MURDOCH     INDEX     SEARCH     PEOPLE  
Policies Index >>  Facilities & Services >>  Information Technology >> 

MurdochNet Policy

Section 1: PREAMBLE
Section 1.1: Purpose
Section 1.2: Scope
Section 1.3: Field of Application
Section 1.4: Policy Vocabulary
Section 1.5: Key Terms
Section 2: INTRODUCTION
Section 2.1: Goals
Section 2.2: Boundary of MurdochNet
Section 2.3: Environment of MurdochNet
Section 3: CODE OF CONDUCT
Section 3.1: Servers
Section 3.2: Content
Section 3.3: Links
Section 3.4: Misconduct
Section 4: SERVER MANAGEMENT
Section 4.1: Registration of Web Servers
Section 4.2: Murdoch Sub-domains
Section 4.3: Alternate Domain Names
Section 4.4: Naming Conventions for Web Servers
Section 4.5: Availability of Web Servers
Section 4.6: Security of Web Servers
Section 4.7: Backup (Hardware, Software, Data) of Web Servers
Section 4.8: Web Server Software
Section 4.9: Responsibility for Web Servers
Section 5: CONTENT MANAGEMENT
Section 5.1: Content Categories
Section 5.2: Content Management Procedures & Practices
Section 5.3: Standards & Guidelines for Content Preparation
Section 5.4: Murdoch Conventions for Content Preparation
Section 5.5: Murdoch Guidelines for Content Preparation
Section 5.6: Applications & Tools
Section 5.7: Responsibility for Content
Section 6: LINK MANAGEMENT
Section 6.1: Permissible Links
Section 6.2: Link Validation & Checking
Section 6.3: Link Revision & Relocation
Section 6.4: Responsibility for Registered Links
Section 7: Glossary of MurdochNet Terminology
: SCHEDULES
Schedule 1: Forms
Schedule 2: Contracts
Schedule 3: Guidelines
Schedule 4: Regulations
Schedule 5: Disclaimers
Schedule 6: Roles & Responsibilities

Section 4 SERVER MANAGEMENT

Section 4.6 Security of Web Servers

Section 4.6.5 Security Audits of MurdochNet Servers & Affiliated Web Servers

It is recommended that Central MurdochNet Servers should be audited at appropriate intervals to ensure that the security set up of operating system and Web Server software meets the Security Guidelines for Computers Used to Run Web Servers.

MurdochNet Servers and Affiliated Web Servers that have been authorised to perform the role of Internet Content Host shall be audited for security if they are using IP addresses outside an Internet Accessible Subnet (IAS).

A security audit shall be carried out at appropriate intervals to review the security set up of operating system and Web Server software to ensure that it meets the Security Guidelines for Computers Used to Run Web Servers.

Security audits shall be shall be conducted in consultation with either the Web Administrator responsible for the Server, or the person responsible for IT management in the organisation unit or resource area that runs the Server.

Security audits shall be undertaken by the authorised nominee of the Director of the Office of Information Technology Services (eg. the IT Security Manager), or by an external agency appointed by either the Director of the Office of Information Technology Services, or Internal Audit and Risk Management, should a situation arise that requires it.

In cases where the security audit establishes security violations have occurred on a computer that runs a Web Server, the University’s IT Security Manager shall take appropriate steps as required by the University’s IT Security Policy.