Policy on Web Governance
COMM - KB0013528
1. Purpose
This policy establishes roles and responsibilities for governance of websites within the Fermilab web presence and the minimum requirements that website owners must meet in order to make content accessible via the Fermilab web presence.[1] This policy adopts a graded approach to ensure Fermilab’s web presence supports the laboratory’s scientific mission through a consistent and current website environment that maintains the reputation of the laboratory.
This policy is not a contract and is not intended to create any obligations on Fermi Forward Discovery Group, LLC (FermiForward). This policy may be terminated or changed by FermiForward at any time, with or without notice.
2. Scope
This policy covers all websites in Fermilab-owned domains, regardless of whether hosted on servers within or outside the Fermilab network.
3. Applicability
This policy applies to all employees, users, affiliates and contractors who create or maintain websites within all Fermilab web environments.
4. Effective Date and Date Reviewed/Updated
This policy went into effect on January 1, 2025, and its latest update is effective on December 17, 2025.
5. Policy
a. Governance
Overall governance for Fermilab’s website presence resides within the Communication Division, with input from directorates, divisions, users and affiliates. Governance is more tightly controlled in areas where there is external or labwide internal exposure.
Site owners and content editors are responsible for maintaining a clear understanding of how web governance and relevant laboratory policies and procedures apply to their websites or webpages. Site owners and content editors must ensure compliance with all applicable requirements, including security, access, branding, layout, structure, style, web accessibility, content standards and guidelines[2], as outlined in web governance and laboratory policies, procedures and guidelines.
b. Graded approach to website governance
The level of governance rigor implemented by the Communication Division for any given website will be determined using a graded approach[3] that is based on a website’s intended audience and function; method of user access; and entity that owns the website.
The primary function of the graded approach is to provide an initial determination of (1) whether a site will undergo review by the Communication Division and (2) the likely need for approvals of site branding and content and expected update frequency. Final decisions on required approvals for site ownership, branding and content, and minimum update frequency will be made by the Communication Division on a case-by-case basis, guided by the governance levels listed below.
Before any Fermilab website is created, significantly changed or upgraded to a new technology, the website owner must: attest the necessary web skills and competence to supporting web updates; evaluate the site according to the criteria below; document the results; and follow the appropriate governance procedure depending on the level indicated.
|
CRITERIA USED TO DETERMINE LEVEL OF GOVERNANCE |
||
|
“high” criteria |
if one or more of the following applies: A1, A2, F1, F2, F3, V1, O1 |
|
|
“moderate” criteria |
if one or more of the following applies: A3, O2 |
|
|
“minimal” criteria |
if the following applies: F6 |
|
|
“low” criteria |
if none of the “high” or “moderate” or “minimal” criteria applies |
|
|
|
||
|
Intended audience |
||
|
A1 |
Public |
|
|
A2 |
All employees and/or all users and affiliates |
|
|
A3 |
Large subset of employees, users or affiliates |
|
|
A4 |
Small subset of employees, users or affiliates |
|
|
Intended function |
||
|
F1 |
Public relations |
|
|
F2 |
Public outreach |
|
|
F3 |
Recruitment |
|
|
F4 |
Information |
|
|
F5 |
Collaborative work |
|
|
F6 |
Web application or service; Database |
|
|
F7 |
All other cases |
|
|
Visibility; authentication |
||
|
V1 |
External-public visibility; no authentication required |
|
|
V2 |
External-restricted visibility; authentication required |
|
|
V3 |
Internal-only visibility; authentication required; must be in network |
|
|
Entity that owns the website |
||
|
O1 |
Major laboratory unit(s) |
|
|
O2 |
Scientific collaboration or external laboratory-affiliated group |
|
|
O3 |
Small teams; departments; individuals |
|
|
O4 |
All other cases |
|
The levels of governance are:
High: Websites meeting the “high” criteria will automatically undergo review by the Communication Division. After initial review, the Communication Division will approve or deny public visibility if requested and document the high-level requirements for site branding, content and review/update frequency as well as any required additional approvals before the site can go into production. Sites meeting the “high” criteria will be required to:
- Identify site ownership.
- Adhere to specified maintenance and branding guidelines.
- Have their branding, architecture and content approved by the Communication Division before entering production.
- Review their site content once or twice a year and update it as deemed appropriate by the site owner in consultation with the Communication Division.
Moderate: Websites meeting the “moderate” criteria will automatically undergo review by the Communication Division; however, high-level requirements for site branding, content and review/update frequency will typically be less rigorous than for sites meeting the “high” criteria. After initial review, the Communication Division will approve or deny public visibility if requested and document the high-level requirements for site branding, content and review/update frequency, as well as any required additional approvals before the site can go into production. In many cases, sites meeting the “moderate” criteria will be required to:
- Identify site ownership.
- Adhere to specified branding guidelines.
- Have their branding (but not content) approved by the Communication Division before entering into production.
