Oxford Security Services and Oxford Security Internet, Email and Social Media Policy
Introduction
Oxford Security Services and Oxford Security reliance on the use of the Internet, email and social media is essential to the effective delivery of the services it provides. Along with this reliance comes the need to identify and address the vulnerabilities and risks associated to ensure that we are protecting every aspect of the company and customers’ businesses and are able to maintain the efficient and effective services to both our service users and our Customers.
Purpose
The purpose of this policy is to provide clear guidance on acceptable behaviour in the use of the Internet and email – including the use of social media both during and out of work, and that it is consistent with the companies Employee Code of Conduct, Acceptable Use policies, Risk Management Strategy and professional best practices. Nothing in this policy should be read as restricting the proper use of the Internet, email, and social media for work purposes.
Scope
This policy applies to all employees, contractors, and customers who have access to use the company’s Internet and email and who use both work and/or personal social media and internet related accounts where they may also be representing the company by virtue of association, such as that of an employee.
This policy applies to all information technology and communications equipment provided by Oxford Security Services and Oxford Security capable of accessing the Internet, sending/receiving emails, and using social media accounts e.g. PC’s, laptops, tablets, mobile phones, and all other internet capable computing devices.
Policy Statement
All parties identified in the scope of this policy are required to maintain the good reputation of the company when using the Internet, email, and social media. Any such use which brings the company into disrepute may result in the removal of internet, email, and company social media access. Disciplinary action may be taken against employees where necessary.
Any personal information sent via email, the Internet, social media, and associated services such as Microsoft Teams is covered by the Data Protection Act 2018. All parties are required to handle personal information in accordance with the Data Protection Act and the UK GDPR. Further information about handling personal data is available ICO. Guidance: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources
Internet Use
For this policy, the use of the internet will include associated internet enabled technologies such as Teams.
The use of Oxford Security Services and Oxford Security internet systems is restricted to the following conditions:
- Personal use of the Internet is not allowed during working hours.
- Personal use is only permitted in your own time and limited to browser-based activities. You can use the Internet before you start work, during your lunchtime, or after work. For flexi-time users, this should be recorded accordingly in Workplace as non-working time
- Any personal use must not, in any way, distract others from the effective performance of their duties. Improper or inappropriate personal use of the company’s Internet and associated systems may result in disciplinary action
- You must not use the company Internet systems for trading or personal business purposes
- You must not reveal personal, sensitive, or confidential information relating to service users or the company
- You are advised not to conduct online payments. This is due to the information being stored locally on your computer, which potentially could be compromised, putting the user at financial risk. If you use the Internet to buy goods or services, the company will not accept liability for default of payment or for the security of any personal information you provide. Goods must notbe delivered to a company or customer address
- All Internet sessions should be terminated as soon as they are concluded
- Use of Microsoft Teams services for personal use is not permitted at any time. More information on the use of other social media can be found in sectionSocial Media Use of this policy
- Collaborative features of Microsoft Teams are approved for use by company employees or in conjunction with partners. Audio-visual recording and automated transcription are permitted only if participants are aware they are being recorded. The purpose of recording must be stated, with directions to a relevant privacy notice, so participants can understand how their personal data is processed. The initiator of the recording or transcription is responsible for its management. Ordinarily, the data will be categorised as transient under the Corporate Records Management Policy and should be promptly deleted. If needed as a substantive record, the relevant content must be captured in a company approved recordkeeping system (e.g. extract from transcription copied into minutes). Desktop and document sharing capabilities must be used with caution. Presenters and Teams site owners have a responsibility to ensure that the information is managed appropriately
- You must use the company’s internet provision responsibly in accordance with this policy and all relevant policies and guidelines.
Filtering Content
Many Internet sites that contain unacceptable content are blocked automatically by the company systems. However, it is not possible to block all “unacceptable” sites electronically in all circumstances.
The company has a process in place to block categories of internet sites and individual sites if it is deemed appropriate to do so.
Downloading Material
- Downloading of video, music files, games, software files, and other computer programs is not permitted. These types of files consume large quantities of storage space on the system (and can slow it down considerably), may violate copyright laws, and may pose serious security risks by introducing malware/viruses onto the company’s computer network.
- Online Mapping Software should not be used unless for specific work purposes, as it is resource intensive and involves downloading an application to your computer.
- Streaming media, such as radio or tv programmes, for non-work-related purposes, is not permitted.
If you are in doubt about software use or installation, seek guidance from the managing director.
