D R A F T
Classification Number: 3.9
Date Issued: 8/97,6/02, [new date]
SUBJECT:
UNT WEBWEB PUBLISHING POLICYNOTE: This draft was approved by the Information Resource Council on May 16, 2006
Role of the World Wide WebWeb
Role of the World Wide Web
World Wide WebWeb services at the University of North Texas provide information as well as services to members of the University community, prospective students, and the general public. The WebWeb plays a vital role in helping the University fulfill its mission. Consequently, the structure of the WebWeb's information, and its ease of use, accuracy of information, and its security are of paramount importance to the University community.
Common Definitions
WebWeb site
A webWebsite (or webWeb site) is a collection of WebWeb pages, typically common to a particular domain name or sub-domain on the World Wide WebWeb on the Internet.
WebWeb applications
A webWeb application is an application delivered to users from a webWeb server over a network such as the Internet or an intranet. WebWeb applications are popular due to the ubiquity of the webWeb browser as a client , sometimes called a thin client.
Types of Information
Types of Information
OOffficial information refers to the governing or authoritative documents of the University or information that is published as part of the normal course of doing the University’s business. WebWeb pages containing official information generally are authored by or for departments, colleges, schools, and administrative offices at the University.
Personal Information information is published by individuals and is unrelated to the person’s official work role at the University. Examples of personal information includeare student pages, faculty members’ vitas that are published independently of their department’s pagesinformation about their faculties, and staff members’ pages that representing personal interests such as hobbies. Personal publishers are responsible for the content of the pages they create, and the views and opinions expressed on a personal page are strictly those of the page author and do not represent the University. However, personal publishers must comply with all University rules and policies as well as state and federal laws concerning appropriate use of computers.
Research and teaching information may be published on UNT Web sites by faculty members and/or students in the course of conducting research or fulfilling class assignments requiring the development of Web content. The content and structure of those sites are outside the scope of this policy, except that forms collecting personally-identifiable information must meet the registration requirements of those forms described below. Faculty members who publish research on UNT Web sites or assign Web development projects to students are responsible for complying with all University rules and policies as well as state and federal laws concerning appropriate use of computers.
Structure of the University WebWeb
Web
University Relations, Communications and Marketing (URCM,) with tThe advice of the UNT Information Resources Council (IRC,) will establish publishing standards for the structure and operation of UNT's WebWeb services as well as develop policies and procedures needed to maintain WebWeb sites that serve the mission of the University in an effective manner.
Responsibility for Official Information
Because official information represents the University to a worldwide community, it must be timely, accurate, and consistent with University policies and local, state and federal laws. Furthermore, the presentation of official UNT information via the WebWeb must adhere as closely as possible to UNT's editorial and graphic standards, just as printed publications are subject to these same standards. WebWeb Publishing Guidelines, approved by the IRC, assist WebWeb authors in preparing materials that meet those standards.
Each Vice President, or the President in the case of those areas that do not report to a Vice President, is the ""owner"" of the official information that is created or maintained by his/her area of responsibility. An "owner" is defined by Texas Administrative Code regarding Information Security Standards (TAC 1.10.202).as "a person responsible for a business function; and for determining controls and access to information resources supporting that business function. " (Texas Department of Information Resources. Information ( - I 1 TAC TAC202(C)201.13(b)G.3, Information Security Standards, Adopted August 13, 1998.) The owner of an official WebWeb document is the person responsible for overseeing the management of that official information. Each Vice President may delegate the management of this official information to department heads, deans, or directors, as appropriate. Only the owners of information, or their designated information managers, may change the content of the information that they manage. Owners must routinely review the official information placed on the WebWeb by their staff to ensure its timeliness and accuracy.
Any UNT WebWeb document may provide access to any official UNT information that is on the WebWeb, but this should be accomplished by a link to the information, rather than a duplicate copy of that information. In other words, managers of WebWeb documents should not duplicate information that they do not manage, but instead should refer the reader to the original copy.
Maintenance of Official Information
Owners of official information will identify the information managers who will implement information services within the UNT WebWeb structure, determining how their information maintenance needs can best be met within existing resources. These individuals must follow the standards and procedures developed by the IRC for the University's WebWeb implementation.
Registration of UNT Web Sites
In order to ensure that Web sites and webWeb applications developedcreated by UNT departments or external vendors are developed and maintained in conformance with UNT, state and federal policies and guidelines, each UNT webWeb major site (such as one for a college or school , or administrative department, center, or academic department) that is maintained at UNT must be registered. New and redesigned webWeb sites (including those created by external vendors) must be registered and conform to UNT policies and guidelines before they are made public.
