, in a responsible, professional, lawful and secure manner in accordance with the IT Appropriate Use Policy and Information Security Policy.
Digital and Campus Services (DCS)
Provide, maintain and oversee the VU IT environment, and monitor/audit use of VU IT facilities and services as required.
Subject to the necessary approvals and requests:
- Set up new shared mailboxes
- Provide delegate access to mailboxes
- Manage the internal mailing list services
- Connect a personal device to VU wireless network and software/applications
- Install software on VU devices.
Managers
Approve access to mailboxes if required.
Approve software installation requests if required.
Chief Digital Officer and Executive Director Campus Services Approve access to mailboxes if required. 

Part B - Email

Standards of Use

(4) All email accounts maintained on the University’s email system are the property of VU.

(5) The use of VU email services must comply with:

  1. the IT Appropriate Use Policy and this Procedure,
  2. the Information Security Policy and associated procedures;
  3. other relevant University policy and procedures, including the Appropriate Workplace Behaviour Policy, Student Conduct Policy and Student Charter; Bullying Prevention and Management Policy, Gender-based Violence Policy, Discrimination and Harassment Prevention and Management Policy; and the Copyright Policy.

(6) VU email accounts must be used for University-related email communications.

(7) Email is the University’s primary communication channel. Staff and students are expected to monitor their VU email accounts regularly and respond in a timely manner where required.

(8) VU email configurations, including disclaimers, must not be altered or interfered with.

(9) Automatic forwarding of VU emails to external accounts should be avoided.

Mailbox Access

(10) Requests for shared mailboxes, delegated access or other mailbox permissions must be submitted via the VU Support Hub and are subject to appropriate approval.

(11) Users may only access or send email on behalf of another user where authorised.

(12) Access to email accounts is removed upon cessation of employment or enrolment. Where ongoing access is required for business continuity, requests must be approved by the relevant manager and submitted via the VU Support Hub for approval by the Chief Digital Officer and Executive Director Campus Services.

Unacceptable Communications

(13)  Users must not:

  1. send email or other communication material that infringes copyright (refer to the Copyright Policy in determining what third-party material can be used).
  2. send emails or other communications that are unlawful, offensive, defamatory or otherwise breach VU policies.
  3. send unsolicited or unauthorised mass emails or communications (spam).
  4. forge, misrepresent or falsely attribute emails or other communications.
  5. interfere with or disrupt VU business through misuse of email or other communications.
  6. bring VU or its officers into disrepute.
  7. send malicious content, including phishing emails or malware, except where authorised for legitimate University purposes, such as approved research or cyber security awareness activities.  

Email Security and Awareness

(14) Users must remain vigilant to potential cybersecurity threats, including spam and phishing.

(15) Suspicious emails, attachments or links should not be opened and should be reported using the “Report ” button within Microsoft Outlook.

(16) VU will not request account credentials via email. 

(17) Suspected credential compromise must be reported to the VU Support Hub immediately.

Monitoring and Records

(18) VU may monitor and access email communications to maintain system integrity and/or to comply with legal or regulatory requirements. See the Information Security Policy.

(19) Email records are retained and managed in accordance with the Records Management Policy and Information Security Policy.

Part C - Internet Use

(20) Use of the internet via VU IT systems and networks must comply with the IT Appropriate Use Policy, this Procedure, and the Information Security Policy.

(21) Users must ensure that internet use does not expose VU to security, legal or reputational risk.

(22) Access to internet services may be monitored or restricted by VU where required for security, operational or compliance purposes.

Part D - Internal Mailing Lists

(23) Internal mailing lists are configured to support University-wide, campus-based and organisational communications, and are used as an effective means of sending bulk email communications to VU staff and students.

(24) Internal mailing lists must only be used for official VU business. They must not be used for personal advertising, non-University announcements, frivolous content, or any use that breaches VU policies. Mailing list messages may be subject to moderation to ensure compliance.

(25) Emails sent to internal mailing lists must be sent from a VU email account. Messages must include a subject line that clearly reflects the content, and where appropriate, indicates the intended audience. 

(26) Details of internal mailing lists, including usage parameters, authorised senders and moderators, are maintained in the Internal Mailing List Guidelines.

Part E - Personal Devices

(27) Personal devices must be connected to the University’s eduroam wireless network when accessing VU IT systems.

(28) VU is not liable for loss of, or damage to, personal data on personal devices.

(29) Limited support is available to assist users to connect personal devices to VU networks and access VU systems and applications.

(30) VU does not guarantee compatibility of personal devices with VU systems or services and is not liable for any loss, damage or costs associated with their use.

(31) VU does not provide support for:

  1. non-VU software or applications;
  2. operating system configuration;
  3. personal data recovery; or
  4. personal internet services or external providers.

Part F - Software

(32) Users must not install or use unauthorised software on VU systems or devices.

(33) Use of AI software must comply with the AI Governance and Responsible Use Policy.

(34) VU devices are equipped with a standard software suite. Requests for additional software required for teaching, research or business purposes must be submitted via the VU Support Hub.

(35) Software requests with cost implications or that are not part of the VU software catalogue require manager/supervisor approval.

Part G - Cloud Storage

(36) VU-approved cloud storage services must be used to store and share VU information, in accordance with the Information Security Policy. 

(37) Personal cloud storage accounts (eg: privately subscribed services) must not be used to store or share VU information. This includes:

  1. official VU information or communications;
  2. personal or confidential information;
  3. sensitive or restricted data;
  4. financial or strategic information,
  5. information covered by the Health Records Act 2001 (Vic) including all health information disclosed to VU, regardless of context (e.g. information disclosed to VU’s Counselling and Disability Services, health information disclosed in a VU clinic or teaching facility).

(38) Use of cloud storage for research purposes must comply with the Research Integrity - Research Data Management Procedure.

(39) VU information stored in unauthorised cloud services must be migrated to approved systems and removed from the unauthorised location.

(40) Users should follow the Best Practice Guidelines for Using Cloud Storage Safely when using cloud storage services to store, access or share VU information.

(41)  IT support is only provided for VU-approved cloud storage solutions.

Part H - Breaches

(42) Breaches of this Procedure will be managed in accordance with the IT Appropriate Use Policy and relevant VU policies and may result in disciplinary or other appropriate action.

Top of Page

Section 5 - HESF/ASQA/ESOS Alignment

(43) HESF: Standard 2.1 Facilities and Infrastructure, 7.3 Information Management. 

(44) Outcome Standards for NVR Registered Training Organisations 2025: Standard 1.8 Facilities, Equipment and Resources. 

Top of Page

Section 6 - Definitions

(45) User: VU staff, students, contractors, visitors, third-party providers and Council members and members of its committees using IT computing facilities, systems, networks and accounts.

(46) Communications / communication material: The sending or receiving of information on VU computing facilities, systems, networks and accounts, such as email, MS Teams, Zoom, Jabber, phone, and Viva Engage.

(47) Internal mailing list: Email list for VU staff communications. Does not include mailing lists from VU to email external stakeholders. 

(48) Personal data and information: Non-VU data and information that belongs to the device owner including but not limited to personal files and documents.

(49) Personal device: A device not owned by VU used to connect to or gain access to the University environment. This includes but is not limited to personal computers, laptops, tablets and smartphones. 

(50) University environment: Information assets owned and/or operated by VU and/or outsourced or hosted by external/third-party service providers including but not limited to VU network, IT facilities, accounts, systems and applications.

(51) VU information: Any data and information that is intended to be used within VU, including but not limited to files, documents, records, reports and staff email.