Accidental Access To Inappropriate Material
You may receive an email or mistakenly visit an Internet site that contains unacceptable material. If this occurs, you must inform your line manager or a more senior manager immediately. Your manager will ask you for details relating to the incident, and you will be asked how the event occurred. This information may be required later for management and audit purposes.
Copyright
You may be in violation of copyright laws if you simply cut and paste material from one source to another. Most sites contain a copyright notice detailing how the material may be used. If you are in any doubt about downloading and using material for official purposes, you should seek advice from the managing director.
Email Use
Email is an extremely efficient means of communication, but always ask yourself whether a quick internal telephone call would be more effective than sending an email message. Use of the company’s email systems is restricted to the following conditions:
- Personal use of oxsec.co.uk email or any other email system provided for use as a company employee is not permitted at any time. It is also inappropriate as it may give the impression that any business is on behalf of the company.
- If a genuine emergency arises where you have received and replied to an email for personal reasons, you should inform your line manager at the earliest opportunity that you have responded to the email, and they will make a note of it. You should inform the sender that personal use of the Oxford Security Services and Oxford Security’s email system is not permitted, and an alternative method of communication will need to be considered.
- Emails should only be kept in your inbox for a maximum of 6 months. Any emails that you need to keep beyond this period should be moved to appropriate file storage, EDRM or network files
- You must only use Oxford Security Servicesand Oxford Security provided email systems to send and receive Oxford Security Services and Oxford Security information
- Employees are permitted to send their copy payslips to a personal email account. This must be done in compliance with Oxford Security Servicesand Oxford Security’s Secure Email Policy
- You must not use the email system in any way that is insulting or offensive, as described in the section Unacceptable Use
- Any authorised personal data sent externally by email e.g. to solicitors, Inland Revenue etc, must be sent in compliance with the Secure Email Policy: info@oxsec.co.uk
- You must not use anonymous mailing services to conceal your identity when mailing through the Internet, or falsify (spoof) emails to make them appear as if they have been sent from someone else
- All emails are automatically tagged with the classification ‘controlled’. You should consider whether you need to change the classification to ‘public’ or ‘restricted’.
- If you receive an email that is inappropriate or abusive, you must report it to your line manager immediately, who will take the appropriate action. If the sender is known to you, inform them that they should cease sending the material
- Emails that appear suspicious, may be ‘phishing or malware attempts and must be reported immediately as a security incident in accordance with the Oxford Security Services and Oxford Security’s Security Incident Management Policy and Procedures: Email:info@oxsec.co.uk
The content of incoming email is automatically scanned to detect computer viruses; however, the actual text of the email is not viewed as part of this process. The content of all emails may be viewed by Oxford Security Services and Oxford Security in certain circumstances, for example, in connection with disciplinary investigations or Audit reviews.
See guidelines on email management for advice on email: info@oxsec.co.uk
Email Disclaimer
A disclaimer is automatically attached to all emails sent from Oxford Security Services and Oxford Security informing the recipient that the email is intended solely for them, is confidential, may be legally privileged, and may contain personal views that are not those of Oxford Security Services and Oxford Security.
Office 365 Photos
Staff can voluntarily choose to have a photo assigned to their Office 365 account. The stored photo linked to ID badges may be used if available. Alternatively, staff are permitted to upload one of their own choosing, provided it conforms to the following criteria:
- A recognisable recent image of yourself • suitable for a professional environment
- Close up of face, head, and shoulders
- Free from reflection or glare on glasses
- Contain no other subjects in the photo
- Of a file size smaller than 4MB
- Of file format .png, .jpg or .gif
No other images are acceptable, including icons or caricatures.
Access to Email
Employees should delegate permission to their inbox on a permanent basis in accordance with Departmental Policy.
Where an employee is absent, the employee’s line manager may authorise access to an Oxford Security Services and Oxford Security email account to obtain messages that require action during their absence. The manager will inform the employee of this access on the employee’s return.
INSTANT MESSAGING (IM) USE
Instant Messaging is a form of real time communication between two or more people based on typed text. The text is conveyed via devices connected over the Internet or an internal network/intranet. Messages are retained in your conversation history in your email folder list or are saved as emails in your inbox if the recipient does not respond immediately.
You must only use Oxford Security Services and Oxford Security provided internet messaging (IM) services.
IM should not be used as a substitute for email. IM should be used only for questions or announcements that are short and need to be communicated immediately.
Private use of instant messaging for any purpose is not permitted.
