Regulations for web projects
Web projects are subject to the following rules:
- The ITCC must always be informed of both the technical contact person and the person with overall responsibility for the project. If there are changes in responsibilities for TYPO3 projects, please contact TYPO3master. For other web projects, automatic lists of users with write permissions are maintained and posted in the information channels. If no one has write permissions for a web project, we reserve the right to deactivate the project.
- If you use software from a third-party source (for example Wordpress, phpBB), you have the obligation to install independently the latest security updates. This rule applies furthermore to installed extensions.
- Therefore, check at least every week if any security updates are available for the software in use. We recommend you to subsribe to a news outlet (like a newsletter or social media feed) to learn about important software updates as soon as they are realeased.
- For projects that use the WordPress CMS, the use and activation of Wordfence via a license provided by ITCC is mandatory.
- Scripts must not impair intentionally or gross negligently other projects.
- Any activities that could lead to a surge in visitors must be avoided. This includes course and event registrations with limited capacity and high demand. Event registrations must be processed through KLIPS. In the event of excessive traffic, the ITCC reserves the right to take websites offline to protect other services.
- The ITCC cannot fully guarantee that the stored data is protected from unauthorized access. (This would require a separate server for exclusive use.)
- Write permission on the web servers is only adjusted selectively for AFS- and NFS-projects.
- The ITCC is not liable for programming errors of persons involved in the project.
- The provided scope of a project must only be used for the purposes of the respective facility. Content of private nature is not permitted.
- Make sure that you comply with copyright and other regulations regarding the provided contents.
- It is prohibited to circumvent security measures installed by the ITCC. If you find a security breach, please get in touch with the ITCC immediately. Taking advantage of a loophole (even for test purposes) can result in the immediate deactivation of the project and/or the account.
- The GDPR and other data protection regulations must be observed. In the event of intentional or negligent non-compliance, the ITCC will first issue a warning. If there is no prompt response to a second warning, the university’s data protection officer will be notified of the violation.
This also applies to the collection of sensitive data using tools unsuitable for this purpose, such as TYPO3 Powermail for personal data and documents (upload). The ITCC reserves the right to delete data in critical cases to prevent unauthorized access by third parties.
The ITCC reserves the right to remove the project at least temporary from the network in case of non-compliance.