US · guidance
BOP Program Statement 1237.15 § 5
RESPONSIBILITIES OF INFORMATION AND COMPUTER USERS. The
following responsibilities are based upon best practices for
protecting the Bureau’s Information Resources.
a. Official Business. Personal use of Government office
equipment such as computers, printers, fax machines, telephones,
copiers, and calculators is permitted, if it does not involve
more than a negligible cost to the Government.
Ž Use of such items by an employee in any employment
category may occur before or after official working
hours or during non-paid meal breaks, provided the use
does not adversely affect the performance of official
duties by the employee or the Bureau.
Government computer resources are placed at the disposal of all
categories of employees to help them more efficiently and
effectively carry out the agency’s business and to serve the
public better. Certain prohibitions are associated with the use
of these resources including:
(1) Using the computer for non-work purposes during duty
hours.
(2) Accessing external computer systems (such as bulletin
boards and the Internet) when the access is not
necessary to perform an official duty during normal
work hours.
(3) Using government-owned software, information, or
equipment including the development of computer
programs for unofficial purposes exceeding what is
licensed or authorized above.
P1237.15
12/31/2007
Page 3
(4) Accessing Internet sites that impose a cost to the
Government or provide sexually explicit, racially
degrading, or other material inappropriate for the
workplace.
* (5) Storing on government hard drives (or diskettes,
directories, or archives)or copying, displaying,
generating, recording, transmitting or printing files
or data, sending or forwarding E-mail (attachments,
photos, information, etc.), from or to Government
computers, which could be offensive or inappropriate
for the Bureau work environment.
Ž Including but not limited to, items or
descriptions that are sexually explicit or
degrading to any other person, as it relates to a
person’s gender, sexual orientation, race, creed,
culture, etc. *
(6) Accessing Internet sites during normal duty hours for
other than official business. (It is permissible to
access sites, except as noted in subsection (4) above,
before or after duty hours or during non-paid lunch
periods.)
(7) Sending or re-sending ¡Chain Letters¢ via the Internet
or BOPNet GroupWise mail or by other methods on
Government equipment. Chain letters sent through the
U.S. Mail are illegal; using government resources to do
so is strictly prohibited by this Program Statement.
(8) Using local area network (LAN) disk space/storage and
telecommunications bandwidth by sending attachments
consisting of elaborate graphics for unofficial
purposes via E-mail transmissions. This activity
wastes computing resources, particularly when sent to
multiple addresses.
(9) Divulging sensitive Government information to any
person who is not authorized to have access to the
information.
(10) Leaving sensitive Government information unprotected or
accessible to unauthorized persons by leaving a
workstation logged onto a LAN without invoking a
currently required Bureau approved screen saver with
password protection.
P1237.15
12/31/2007
Page 4
(11) Removing sensitive documents (electronic media or
paper) from the workplace without proper authority.
(12) Failing to secure ¡Privacy Act Protected Information,¢
¡Limited Official Use,¢ ¡Extremely Sensitive
Information,¢ or classified documents adequately,
regardless of the manner in which the information is
recorded.
(13) Permitting inmates to use Staff Only workstations.
(14) Permitting or having use of, or access to systems which
is facilitated through the use of a personal ID and
password issued to another person.
b. Information Access. Although not all information on
personal computer hard drives, file servers, and removable media
(diskettes) is considered sensitive (critical to the Bureau’s
daily operation) or protected because of the Privacy Act
requirements, much of the information in electronic systems is
vulnerable because once the system is accessed, all information
(regardless of sensitivity) is available to the user or a
perpetrator.
This level of vulnerability requires that the entire system be
protected from unauthorized access. Therefore, employees shall:
(1) Only access systems or data for which the supervisor
has determined a need and additionally, have been
granted authorization by the system administrator(s).
(2) Not retrieve information (printed or electronic) from a
system for someone who does not have authority to
access the information.
(3) Only provide information, forms, surveys, etc., to
persons who have shown a legitimate official need.
(4) Not provide paid or non-paid employees, contractors,
volunteers, or other types of employees with a system
USER ID and PASSWORD without proper clearance as
defined in the Program Statement on Information
Security Programs.
c. System Integrity. All systems, whether automated or
manual, must provide information to the user quickly,
accurately, and reliably. To ensure that the information
contained in Bureau systems continues to be responsive, employees
shall:
P1237.15
12/31/2007
Page 5
(1) Scan all files and disks for viruses before use and
execute virus protection on computer workstations
according to procedures defined by local Computer
Services Managers (CSM) or policy. Discontinue the use
of any computer workstation showing indications of
being infected with a virus and notify the local CSM.
(2) Use only U.S. Government, Bureau, Information Security
Programs or Office of Information Systems (OIS)
authorized software (i.e., personally owned software,
shareware, public domain software, or similar programs
must not be used unless specifically authorized by the
local Information Security Officer). Users are
responsible to ensure that all software installed on
the hard drives of their workstations comply with
licenses, agreements and copyright laws.
(3) Ensure that only authorized and accurate information is
entered into information databases.
(4) Protect personal passwords from disclosure and not
share them with anybody or ask another person for his
or hers for any reason. Exceptions are limited to
prescribed circumstances noted in the Program Statement
on Information Security Programs.
d. System Availability. To protect data and system
availability employees shall:
(1) Make backups of critical and sensitive systems and
files regularly.
(2) Store backups away from originals and from devices that
produce magnetic fields.
(3) Protect disks and equipment from spillage of food and
drink.
(4) Know whom to contact for emergencies and significant
malfunctions.
History
PS 1237.15 dated 2007-12-31
Provenance
- Source
- bop.gov
- Retrieved
- 2026-09-20
- Edition
- bop-ps-2026-09-20
- Content hash
d34c4c40d8a8d60eba508bc30688936803708864c3a3d541ca71e426cec6bced
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.