Social Media Use
Social media is a type of interactive online media that allows parties to communicate instantly with each other or to share data in a public forum. This includes online social forums such as Twitter, Facebook, LinkedIn, internet newsgroups, and chat rooms.
Social media also covers blogs and video/image sharing websites such as Instagram, YouTube, and Flickr. There are many more examples of social media than can be listed here, and this is a constantly changing area. This policy refers to all social media, including the examples listed, and any new social media that is developed in the future.
The Oxford Security Services and Oxford Security recognise that the Internet provides an opportunity to participate in interactive discussions and share information using a wide variety of social media. The scope of this policy applies to those who are likely to use social media privately, (outside of work) as well as in their role during office hours or otherwise – whether the social media is accessed using Oxford Security Services and Oxford Security ICT facilities, or by using personal equipment where they may be representing the Oxford Security Services and Oxford Security such as that of an employee.
Use of social media is restricted to the following conditions:
- All employees are expected to behave appropriately and responsibly, and should be aware that they may be held accountable to Oxford Security Servicesand Oxford Security for actions outside of their work
- An employee’s personal social media account should not, directly or by implication, give the impression that they are endorsed by, or speaking on behalf of the Oxford Security Services and Oxford Security
- Online conduct is the employee’s responsibility, and it is important that employees are aware that posting information on social networking sites in a personal capacity cannot be entirely isolated from their working life
- Any information published online can be accessed around the world and will be publicly available for all to see, and this may be impossible to delete/withdraw once published
- You should not upload images or video files of work-based activities unless authorised by your line manager
- The Oxford Security Services and Oxford Security views any comment that is made on a social media site as having been made publicly, and that any inappropriate comment made will be considered in the context in which it is made. For example, disparaging comments against a colleague made on Facebook could be viewed as bullying/harassment and could be considered to bring the Oxford Security Services and Oxford Security into disrepute
- Employees should be aware that all comments made through social media must meet the standards of the relevant legislation and regulations, including Data Protection legislation, the Employee Code of Conduct, and the Equality and Diversity policy
- Employees may be accountable for actions outside of work, including making comments on social media sites, if that is contrary to any of Oxford Security Services and Oxford Security’s policies and procedures, impacts on or compromises the employee’s ability to undertake their role, or undermines management decisions. Such behaviour could be investigated and may result in disciplinary action, and ultimately could result in dismissal
Further employee guidance is available in your hand book
Access To Social Media for Work Purposes
Employees who use social media as part of their job must adhere to this Policy. Employees must be aware that they are representing Oxford Security Services and Oxford Security when they are contributing to Oxford Security Services’ and Oxford Security’s social media activities. Employees should use the same safeguards as they would with any other form of communication about the organisation in the public domain.
Access To Social Media At Work, For Personal Use
Employees are not allowed to access social media websites for personal use from Oxford Security Services and Oxford Security’s computers or devices during working time, and they must not be left constantly running ‘in the background’, whilst at work. These provisions also apply to personal computers and mobile devices.
Employees’ use of social media in both a personal and business capacity can present risks to Oxford Security Services and Oxford Security’s information and reputation, and can jeopardise our compliance with legal and statutory obligations. To minimise these risks and to ensure that our ICT resources and communications systems are used appropriately, employees must comply with this policy.
Personal Safety and Privacy
Employees need to be aware that the information they post on their personal social media profiles can make them identifiable to service users, as well as people they know in a private capacity. Employees should therefore consider this when setting up their online profile, particularly in relation to; use of a photograph, providing details of their occupation, employer, and work location.
Employees should also ensure that clients known to them through their work, where there could be a conflict of interest, are not linked to them through social media. Oxford Security Services and Oxford Security consider it inappropriate to have service users as ‘friends’ through social media, especially where these people are vulnerable and there may be safeguarding issues.
For example, it would be inappropriate for Social Workers to have service users and their families as ‘friends’ on Facebook.
Online sites such as Facebook are in the public domain, and personal profile details can be seen by anyone, even if users have their privacy settings on the highest level. Also, if a user’s profile is linked to other sites, any changes to their profile will be updated there too.
Employees who have set their privacy level to the maximum can have their privacy compromised by ‘friends’ who may not have set their security to the same standard.
Unacceptable Uses
These conditions apply to all internet, email, instant messaging, and social media use as identified in this policy. You must not use any of these systems in any way that is insulting or offensive.
You must not deliberately view, copy, create, publish, download, save, print, participate in or distribute any material that:
- is sexually explicit or obscene.