For the purpose of webWeb site registration, a webWeb site is defined as any key entry point or destination on the unt.edu domain (or that is hosted on UNT webWeb servers) that has its own home page (index page), unique webWeb address, distinct business function, or a navigational structure that differs from its parent site (such as an academic department’s webWeb site that is a part of a college or school parent site).
Besides compliance, the registration of all UNT webWeb sites and webWeb applications will allow departments responsible for webWeb oversight to quickly communicate policy changes, educational resources, new and updated webWeb resources, and other key issues to the webWeb developer community. A webWeb site registry also enables:
Maintenance of a comprehensive directory on the main UNT Web site by the webWeb site URCM’s Office of Online Communications.
Monitoring of web standards by the URCM’s Office of Online Communications.
Periodic security-related monitoring, auditing and response by the Computing and Information Technology Center (CITC).to be maintained by the Office of Online Communications in URCM.
Registration includes providing and the name, phone number, and e-mail address of the Web administrator for the site updated annually the name and contact information of the:
·
Primary webWeb developer - – responsible for the creation and updating of webWeb pages or the development of forms or applications on a webWeb site.;·
Information manager (referred to as the data custodian in security contexts) - department heads, deans, or directors, as appointed by their vice president (or president in the case that the area does not report to a vpvice president), responsible for the supervision of developer(s) and the management of information and resources for a webWeb site.·
Information owner (referred to as data owners in security contexts) -, the UNT vice president (or president in the case that an area does not report to a vpvice president) ultimately responsible for the site’s information, purpose or data collected in support of business functions in their area.In addition, any Web page on a UNT Web site that collects personally identifiable information of any type must be registered separately before it is made available to the public. Though it is the primary responsibility of the webWeb developer, information manager and information owner to make sure that the information collection and storage procedures meet UNT, state and federal requirements, the registration of each form can assist the universityUNT in performing audits and programmatic checks.
Registration of sSites, and data collection pages willmust consist ofbe registered via a Web form that is availablelocated at the the http://www.unt.edu/webWebinfo site. HYPERLINK "http://www.unt.edu/webinfo" http://wwww.unt.edu/webinfo Web site New webWeb sites that have not registered or that do not meet UNT webWeb policies or guidelines can be denied UNT webWeb resources, have their public launch suspended, or have vendor payments delayed until the requirements are met. Sites and pages that already exist when this policy is adopted must be registered within 60 days of the adoption of the policy. The information for each registered site or webWeb application must be updated annually.
Security of UNT Web Sites
All WebWeb sites at UNT will conform to the Texas Administrative Code regarding Information Security Standards (TAC 1.10.202).
All Web sites at UNT will conform to the HYPERLINK "http://info.sos.state.tx.us/pls/pub/readtac$ext.TacPage?sl=R&app=9&p_dir=&p_rloc=&p_tloc=&p_ploc=&pg=1&p_tac=&ti=1&pt=10&ch=206&rl=73" State of Texas rule for protecting the security of information, TAC I.10.206.73..
Legal and Intellectual Property Responsibility
Persons responsible for WwebWeb development are required to adhere to all applicable state and federal regulations and internal policies and guidelines associated with security, risk measures, and copyright compliance. Permission from the copyright owner must be obtained in advance before publishing copyrighted material (text, graphics, etc.) on UNT WebWeb sites and notification of copyright should be shown on pages containing those materials.
Privacy Statement
All UNT Wwweb sites must provide a privacy statement on their top-level webWeb page (also called home or index pages). Each privacy statement must identify the information collected from site visitors, describe its use, and assure site visitors of the integrity of their information during transmission and storage.
In addition, each webWeb form or webWeb application that collects data must also include a link to a privacy statement. The privacy statement can be linked to the same privacy statement on the site’s home page if the security mechanisms, information collected, and intended usage is the same. Otherwise, a new privacy statement should be crafted for each form or webWeb application within a site.
Privacy Notice
Each privacy statement must identify both passive and active information collected from site visitors and describe its use. Passive information is collected without alerting the site visitor. Active information is purposely provided by the site visitor.
Examples of passive information include:
·
Bbrowser detection: browser type and browser version·
Rremote host name: the DNS entry for the computer accessing the webWeb site·
Ccookies: hidden identifiers used to store data during a visit, and cumulatively over timeExamples of active information include:
·
nName of the site visitor·
Eemail address of the site visitor·
Ccomments or answers to questions provided by the site visitorSecurity of Private Information
Each Security of Private Information
Each webWeb site at UNT will assure site visitors of the integrity of their information, in transit and in storage. This assurance should include whether or not the data is encrypted in transit via Secure Socket Layers (SSL) or Transport Layer Security (TLS), the positions or UNT employees that will be able to access the information, and under what conditions that information will be accessed.
