External visibility of web servers

This information is for members of the University who wish to apply for the contents of a web server to be viewable through the firewall to external users.

Decision Process

An initial decision will be made by the Assistant Director (Infrastructure), or the Faculty IT Manager (or their nominees) in discussion with the requestor. IT Services reserves the right to refuse external access to a server if it determines that proposed service would be more suitably hosted on an alternative external system or that providing such access would compromise the Information Security of the University.

In the event that agreement cannot be reached, the decision of the Director of Information Services will be final.

Responsibility for Content

While everyday responsibility for the content of web servers may well be delegated to server managers and their equivalents in different areas of the University, formal responsibility must lie with those in the appropriate positions of authority. In the following situations, the 'responsible person' is identified as:

Heads of Academic and Administrative Departments responsible for information held in Departmental Web pages or on Departmental Web servers

Directors (or equivalents) of Research Centres, Units, Commercial Subsidiaries, etc. responsible for information held in the organisation's Web pages or on its own Web servers

Chairs (or equivalents) of student organisations and societies responsible for information held in the organisation's Web pages or on the organisation's Web servers

Individual Members of Staff responsible for information held in their personally owned user Web areas

Individual Students responsible for information held in their personally owned user Web areas

Others - a member of the University must be nominated as responsible for any Web information not covered by the above five categories

These persons need to be aware of their position of responsibility in relation to the provision of Web material. The form requires a signature both from the responsible person and from the server manager.

The server must include a link to the University’s official disclaimer on the home page of every site hosted on it.

Security and Withdrawal of Access

IT Services reserves the right to withdraw external access to any machine, without notice, under the following circumstances:

  • to protect the University's network and/or servers
  • to prevent the University's systems being used to attack/disrupt other sites or systems
  • if any web site hosted on the server is in breach of University regulations

IT Services reserves the right to test the security of the web system at any time, using either automatic tools or manual testing.