- includes discriminatory, derogatory, or offensive, inappropriate comments, media, or images relating to sex, sexual orientation, gender, reassignment, disability, age, religious belief, nationality, or race – including links to such materials
- contains material the possession of which would constitute a criminal offence
- promotes or participates in any form of criminal activity
- contains unwelcome propositions
- involves gambling, multi-player games, or soliciting for personal gain or profit
- contains images, cartoons, or jokes that may cause offence
- appears to be a chain letter.
- knowingly misrepresents and/or brings the Oxford Security Services and Oxford Security into disrepute or exposes it to legal action.
- contains defamatory comments, images, or media about individuals or other organisations/groups, and that which could also be considered as bullying or harassment
- agrees with or condones inappropriate comments or content
- contains or refers to confidential and/or personal information about an individual, such as a service user, colleague or Oxford Security Servicesand Oxford Security.
Employees are encouraged to talk to their manager and seek advice if they are unclear. Managers should ensure that all reports of inappropriate use and/or complaints are dealt with consistently, fairly, and in a timely manner.
All employees are required to make themselves aware of Oxford Security Services and Oxford Security’s Information Security policies. See the ‘Data Security’ section of working for us on the Oxford Security Services and Oxford Security’s website: www.oxsec.co.uk
This policy should be read in conjunction with the Employee Code of Conduct, Harassment and Bullying Procedure, ICT Acceptable Use policy, and Media Contact policy.
The Oxford Security Services and Oxford Security reserves the right to withdraw Internet access, email, or social media use, including access to the Oxford Security Services and Oxford Security’s computer or communications network, if the user has been found to be in breach of these conditions.
This list is not exhaustive, and Oxford Security Services and Oxford Security may define other areas of unacceptable use.
Monitoring
The Oxford Security Services and Oxford Security maintain logs of all internet, instant messaging (IM), and email use and monitor the service constantly.
Monitoring Internet Access
Oxfordshire County Council, Oxford Security Services, and Oxford Security record the details of all Internet traffic. This is to protect Oxford Security Services, Oxford Security, and its employees from security breaches, including hacking, and also to ensure that “unacceptable” sites are not being visited.
The logs record:
- The network identifier (username) of the user
- The URL address of the Internet site being accessed
- Where access was attempted and blocked by the system
- The Web pages visited and their content,
- The name of any files accessed and/or downloaded,
- The identity of the computer on the network and the date and time.
Any excessive or inappropriate use may result in disciplinary action being taken. All monitoring information will be kept for six months.
Monitoring Of Email and Instant Messages
The Oxford Security Services and Oxford Security’s email system automatically records details of all emails sent both internally and externally. The automatic system highlights the use of certain prohibited words, and any potential infringement will be referred to the Executive Directors by Audit Services as part of routine audit reviews.
The following details are recorded with respect to every email message:
- Name of the person sending the email
- The email addresses of all recipients and copy recipients
- The size and name of any file attachments
- The date and time sent
- A copy of the email
- A copy of file attachments.
Oxford Security Services and Oxford Security may read and inspect individual emails and attachments for specific business purposes or during disciplinary investigations, including:
- Establishing the content of transactions
- Ensuring employees are complying with both the law and with Oxford Security Servicesand Oxford Security’s email policy
- Checking email when employees are on leave, absent, or for other supervisory purposes
The Oxford Security Services and Oxford Security routinely produce monitoring information, which summarises email usage and may lead to further enquiries being undertaken. Monitoring information will be kept for six months.
Emails, including conversations recorded using facilities such as Teams, are covered by the Freedom of Information (FOI) Act and may be disclosed as part of an FOI request for information or as part of any legal proceedings. Always exercise the same caution on email content as you would in more formal correspondence.
Breaches of Policy
Breaches of this policy and/or security incidents can be defined as events which could have, or have resulted in, loss or damage to Oxford Security Services and Oxford Security’s assets, or an event which is in breach of Oxford Security Services’ and Oxford Security’s security procedures and policies.
All employees, elected members, contractors, volunteers, vendors, apprenticeships, student/work experience placements, and partner agencies have a responsibility to report security incidents and breaches of this policy as quickly as possible through Oxford Security Services and Oxford Security’s Incident Reporting Procedure. This obligation also extends to any external organisation contracted to support or access the Information Systems of Oxford Security Services and Oxford Security.
