Revision by System
July 30, 2026 — 7:17 PM — compared to revision from Nov. 23, 2025
Content Diff
Added
Removed
---
+++
{
"pk": 244,
- "body": "[{\"type\": \"paragraph\", \"value\": \"<p>The EUS IT Committee recommends the following best practices\\r\\nregarding internal security.</p>\\r\\n<h2 id=\\\"google_passwords\\\">Google Passwords</h2>\\r\\n<p>All EUS e-mails go through the <a href=\\\"G_Suite\\\" class=\\\"wikilink\\\"\\r\\ntitle=\\\"G Suite\\\">G Suite</a>, which has the advantage of having a good\\r\\ndefault level of security. It is, however, recommended to enable <a\\r\\nhref=\\\"https://www.google.ca/landing/2step/\\\">two-factor\\r\\nauthentication</a> for the highest level of security, depending on how\\r\\nsensitive the e-mails your EUS account receives are.</p>\\r\\n<p>As a general guideline, all EUS e-mails get their passwords\\r\\nautomatically reset every year over the summer, to ensure that retired\\r\\nEUS members lose access to their accounts.</p>\\r\\n<h3 id=\\\"account_recovery\\\">Account Recovery</h3>\\r\\n<p>To gain access to your account, simply e-mail <a href=\\\"IT_Director\\\"\\r\\nclass=\\\"wikilink\\\"\\r\\ntitle=\\\"it.director@mcgilleus.ca\\\">it.director@mcgilleus.ca</a> using a\\r\\npersonal e-mail account. Ensure that your personal e-mail accounts is\\r\\nlisted in the <a href=\\\"Directory\\\" class=\\\"wikilink\\\"\\r\\ntitle=\\\"EUS Directory\\\">EUS Directory</a>. If you are part of a club or\\r\\ndesign team, it's possible that not all members appear in the EUS\\r\\nDirectory; in this case, please ask the president of your club or design\\r\\nteam to request the reset.</p>\\r\\n<h2 id=\\\"web_services_connection_strings\\\">Web Services Connection\\r\\nStrings</h2>\\r\\n<p>Our web services may require a number of connection strings. These\\r\\nusually include usernames & passwords to databases, passwords or\\r\\nsecret keys to external <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Web_API\\\">API's</a>, etc. Given that\\r\\nmultiple web services tend to be shared by the same server and that our\\r\\nweb services are starting to be placed on <a\\r\\nhref=\\\"https://github.com/\\\">Github</a>, it is ideal to have these\\r\\nconnection strings passed as environment variables. You may keep a file,\\r\\nwith \\\"reading\\\" rights restricted only to your user, storing the actual\\r\\nvalues of these environment variables for future reference.</p>\\r\\n<h2 id=\\\"backups\\\">Backups</h2>\\r\\n<p>It is ideal to have regular backups of web servers to ensure that,\\r\\nshould a security breach occur through malware, we can safely wipe the\\r\\naffected server and create a clean new one.</p>\\r\\n<h2 id=\\\"folder_permissions\\\">Folder Permissions</h2>\\r\\n<p>Folder permissions should be as restrictive as possible. For example,\\r\\ngiving <em>777</em> or <em>a+rwx</em> or <em>Read, Write, Execute</em>\\r\\npermissions to all users for a given file is to be avoided. The general\\r\\nrule for a folder on our servers are:</p>\\r\\n<ul>\\r\\n<li>Folders and files should be owned by the official owner. This means\\r\\nthat <em>webmaster</em> shouldn't be the owner of the folder containing\\r\\nthe <a href=\\\"Ledger\\\" class=\\\"wikilink\\\" title=\\\"ledger\\\">ledger</a>'s\\r\\nwebsite;</li>\\r\\n<li>Folders and files should be under the group <em>eusit</em>;</li>\\r\\n<li>Folders and files should at least be given all permissions for the\\r\\nowner;</li>\\r\\n<li>Depending on the nature of the folder of file, the group\\r\\n<em>eusit</em> may also have read, write or execute permissions;</li>\\r\\n<li>All users should <strong>at most</strong> be given <em>Read,\\r\\nExecute</em> permissions, but <strong>not</strong> <em>Write</em>.