Bindinglaw

US · guidance

BOP Program Statement 1237.15 § 5

RESPONSIBILITIES OF INFORMATION AND COMPUTER USERS. The

activein force · 2007-12-31 – presentact-effective-date

following responsibilities are based upon best practices for

protecting the Bureau’s Information Resources.

a. Official Business. Personal use of Government office

equipment such as computers, printers, fax machines, telephones,

copiers, and calculators is permitted, if it does not involve

more than a negligible cost to the Government.

Ž Use of such items by an employee in any employment

category may occur before or after official working

hours or during non-paid meal breaks, provided the use

does not adversely affect the performance of official

duties by the employee or the Bureau.

Government computer resources are placed at the disposal of all

categories of employees to help them more efficiently and

effectively carry out the agency’s business and to serve the

public better. Certain prohibitions are associated with the use

of these resources including:

(1) Using the computer for non-work purposes during duty

hours.

(2) Accessing external computer systems (such as bulletin

boards and the Internet) when the access is not

necessary to perform an official duty during normal

work hours.

(3) Using government-owned software, information, or

equipment including the development of computer

programs for unofficial purposes exceeding what is

licensed or authorized above.

P1237.15

12/31/2007

Page 3

(4) Accessing Internet sites that impose a cost to the

Government or provide sexually explicit, racially

degrading, or other material inappropriate for the

workplace.

* (5) Storing on government hard drives (or diskettes,

directories, or archives)or copying, displaying,

generating, recording, transmitting or printing files

or data, sending or forwarding E-mail (attachments,

photos, information, etc.), from or to Government

computers, which could be offensive or inappropriate

for the Bureau work environment.

Ž Including but not limited to, items or

descriptions that are sexually explicit or

degrading to any other person, as it relates to a

person’s gender, sexual orientation, race, creed,

culture, etc. *

(6) Accessing Internet sites during normal duty hours for

other than official business. (It is permissible to

access sites, except as noted in subsection (4) above,

before or after duty hours or during non-paid lunch

periods.)

(7) Sending or re-sending ¡Chain Letters¢ via the Internet

or BOPNet GroupWise mail or by other methods on

Government equipment. Chain letters sent through the

U.S. Mail are illegal; using government resources to do

so is strictly prohibited by this Program Statement.

(8) Using local area network (LAN) disk space/storage and

telecommunications bandwidth by sending attachments

consisting of elaborate graphics for unofficial

purposes via E-mail transmissions. This activity

wastes computing resources, particularly when sent to

multiple addresses.

(9) Divulging sensitive Government information to any

person who is not authorized to have access to the

information.

(10) Leaving sensitive Government information unprotected or

accessible to unauthorized persons by leaving a

workstation logged onto a LAN without invoking a

currently required Bureau approved screen saver with

password protection.

P1237.15

12/31/2007

Page 4

(11) Removing sensitive documents (electronic media or

paper) from the workplace without proper authority.

(12) Failing to secure ¡Privacy Act Protected Information,¢

¡Limited Official Use,¢ ¡Extremely Sensitive

Information,¢ or classified documents adequately,

regardless of the manner in which the information is

recorded.

(13) Permitting inmates to use Staff Only workstations.

(14) Permitting or having use of, or access to systems which

is facilitated through the use of a personal ID and

password issued to another person.

b. Information Access. Although not all information on

personal computer hard drives, file servers, and removable media

(diskettes) is considered sensitive (critical to the Bureau’s

daily operation) or protected because of the Privacy Act

requirements, much of the information in electronic systems is

vulnerable because once the system is accessed, all information

(regardless of sensitivity) is available to the user or a

perpetrator.

This level of vulnerability requires that the entire system be

protected from unauthorized access. Therefore, employees shall:

(1) Only access systems or data for which the supervisor

has determined a need and additionally, have been

granted authorization by the system administrator(s).

(2) Not retrieve information (printed or electronic) from a

system for someone who does not have authority to

access the information.

(3) Only provide information, forms, surveys, etc., to

persons who have shown a legitimate official need.

(4) Not provide paid or non-paid employees, contractors,

volunteers, or other types of employees with a system

USER ID and PASSWORD without proper clearance as

defined in the Program Statement on Information

Security Programs.

c. System Integrity. All systems, whether automated or

manual, must provide information to the user quickly,

accurately, and reliably. To ensure that the information

contained in Bureau systems continues to be responsive, employees

shall:

P1237.15

12/31/2007

Page 5

(1) Scan all files and disks for viruses before use and

execute virus protection on computer workstations

according to procedures defined by local Computer

Services Managers (CSM) or policy. Discontinue the use

of any computer workstation showing indications of

being infected with a virus and notify the local CSM.

(2) Use only U.S. Government, Bureau, Information Security

Programs or Office of Information Systems (OIS)

authorized software (i.e., personally owned software,

shareware, public domain software, or similar programs

must not be used unless specifically authorized by the

local Information Security Officer). Users are

responsible to ensure that all software installed on

the hard drives of their workstations comply with

licenses, agreements and copyright laws.

(3) Ensure that only authorized and accurate information is

entered into information databases.

(4) Protect personal passwords from disclosure and not

share them with anybody or ask another person for his

or hers for any reason. Exceptions are limited to

prescribed circumstances noted in the Program Statement

on Information Security Programs.

d. System Availability. To protect data and system

availability employees shall:

(1) Make backups of critical and sensitive systems and

files regularly.

(2) Store backups away from originals and from devices that

produce magnetic fields.

(3) Protect disks and equipment from spillage of food and

drink.

(4) Know whom to contact for emergencies and significant

malfunctions.

History

PS 1237.15 dated 2007-12-31

Provenance

Source
bop.gov
Retrieved
2026-09-20
Edition
bop-ps-2026-09-20
Content hash
d34c4c40d8a8d60eba508bc30688936803708864c3a3d541ca71e426cec6bced
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.