ÎÛÎÛ²ÝÝ®ÊÓƵ
Why is this important?
Visitors need to be confident our sites are secure and their privacy is protected.
Legislation and policy
ÎÛÎÛ²ÝÝ®ÊÓƵ staff are subject to Quebec and Canadian laws and ÎÛÎÛ²ÝÝ®ÊÓƵ University’s policies concerning information security and maintaining the confidentiality of personal information.
In addition, anyone who processes, transmits or stores credit cards information in an unsecure and unauthorized manner may be found in violation of financial confidentiality laws and expose themselves to legal liability. If you need to collect payment, please get in touch with Financial Services.
Christopher Manfredi, Provost and Vice-Principal Academic, describes the responsibility of all academics to uphold ÎÛÎÛ²ÝÝ®ÊÓƵ's information security
Visit ÎÛÎÛ²ÝÝ®ÊÓƵ’s cybersecurity websiteÌýSecure your journeyÌýfor additional tools and resources.
Checklist of things to do
- Create secure webpages and webforms that properly protect users' personal data (e.g. use secure formats and platforms like https, adhere to recommendations for building secure webforms)
- Don't display or email people's confidential information (unless it's using ÎÛÎÛ²ÝÝ®ÊÓƵ's official email).
- Don't identify student names without their written consent, e.g. on Research web pages, do not list student participants.
- Don't share sensitive or restricted data on unauthorized generative AI tools.
- Microsoft Copilot is currently the only authorized generative AI tool at ÎÛÎÛ²ÝÝ®ÊÓƵ. Refer to the to learn what is acceptable and not acceptable to enter into a prompt.
- If you become aware of unsafe practices or vulnerabilities, .
- Keep web systems and tools up to date.
- Ensure your site has a designated sponsor/asset steward.
- Delete/decommission websites when they become inactive and/or are no longer of value.
- Update website access permissions accordingly when your web team members change roles, leave your department or leave the university.
- Use ÎÛÎÛ²ÝÝ®ÊÓƵ usernames and passwords for authentication on ÎÛÎÛ²ÝÝ®ÊÓƵ websites and systems (where possible).
- If authentication is required on ÎÛÎÛ²ÝÝ®ÊÓƵ websites, it should be performed using one of our preferred Single Sign On (SSO) methods, such as SAML, Ìýwith ÎÛÎÛ²ÝÝ®ÊÓƵ’s central identity provider.
- Limit data collection for analytics and user research to interactions around links, buttons and page elements only.
- If linking to information in a cloud service, adhere to instructions in ÎÛÎÛ²ÝÝ®ÊÓƵ's Cloud Directive which describes when and where you can process, transmit and storeÌýÎÛÎÛ²ÝÝ®ÊÓƵ data
Supporting resources
Related sites
How to create secure webforms
Ìý
Privacy and security policies and guidelines
ÎÛÎÛ²ÝÝ®ÊÓƵ policies and guidelines site owners and managers should be aware of.
Use of information technology
- Policy on the Responsible Use of Information Technology at ÎÛÎÛ²ÝÝ®ÊÓƵ, IT Services
- IT Policies, Directives, Regulations and Standards
- IT Security Incident Response
- Guide to secure web service/servers
- Cloud Services at ÎÛÎÛ²ÝÝ®ÊÓƵ - When acquiring or using a new software app, here's what you need to know...
- Domains and URLs for ÎÛÎÛ²ÝÝ®ÊÓƵ websites
Privacy and personal information
- Cloud Services at ÎÛÎÛ²ÝÝ®ÊÓƵ
- Guidance for safe use of cloud applications at ÎÛÎÛ²ÝÝ®ÊÓƵ
- Information Security Reminder, Enrolment Services
- Information security, IT Services
- IT Governance - Data Classification Document from the Secretary General
- ÎÛÎÛ²ÝÝ®ÊÓƵ's Cloud Directive
- Privacy Notice, ÎÛÎÛ²ÝÝ®ÊÓƵ University
- Protection of Personal Information, Student Rights and Responsibilities