</li>\\r\\n</ul>\\r\\n<h2 id=\\\"wordpress\\\">Wordpress</h2>\\r\\n<p>Wordpress plugins tend to be <a\\r\\nhref=\\\"https://www.elegantthemes.com/blog/tips-tricks/how-malware-really-affects-your-wordpress-website\\\">susceptible\\r\\nto malware</a>. For this reason, the EUS has moved towards our own <a\\r\\nhref=\\\"https://github.com/McGillEUS/EUS-Templates\\\">EUS Templates</a>, in\\r\\nan effort to build our own <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Content_management_system\\\">content\\r\\nmanagement system</a>. The issues that can arise with Wordpress are due\\r\\nto its complexity: although it provides a nice interface for users to\\r\\nlog-in and edit their web pages, it also exposes a server or a web\\r\\nservice to more vulnerabilities than a simple <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Static_web_page\\\">static web\\r\\npage</a>.</p>\\r\\n<p>There is not much to do in this regard other than being careful with\\r\\nwhat Wordpress plugins are downloaded for pages which absolutely must\\r\\nuse Wordpress. It seems like Wordpress is making efforts to remain as\\r\\nsecure as possible, therefore updating the Wordpress distributions to\\r\\nthe latest possible is ideal.</p>\\r\\n<p>For pages which are very simple (i.e.: typical club/design team/event\\r\\ninformation pages), it is recommended to opt for a simple <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Static_web_page\\\">static web page</a>\\r\\nrather than Wordpress or other content management services.</p>\\r\\n<h2 id=\\\"security_certificates\\\">Security Certificates</h2>\\r\\n<p>The EUS has access to security certificates ensuring our pages can be\\r\\naccessed through <em>HTTPS</em>. These must be kept valid and\\r\\nup-to-date.</p>\\r\\n\", \"id\": \"5f0b42d7-4a07-48a8-a44f-60b006eacd03\"}]",
+ "body": "[{\"id\": \"5f0b42d7-4a07-48a8-a44f-60b006eacd03\", \"type\": \"paragraph\", \"value\": \"<p>The EUS IT Committee recommends the following best practices\\r\\nregarding internal security.</p>\\r\\n<h2 id=\\\"google_passwords\\\">Google Passwords</h2>\\r\\n<p>All EUS e-mails go through the <a href=\\\"G_Suite\\\">G Suite</a>, which has the advantage of having a good\\r\\ndefault level of security. It is, however, recommended to enable <a\\r\\nhref=\\\"https://www.google.ca/landing/2step/\\\">two-factor\\r\\nauthentication</a> for the highest level of security, depending on how\\r\\nsensitive the e-mails your EUS account receives are.</p>\\r\\n<p>As a general guideline, all EUS e-mails get their passwords\\r\\nautomatically reset every year over the summer, to ensure that retired\\r\\nEUS members lose access to their accounts.</p>\\r\\n<h3 id=\\\"account_recovery\\\">Account Recovery</h3>\\r\\n<p>To gain access to your account, simply e-mail <a href=\\\"IT_Director\\\">it.director@mcgilleus.ca</a> using a\\r\\npersonal e-mail account. Ensure that your personal e-mail accounts is\\r\\nlisted in the <a href=\\\"Directory\\\">EUS Directory</a>. If you are part of a club or\\r\\ndesign team, it's possible that not all members appear in the EUS\\r\\nDirectory; in this case, please ask the president of your club or design\\r\\nteam to request the reset.</p>\\r\\n<h2 id=\\\"web_services_connection_strings\\\">Web Services Connection\\r\\nStrings</h2>\\r\\n<p>Our web services may require a number of connection strings. These\\r\\nusually include usernames & passwords to databases, passwords or\\r\\nsecret keys to external <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Web_API\\\">API's</a>, etc. Given that\\r\\nmultiple web services tend to be shared by the same server and that our\\r\\nweb services are starting to be placed on <a\\r\\nhref=\\\"https://github.com/\\\">Github</a>, it is ideal to have these\\r\\nconnection strings passed as environment variables. You may keep a file,\\r\\nwith \\\"reading\\\" rights restricted only to your user, storing the actual\\r\\nvalues of these environment variables for future reference.</p>\\r\\n<h2 id=\\\"backups\\\">Backups</h2>\\r\\n<p>It is ideal to have regular backups of web servers to ensure that,\\r\\nshould a security breach occur through malware, we can safely wipe the\\r\\naffected server and create a clean new one.