MURDOCH     INDEX     SEARCH     PEOPLE  
Policies Index >>  Facilities & Services >>  Information Technology >> 

MurdochNet Policy

Section 1: PREAMBLE
Section 1.1: Purpose
Section 1.2: Scope
Section 1.3: Field of Application
Section 1.4: Policy Vocabulary
Section 1.5: Key Terms
Section 2: INTRODUCTION
Section 2.1: Goals
Section 2.2: Boundary of MurdochNet
Section 2.3: Environment of MurdochNet
Section 3: CODE OF CONDUCT
Section 3.1: Servers
Section 3.2: Content
Section 3.3: Links
Section 3.4: Misconduct
Section 4: SERVER MANAGEMENT
Section 4.1: Registration of Web Servers
Section 4.2: Murdoch Sub-domains
Section 4.3: Alternate Domain Names
Section 4.4: Naming Conventions for Web Servers
Section 4.5: Availability of Web Servers
Section 4.6: Security of Web Servers
Section 4.7: Backup (Hardware, Software, Data) of Web Servers
Section 4.8: Web Server Software
Section 4.9: Responsibility for Web Servers
Section 5: CONTENT MANAGEMENT
Section 5.1: Content Categories
Section 5.2: Content Management Procedures & Practices
Section 5.3: Standards & Guidelines for Content Preparation
Section 5.4: Murdoch Conventions for Content Preparation
Section 5.5: Murdoch Guidelines for Content Preparation
Section 5.6: Applications & Tools
Section 5.7: Responsibility for Content
Section 6: LINK MANAGEMENT
Section 6.1: Permissible Links
Section 6.2: Link Validation & Checking
Section 6.3: Link Revision & Relocation
Section 6.4: Responsibility for Registered Links
Section 7: Glossary of MurdochNet Terminology
: SCHEDULES
Schedule 1: Forms
Schedule 2: Contracts
Schedule 3: Guidelines
Schedule 4: Regulations
Schedule 5: Disclaimers
Schedule 6: Roles & Responsibilities

Section 4 SERVER MANAGEMENT

Section 4.6 Security of Web Servers

The following recommendations and requirements for the management of Web Servers are intended to facilitate compliance with the University’s IT Security Policy.

It is recommended that an organisation unit or resource area concerned about the security of any of the following:

(a) the computer (eg. the operating system) that runs their Web Server

(b) the Web Server software

(c) a software application that uses the Web Server

(d) Content hosted by the Web Server

should seek advice from the IT Security Manager (Office of Information Technology Services).

A Web Administrator may also refer to the Australian Communications Electronic Security Instruction 33 (ASCI-33). Handbook 10 – Web Security.

Section 4.6.1: Internet Accessible Subnet
Section 4.6.2: TCP / IP Ports and the Management of HTTP & HTTPS Requests
Section 4.6.3: Physical Security of Computers Used to Run Web Servers
Section 4.6.4: Security Guidelines for Computers Used to Run Web Servers
Section 4.6.5: Security Audits of MurdochNet Servers & Affiliated Web Servers
Section 4.6.6: Responsibility for the Security of Web Servers
Section 4.6.6.1: Divided Responsibilities for the Security of Web Servers
Section 4.6.7: Authorised Access to Web Servers
Section 4.6.7.1: Content Publishing Authorisation
Section 4.6.7.2: Appropriate Access to Content