![]() |
![]() |
||||
|
|
|
Requirements to Coordinate Acquisition, Authentication and Security for Online Services to the University Community Which Are Hosted Either On Campus or Off CampusAudience:This policy applies to any members of the University community who provide personalized or authenticated online services where:
Definition:Host – a computer or cluster of computers that deliver an online service to the University community. Administration – An individual administers a host when he or she has primary, day-to-day, super-user privileges which grant him or her means to control the services on the host and to bypass security measures on the host. On-campus host – a host which is located logically within the University IP networks and is administered only by University employees. Mixed host – a host which is located logically within the University IP networks but is administered by an ASP with or without assistance from University employees. Off-campus host – a host which is located logically outside of the University IP networks, regardless of its administration by University employees or an ASP. Application Service Provider (ASP) – a company which, under contract, uses off-campus hosts or mixed host solutions to deliver an online service.
Sensitive information – personally-identifiable data which the University treats as internal and not public, or which is classified as protected under regulations. All sensitive information is administered by the University through a data steward.
Statement:All online services to the University community must be reviewed and approved by the Vice President for Information Technology under the Policy for Information Technology Acquisition, Development and Deployment. Authentication
Security
Notice of Right to Refuse Services and Block Implementation
Background Issues:Services may be delivered to the University community from mixed host or off-campus host configurations only upon the prior approval of NUIT under the Policy for Information Technology Acquisition, Development and Deployment. A portion of that approval process will include review of what University data is to be exposed to the ASP and stored at the ASP. Information exposed to or stored by the ASP must be limited to information about only those persons who are actually using the service. This requires the ASP to employ “first-access provisioning” when a new user accesses the service. The University will not supply the ASP with a list of all possible users of the service. Authentication to the service should use existing University credentials (NetID and other factors). For on-campus or mixed host configurations, this will use the Northwestern Web SSO facility via Web server plug-in software and appropriate credentials issued by NUIT. For off-campus host configurations, this will use federated authentication or Web-proxy. Note that Web-proxy authentication does not provide attribute information about the user other than NetID. Federated authentication can pass additional attributes as agreed between the University and the ASP in the service contract. Access to any user attributes must be reviewed and approved by the relevant data steward and NUIT through current administrative processes. Off-campus host configurations cannot access Northwestern information based in LDAP, Active Directory, or Kerberos authentication services. Therefore, additional attribute information, such as name or e-mail address, cannot be retrieved except through federated authentication protocols. The requirements set forth in this policy should be conveyed to potential vendors while investigating possible solutions so that those vendors may propose any necessary costs for compliance as a portion of the project expense. Any cost of compliance with this policy is borne by the service provider. This could include:
Service providers should minimize these costs by including NUIT in conversations with prospective vendors, conveying this policy to the vendors, and incorporating this policy in any contract. Original Issue Date: December 2006
Related Policies:
Policy for Information Technology Acquisition, Development and Deployment
|
|||||
Last Updated: 30 May 2007 |
![]() |
Services |
Get Connected |
Support |
Academic Resources |
About NUIT
|
|