</p>\\r\\n<h2 id=\\\"folder_permissions\\\">Folder Permissions</h2>\\r\\n<p>Folder permissions should be as restrictive as possible. For example,\\r\\ngiving <em>777</em> or <em>a+rwx</em> or <em>Read, Write, Execute</em>\\r\\npermissions to all users for a given file is to be avoided. The general\\r\\nrule for a folder on our servers are:</p>\\r\\n<ul>\\r\\n<li>Folders and files should be owned by the official owner. This means\\r\\nthat <em>webmaster</em> shouldn't be the owner of the folder containing\\r\\nthe <a href=\\\"Ledger\\\">ledger</a>'s\\r\\nwebsite;</li>\\r\\n<li>Folders and files should be under the group <em>eusit</em>;</li>\\r\\n<li>Folders and files should at least be given all permissions for the\\r\\nowner;</li>\\r\\n<li>Depending on the nature of the folder of file, the group\\r\\n<em>eusit</em> may also have read, write or execute permissions;</li>\\r\\n<li>All users should <strong>at most</strong> be given <em>Read,\\r\\nExecute</em> permissions, but <strong>not</strong> <em>Write</em>.</li>\\r\\n</ul>\\r\\n<h2 id=\\\"wordpress\\\">Wordpress</h2>\\r\\n<p>Wordpress plugins tend to be <a\\r\\nhref=\\\"https://www.elegantthemes.com/blog/tips-tricks/how-malware-really-affects-your-wordpress-website\\\">susceptible\\r\\nto malware</a>. For this reason, the EUS has moved towards our own <a\\r\\nhref=\\\"https://github.com/McGillEUS/EUS-Templates\\\">EUS Templates</a>, in\\r\\nan effort to build our own <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Content_management_system\\\">content\\r\\nmanagement system</a>. The issues that can arise with Wordpress are due\\r\\nto its complexity: although it provides a nice interface for users to\\r\\nlog-in and edit their web pages, it also exposes a server or a web\\r\\nservice to more vulnerabilities than a simple <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Static_web_page\\\">static web\\r\\npage</a>.</p>\\r\\n<p>There is not much to do in this regard other than being careful with\\r\\nwhat Wordpress plugins are downloaded for pages which absolutely must\\r\\nuse Wordpress. It seems like Wordpress is making efforts to remain as\\r\\nsecure as possible, therefore updating the Wordpress distributions to\\r\\nthe latest possible is ideal.</p>\\r\\n<p>For pages which are very simple (i.e.: typical club/design team/event\\r\\ninformation pages), it is recommended to opt for a simple <a\\r\\nhref=\\\"https://en.wikipedia.org/wiki/Static_web_page\\\">static web page</a>\\r\\nrather than Wordpress or other content management services.</p>\\r\\n<h2 id=\\\"security_certificates\\\">Security Certificates</h2>\\r\\n<p>The EUS has access to security certificates ensuring our pages can be\\r\\naccessed through <em>HTTPS</em>. These must be kept valid and\\r\\nup-to-date.</p>\\r\\n\"}]",
"live": true,
"path": "00010001006P",
"slug": "it-security",
"locked_at": null,
"locked_by": null,
"seo_title": "",
+ "side_info": "",
"go_live_at": null,
+ "side_image": null,
"draft_title": "IT Security",
- "content_type": 30,
+ "page_status": "up_to_date",
+ "website_url": "",
+ "content_type": 21,
+ "edit_summary": "Auto-fix: remove duplicate tab leftovers / broken import HTML",
+ "facebook_url": "",
"phone_number": "",
- "live_revision": null,
+ "tagged_items": [],
+ "contact_email": "",
+ "instagram_url": "",
+ "live_revision": 242,
+ "related_links": [],
"show_in_menus": false,
- "latest_revision": null,
+ "latest_revision": 242,
"translation_key": "dede55d5-35ec-4587-9f92-454b10c981f0",
- "last_published_at": null,
- "first_published_at": null,
+ "last_published_at": "2025-11-23T07:10:58.039Z",
+ "first_published_at": "2025-11-23T07:10:58.039Z",
"search_description": "",
+ "side_image_caption": "",
"address_head_office": "",
"wagtail_admin_comments": [],
"has_unpublished_changes": false,
- "latest_revision_created_at": null
+ "latest_revision_created_at": "2025-11-23T07:10:58.034Z"
}