- Review and update their site content at least annually.
Low or Minimal: Websites meeting the “low” or “minimal” criteria will not be presented to the Communication Division for review before they go into production. As with all laboratory-supported websites, sites meeting the “low” or “minimal” criteria must still meet all applicable IT policies and requirements as specified by the laboratory.
6. Definitions
Fermilab web presence is all web accessible information in Fermilab-owned domains.
Website is a set of one or more webpages and related content under a subdomain.
Webpage is a document reachable at one URL on the web with a client such as a browser
Site owners are people who own and are directly responsible for managing a website.
Content editors are people who have the authority and access, as designated by site owners, to modify some or all of the content of a website.
Authentication and visibility:
- External-Public - Intended for anyone in the world and can be viewed by anonymous visitors
- External-Restricted - Accessible on the Internet with authentication and authorization.
- Internal-Only - Only accessible from the Fermilab Network or over VPN with authentication and authorization. Not visible or accessible on the Internet.
7. Responsibilities
Communication Division responsibilities:
- Set standards for website/webpage maintenance and ownership.
- Maintain overall governance of the Fermilab website. Ensure website/webpage owners follow web maintenance, guidelines and brand standards.
- Set priorities for Fermilab’s web program.
- Create look and feel (branding) and high-level messaging across the web (intranet, internet and collaboration sites).
- Createand maintain accessibility-ready web templates and provide web content standards and style guides.
- Own and maintain content of Fermilab public relations pages.
- Approve subdomain names in the Fermilab web presence.
- Authorize public visibility for website content.
- Oversee the labwide web taxonomy standards for website/webpage maintenance and ownership.
Information Technology Division responsibilities:
- Establish labwide website technology and development standards and guidelines.
- Support website infrastructure and content management system platforms.
- Maintain Service Owner documentation for Site Owners and Content Editors at https://fermi.servicenowservices.com/kb_view.do?sysparm_article=KB0011347
Cybersecurity Department responsibilities:
- Establish labwide website cybersecurity standards and guidelines.
- Set cybersecurity processes to ensure that the information systems at Fermilab are operated at an appropriate level of risk.
- Run web content scans to ensure no Personally Identifiable Information (PII) and sensitive information is stored on public websites.
The Web Governance Committee serves as the advisor on new web templates based on laboratory branding.
Site Owners and Content Editors responsibilities:
- Ensure the processes and procedures required by this and any applicable Information Technology (IT) policies are followed.
- Ensure web content made accessible via their websites is properly maintained and updated.
- Ensure web content style guide compliance.
- Ensure only authorized information is exposed to the public.
8. Authorities
Fermilab Policies
- Policy on Communications
- Policy on Records Management
- Policy on Information, Categorization, Access, and Document Control
- Other Fermilab Information Technology Policies
Overarching policies covering basic requirements for all federal websites and digital services:
- H.R.5759 - 21st Century Integrated Digital Experience Act (IDEA)
- Requirements for delivering a digital-first public experience
- H.R.2331 - Connected Government Act
9. Owner
This policy is owned by the Director of the Communication Division.
10. Review Cycle
This policy shall be reviewed every 2 years.
11. Communication Plan
This policy shall be available in the Fermilab policy database and linked from the “Request a Website” form in Service Now. The Director of the Communication Division is responsible for the communication of this policy.
Revision History
|
M&O |
Author |
Description of Change |
Revision Date |
|
FFDG |
M. Barone |
Revised the graded approach table for improved clarity. Added reference to web style and guides published by the Communication Division. |
December 17, 2025 |
|
FFDG |
M. Barone |
Updated formatting after contract transition. Aligned visibility types with current taxonomy. |
May 15, 2025 |
|
FFDG |
A. Campbell |
Policy adopted by FFDG. |
January 1, 2025 |
|
FRA |
M. Barone |
Separated responsibilities of Information Technology Division and Cybersecurity, formerly together under Office of the CIO. |
January 31, 2023 |
|
FRA |
M. Barone |
Updated responsibilities of the Office of Communication. Updated scope to include all web content in Fermilab-owned domains. Added ‘minimal’ level to graded approach. |
January 22, 2021 |
|
FRA |
M. Barone |
Improved formatting of graded approach table. |
August 8, 2018 |
|
FRA |
M. Barone |
Added language on governance of public visibility for web content. |
October 20, 2015 |
|
FRA |
M. Barone, |
Original release |
October 1, 2015 |
[1] Governance of web documents not directly linked from websites and stored in dedicated repositories such as DocDB, SharePoint libraries or shared drives, is documented in the Fermilab Policy on Information Categorization, Access and Document Control and not covered in this policy.
[2] Refer to the communication.fnal.gov website for detailed guidelines from the Communication Division.
[3] A similar graded approach is used by IT for governance of documents stored in repositories – see Fermilab Policy on Information Categorization and Access for details.