Web Hosting (Web Publishing & cPanel) SLA 24-25


Overview

This Service Level Agreement (SLA) defines the Web Publishing service provided by the Office of Information Technology (OIT) to campus departments for an annual fee, as well as the roles and responsibilities of both parties that are needed in order to meet the defined support levels.

This SLA will remain in effect for one (1) fiscal year. The SLA may be renewed on an annual basis by mutual agreement of both parties and a new copy of the SLA will be prepared and signed. If the SLA is not renewed or payment is not received, then OIT reserves the right to revoke access and remove data. Services will not be initiated until the completed SLA is received by OIT. Modifications to an executed SLA may be made only by mutual consent of both parties. If modifications occur, a signed and dated addendum will be made to this SLA.

Service Offerings

Responsibilities of Service Agreement

As the individual or entity that has registered this website, you are responsible for:

These web services may not be used to operate your website as a course management service or a mail hosting service.

Web Publishing-Specific Terms

At some service levels, you may be permitted to activate themes and plugins that have been selected, purchased, or written by you. These themes and plugins will undergo a code review prior to installation in the Web Publishing service. However, you are still responsible for ensuring that this custom code:

cPanel-Specific Terms

You are responsible for all cPanel account maintenance:

All software installed by the customer must be maintained at the latest available version and in a secure configuration.

The cPanel administrative web interface, SSH, and FTPS interfaces require using the NCSU VPN for access.

All services hosted in cPanel should implement strong authentication, preferably using NCSU’s Shibboleth Service as it includes strong passwords and multi-factor authentication. All of our cPanel servers include a Shibboleth Service Provider that can be accessed/configured from your account using .htaccess files. More information: https://ncsu.service-now.com/sp?id=service_page&service=Shibboleth

Support Contract-Specific Terms

When customers contract OIT in the maintenance, management, and support of WordPress sites hosted with the cPanel or Web Publishing environments, OIT agrees to additionally be responsible for:

Web Content

You are responsible for the content stored within your website, as well as any content requested by and displayed on your website (e.g. an embedded YouTube video). In particular, you are responsible for ensuring that the content on your website:

If your website represents a University unit or otherwise exists to conduct official University business, you must adhere to the University’s branding guidelines or have permission from University Communications to deviate from those guidelines.

Personal Information

Your website must adhere to the University’s privacy statement. Under the University’s Data Management Procedures Regulationno purple or red data may be stored on your website.

When collecting information from your users (via form submissions, automated scripts, or other methods), you are expected to practice data minimization. Only collect the information required to fulfill your operational needs. Do not collect information that you do not need and do not store data you will not use.

You are responsible for responding in a timely manner to any requests related to personal information. This includes requests for removal of personal information from your website or systems connected to your website.

Payment Processing

The Web Publishing and/or cPanel services are NOT PCI-compliant. You are not permitted to accept, receive, or transmit any sort of payment card information through these services, nor may your site link or transmit information to a payment processor.

If you need to accept credit card information for any purpose, you are required to contact NC State Merchant Services (merchantservices@ncsu.edu) to arrange for use of the university’s e-storefront service or other Merchant Services-approved options.

Non-Compliance

Failure to fulfill your responsibilities may result in the temporary or permanent removal of your website from the Web Publishing service. OIT may temporarily suspend your website while investigating complaints related to your website.

OIT is not required to provide notice that a website has been removed, but will make a good faith effort to do so in a timely manner.

OIT’s Responsibilities

OIT will be responsible for:

OIT will not be responsible for:

OIT reserves the right to disable any services, sites or applications that are – in the opinion of the Manager of Identity & Web Services (or their designate) – misbehaving, run-away, or consuming excessive CPU resources.

Communications, questions, and requests from the Customer to OIT Web Services staff should be submitted through the IT Service Portal.

Incident Response

If the web service, or any associated applications hosted on this service, are in violation of any of the aforementioned confidentiality or PCI-related terms/conditions, or if a site is reported as hacked or defaced, OIT will take the following actions:

For reporting and help with security incidents please contact OIT Security & Compliance and follow the Cybersecurity Incident Response Procedure.

OIT reserves the right to charge the owning unit for staff hours required to repair and/or remediate accounts that have been hacked, or are in violation of terms.

Service Rates

Web Publishing Service Rates

Web Publishing supports the following service levels:

cPanel Service Rates

Support Contract Service Rates

All maintenance, management, and support of WordPress sites will be hosted within the cPanel or Web Publishing environments.