Skip to main content

Rules of Behavior

1. Purpose & Scope

TAMUS Cybersecurity Communities of Practice (CoP) mailing lists are collaborative, non-operational forums designed for peer learning, professional networking, and broad technical discussion across Texas A&M University System members.

These lists are strictly dedicated to general information security principles, strategic frameworks, architectural and technical discussions, and professional development. Members are encouraged to share insights, post questions, and discuss general best practices within the core areas listed for each community.

They are not an operational threat-intelligence or incident-response exchange.


2. Information Sharing & TLP Standard

To preserve a safe, open, and compliant environment, information sharing on this list is governed by the following strict bounds:

Maximum Sharing Classification: TLP:GREEN

  • Allowed Content (TLP:GREEN & TLP:CLEAR): Information exchanged on this list must be suitable for broad distribution across member organizations, peers, and academic cybersecurity professionals.
  • Prohibited Classification Levels: TLP:AMBER and TLP:RED materials are strictly prohibited.

Prohibited Sensitive Data Types

Members must not post, attach, or request any of the following sensitive information:

  • Active Threat Intelligence: Specific, unmitigated Indicators of Compromise (IOCs), live exploit code, active attack vectors, or zero-day vulnerabilities targeting specific organizations.
  • Operational System Data: Internal IP address schemas, detailed network topology maps, firewall rule bases, or specific system configuration exports.
  • Incident Details: Specifics regarding ongoing, past, or potential security incidents, breaches, or investigations involving any institution or third party.
  • Regulated & Sensitive Data: Controlled Unclassified Information (CUI), FERPA-protected student records, HIPAA PHI, PII, export-controlled data (ITAR/EAR), or proprietary vendor secrets.

3. Code of Conduct & Acceptable Use

Allowed Conduct

  • Requesting general feedback on cybersecurity strategies, governance frameworks, and tools.
  • Sharing publicly available industry news, research papers, webinars, and educational opportunities.
  • Discussing lessons learned and high-level concepts using the Chatham House Rule (discussions may be referenced outside the list, but specific speakers or institutions must not be identified without permission).

Strictly Prohibited Conduct

  1. Commercial Solicitation: Vendor pitches, product promotions, and commercial sales solicitations.
  2. Media & Public Attribution: Re-posting list contents to public social media, blogs, or news media outlets without explicit written approval from list administrators and content authors.
  3. Automated Re-Routing: Setting up automated bots, web scrapers, or third-party auto-forwarding rules that send list messages to non-vetted external systems.
  4. Unprofessional Behavior: Personal attacks, political commentary, or non-security-related discussions.

4. Compliance & Sanctions

  • Reporting Misuse: If a subscriber observes sensitive or out-of-scope information posted to the list, they should notify the TAMUS Cybersecurity List Administrator immediately at contact@cyber.tamus.edu.
  • Enforcement: Failure to adhere to these Rules of Behavior may result in immediate removal from the mailing list and notification to the subscriber's institutional Chief Information Security Officer (CISO) or direct supervisor.

5. Subscriber Acknowledgment

By participating in one or more communities of practice, I acknowledge that I have
received, read, and understand the Texas A&M University System Cybersecurity Communities
of Practice Rules of Behavior (ROB).

I agree to:

1. Limit all shared content to TLP:GREEN or lower.
2. Refrain from posting any sensitive, operational, or incident-specific data.
3. Maintain discussions within general, non-sensitive cybersecurity topics.
4. Promptly report any accidental violations to list administrators.