Because tThe University has special responsibilities to protect students’ information under the Family Educational Rights and Privacy Act (FERPA,). any dDepartments with a university Web site collecting (e.g., via the webWeb), storing (e.g., in a database), using (e.g., sharing with other departments and organizations), and expiring (e.g., deleting) information collecting data falling under FERPA guidelines must periodically and carefully review data handling procedures (collection, storage, use, retirement) to ensure full compliance with any and all related laws such as (but not limited to) FERPA, Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), and Texas Public Information Act.its handling of such data and einsure that its procedures adhere to the act. In addition, departments must insure that the collection of other protected information, such as financial or health information (addressed by the Gramm-Leach-Bliley Act) is accorded the level of protection that ensures the privacy of persons providing that information.
Commercial Sales, Solicitations and Advertisements Via University Department or
Organization WebWeb Pages
AllPages
All commercial sales, solicitations or advertisements by University departments on University webWeb sites must reflect the mission and purpose of the University and follow its contract policy. Unless the sale is of products produced by academic or administrative departments within the University (such as College of Music CD’s,) a formal contract between the commercial organization and the University must be in place before a sale, solicitation, or advertisement is published on a University WebWeb page.
Unauthorized solicitations by individuals for commercial or personal gain are prohibited.
Student organizations, the alumni association, the UNT Foundation, and other affiliated or outside organizations with webWeb pages hosted by the University must receive written permission from the Provost and Vice Presidents forof Academic Affairs and the Vice President of Finance and Business AffairsVice President for University Relations, Communications and Marketing (or the appointed designee) before posting advertising or solicitations. Such advertising or solicitations must have a demonstrable benefit to the university for approval.
Unauthorized solicitations by individuals for commercial or personal gain are prohibited.
Corporate logos and external links advertising products may not exceed 10% of any Wweb page as viewed on a single computer screen unless an exemption to this rule is specifically approved by the Vice President for University Relations, Communications and Marketing (or the appointed designee)ither the Vice President s of Academic Affairs and or the Vice President of Finance and Business Affairs.
Exemptions to the restrictions regarding the use of corporate logos and/or advertising may be made in designing university WebWeb sites that provide links to free software downloads that provide necessary functionality for viewing WebWeb content, such as Adobe Acrobat files and RealVideo streaming video files.
Accessibility, WebWeb Page Standards, HTML Coding Requirements, and Common Links to Information and Resources
UniversityResources
University WebWeb pages must conform to all University of North Texas WebWeb design, coding and accessibility policies which are available at: http://www.unt.edu/webWebinfo HYPERLINK "http://wwww.unt.edu/webinfo" http://wwww.unt.edu/webinfo.
Sanctions for Policy Violations
·
UNT may delay deployment of new Web sites, suspend developer Web site access, limit or eliminate Web resource privileges, and/or delay vendor payments.·
Penalties for violation of this policy may range from loss of computer resource usage privileges to dismissal from the University, prosecution, and/or civil action. Each case will be determined separately on its merits. Referrals for legal action will be made through the Office of the Vice Chancellor and General Counsel.·
If the offender is a faculty member, the procedures to be followed are those specified in accordance with the UNT’s "Faculty Discipline" policy HYPERLINK "http://www.unt.edu/policy/UNT_Policy/volume3/15_1_33.html" UNT Faculty Discipline Policy (Policy 15.1.33).·
If the offender is a staff member, the procedures to be followed are those specified in the UNT’s "Performance Counseling and Discipline" policyHYPERLINK "http://www.unt.edu/policy/UNT_Policy/volume1/1_7_1.html" Performance Counseling and Discipline Policy (Policy 1.7.1.1).·
If the offender is a student, the procedures to be followed are those specified in the UNT’s "Code of Student Conduct and Discipline" policyHYPERLINK "http://www.unt.edu/csrr/cat_of_misconduct.htm"Code of Student Conduct. If the student in violation of this policy is also an employee of the University, sanctions may include termination of employment.·
Penalties for violation of this policy range from loss of computer resource usage privileges to dismissal from the University, prosecution, and/or civil action.·
If the offender is a faculty member, the procedures to be followed are those specified in accordance with the HYPERLINK "http://www.unt.edu/policy/UNT_Policy/volume3/15_1_33.html"UNT Faculty Discipline Policy (Policy 15.1.33.)·
If the offender is a staff member, the procedures to be followed are those specified in the HYPERLINK "http://www.unt.edu/policy/UNT_Policy/volume1/1_7_1.html"Performance Counseling and Discipline Policy (Policy 1.7.1.)If the offender is a student, the procedures to be followed are those specified in the HYPERLINK "http://www.unt.edu/csrr/cat_of_misconduct.htm"Code of Student Conduct. If the student in violation of this policy is also an employee of the University, sanctions may include termination of employment.