CHOOSE THE RIGHT FEATURES
How to plan basic security responsibilities for your website
Security work depends on the site you are running. Begin with the accounts and data involved, then assign responsibility for each part. A certificate alone does not cover the whole project.
Map the components
List the public site, host, domain account, forms, CMS and external services. Record which components collect data and who maintains them. A static information page has different upkeep needs from a login system or a site receiving uploads.
Protect administrative access
Keep accounts under business control, use strong unique credentials and enable supported additional authentication. Grant project access through provider controls where possible. Review who still needs access after handover. Do not put passwords, private keys or secret API credentials in the public site files.
Check data-handling boundaries
Ask where enquiry information is sent and stored, what access is required and how retention is managed. For a backend, confirm security checks are performed there. MDN warns that front-end input validation can be bypassed and must not be the only security check.
Agree updates and recovery
Name the person responsible for applicable software updates and backups. A static site may need source and deployment backups; a CMS may also need database and upload backups. Ask how a restore would be performed and who can approve it. An untested backup should not be treated as proven recovery.
Keep a contact plan
Write down who receives provider alerts and what to do if the site changes unexpectedly or the enquiry route fails. Keep this information outside the public website. Record renewal responsibilities so an expired account does not become a preventable outage.
These are planning checks, not a security certification. At acceptance, ask for evidence of the agreed controls and known limitations. If the project adds customer accounts, uploads or sensitive information, revisit the scope rather than assuming the original information-site checklist is sufficient.
Sources and further detail
Technical references checked on 8 October 2026. Provider features can change.
Practical guidance with illustrative examples. Read our editorial standards or send a correction.