Any new and existing official University-level website/web resource must be approved by the Division of Strategic Communications and follow the Brand Guidelines, Web Developer Guidelines, and all applicable University policies.
Requirements
Mandatory requirements in this policy apply to all official University websites. Unofficial websites are not covered by these requirements, but should always comply with all applicable campus, state and federal policies, laws and regulations, including, but not limited to, any addressing compliance, copyright, accessibility, privacy and website security.
- Brand Guidelines and Web Development Guidelines: Every official University website must comply with the Brand Guidelines and Web Developer Guidelines, which specifically address the required visual and technical details to achieve compliance.
- University Framework: In order to ensure compliance with this policy, all official University websites must use the official University framework developed by UMC Web Strategy and detailed in the Web Developer Guidelines.
- Ownership Information: All official University websites must clearly display ownership information on each page in the form of a contact email address belonging to the unit represented on the page. In circumstances when an email address cannot be provided, a contact name and telephone number may be substituted.
- Template: All official University websites and pages must display the official University template as provided by the Web Strategy team.
- Compliance: All websites, web resources, pages, and/or documents must be compliant with all other University policies, including and especially those related to computer use, privacy, human resources, and those outlined below.
- Copyright: All websites, web resources, pages, and/or documents must comply with the University's copyright statement.
- Accessibility: All websites, web resources, pages, and/or documents must comply with the University's Digital Accessibility Policy.
- Privacy: All websites, web resources, pages, and/or documents must comply with all applicable state and federal laws, including, but not limited to, FERPA, HIPPA, GDPR, the official University privacy statement, and any privacy policy implemented in the future by the University.
- Website Security: All websites, pages, and/or documents must comply with the security standards set by IT and any current University security policies or any security policies implemented in the future by the University.
- Links to commercial entities must be related to the University's missions of research, teaching, and service and must not imply endorsement by the University.
- Content Life Cycle: As part of the University's website quality assurance, all official University websites must be reviewed by the site authorizer, at a minimum, once a year to ensure that content, mandatory requirements, accessibility, and security measures are current and in compliance with this policy.
Security Breaches and Misconduct
Any website, page, and/or document, including any unofficial University website, that displays any indication of a security risk or threat, including malicious code or inappropriate content, is subject to be taken down, removed, or blocked immediately and without any prior notice to the site authorizer.