1.4.3 Software and Application Policy

POLICY TYPE: 1.0 Administrative Policies \ 1.4 Using Technology at SDLF
EFFECTIVE DATE: 2026-07-08 LAST REVISED:
THIS POLICY APPLIES TO:

Policy Statement

SelfDesign Learning Foundation (SDLF) is committed to ensuring that all software and applications used within the organization are acquired, deployed, maintained, and supported in a secure, lawful, and efficient manner. SDLF strives to protect sensitive data, comply with all relevant legal and licensing obligations, and support the educational and operational goals of the organization through responsible software management.

Definitions

Software: Computer programs and applications that are installed on, accessed through, or used with SDLF devices, systems, or credentials, including both cloud-based and locally hosted software.

Application: A software program designed to perform a specific function or set of functions, including web, mobile, and desktop applications.

Authorized software: Software that has been reviewed, approved, and authorized for use by SDLF and is listed in the organization’s official software inventory maintained by the SDLF IT Department.

Organizational Improvement Governance Group: The group responsible for making decisions and prioritizing actions as part of the organizational improvement process.

Shadow IT: Any software or application used within SDLF without prior approval from the organizational improvement review board.

Policy

SelfDesign Learning Foundation (SDLF) will only use authorized software applications that meet organizational security, privacy, and licensing standards. Our use of software will comply with the vendor’s terms and conditions.

SDLF will maintain an accurate inventory of all authorized software and applications currently in use. SDLF will implement regular reviews and software updates to mitigate security risks and ensure compliance with vendor terms.

The selection of software is approved through the Organizational Improvement Governance Board. Procurement, installation, and use of software must be coordinated through IT (SDLF’s Information Technology Department) or the designated authority to ensure compliance with licensing and security requirements. IT will manage software licenses, updates and patching schedules, where necessary.

Unauthorized or unlicensed software installation or use of Shadow IT on SDLF systems is strictly prohibited. Users must report use of any unauthorized software or suspected security vulnerabilities to IT immediately for investigation.

Software that handles sensitive or personal information must comply with SDLF’s privacy policies and applicable laws, including British Columbia’s Personal Information Protection Act (PIPA).

The IT department will conduct periodic audits to verify compliance with this policy. Audit results will be provided to the Organizational Improvement Governance Group for review.

Related Documents

N/A