The Oxford Security Services and Oxford Security will take appropriate measures to remedy any breach of the policy and its associated procedures and guidelines through the relevant frameworks in place. In the case of an individual, then the matter may be dealt with under the disciplinary process.
It is your responsibility to read this policy carefully and to ask your line manager to explain if there is anything you do not understand. If you feel you may have accidentally breached this policy, you should contact your line manager immediately, or, in their absence, a more senior manager who will record this information. See Unacceptable Use.
This policy also works alongside other policies and procedures, including.
- ICT Acceptable Use Policy
- Employee Code of Conduct
- Disciplinary Procedure
- Harassment and Bullying Procedure
- Social Media Protocols
- Media Contact Policy
Copies of all policies and procedures are available on the Oxford Security Services and Oxford Security’s website, www.oxsec.co.uk.
Employee guidance on the acceptable use of Social Media
- Employees must be mindful that any online activities/comments made in a public domain must be compatible with their position within Oxford Security Servicesand Oxford Security, and safeguard themselves in a professional capacity
- Protect your own privacy. To ensure that your social network account does not compromise your professional position, ensure that your privacy settings are set correctly
- Comments made outside work, within the arena of social media, do not remain private and can have an effect on or have work-related implications. Therefore, comments made through social media, which you may intend to be “private” may still be in contravention of the Employee Code of Conduct, the Harassment and Bullying procedure and/or the Disciplinary procedure. Once something is online, it can be copied and redistributed, making it easy to lose control of. Presume everything you post online will be permanent and can be shared
- Do not discuss work-related issues online, including conversations about service users, complaints, management, or disparaging remarks about colleagues or Oxford Security Servicesand Oxford Security. Even when anonymised, these are likely to be inappropriate. In addition, doing this in the presence of others may be deemed as bullying and/or harassment
- Do not under any circumstances accept friend requests from a person you believe could be a service user or may conflict with your employment
- Be aware that other users may access your profile and if they find the information and/or images it contains offensive, make a complaint about you to the Oxford Security Servicesand Oxford Security as your employer.
- Ensure that any comments and/or images cannot be deemed defamatory, libelous, or in breach of copyright legislation
- When setting up your profile online, consider whether it is appropriate and prudent for you to include a photograph, or provide occupation, employer, or work location details
- You can take action if you find yourself the target of complaints or abuse on social networking sites. Most sites will include mechanisms to report abusive activity and provide support for users who are subject to abuse by others
- If you do find inappropriate references and/or images of you posted by a ‘friend’ online, you should contact them and the site to have the material removed
- If you are very concerned about someone else’s behaviour online, you should take steps to raise your concerns. If these are work related you should inform your manager
- Employees should also act in accordance with the Oxford Security Services and Oxford Security’s Employee Code of Conduct, Internet and Email Acceptable Use procedure, Acceptable Use of ICT policy, and Harassment and Bullying procedure
- Employees should not access social media sites or leave these running in the background during working time, for personal use, on any devices within their control
Oxford Security Services and Oxford Security Social Media Protocols
Purpose:
Oxford Security Services and Oxford Security social media accounts should be used to promote Oxford Security Services and Oxford Security policies, events, and services. They should not be used to promote the views, opinions or experiences of individual officers.
Account Creation:
Creation of all Oxford Security Services and Oxford Security social media accounts needs to be approved by the digital manager, working in the communications division. Individual officers cannot have Oxford Security Services and Oxford Security social media accounts in their own name.
Approval:
Departmental, service, and project social media accounts need approval the managing director before set-up. A brief business case must be provided for each proposed new social media profile. A proposal form can be found on oxsec.co.uk or via the Digital Communications Team. It includes:
- Why is the account needed
- Who is it aimed at
- Key objectives and messages
- Who will manage the account and post content
- How often will it be used and reviewed against its objectives
- An exit strategy for closing the account if it doesn’t meet its objectives
Elected Member Accounts
Elected members can set up their own social media accounts, which are hosted externally. Links to them can be included on the elected member’s page on the county Oxford Security Services and Oxford Security website.
Personal Accounts
Social media accounts held by officers in their private capacity should avoid commenting on Oxford Security Services and Oxford Security policies, along with any other issues relating to their position within Oxford Security Services and Oxford Security. For further guidance, see the Acceptable Use of Social Media Policy.
01865 751605 E-info@oxsec.co.uk
Matthew Collaire (Managing Director)
Review date: 5th May 2026 Next review Date:5th May 2027
Matthew Collaire (Managing Director)
5th May 2026