Go to the content

Mapping of IT services and system administrators

The mapping of Scuola IT services collects information about servers, websites, databases and other IT services connected to funds or projects.

The mapping supports compliance with current regulations and guidelines on personal data processing and IT security.

Fund holders or project managers must provide the required information for the IT services under their responsibility through the dedicated Form. The information must then be validated every six months.

For each IT service, URL, hostname or IP address, service type, short description of the service, internal service owner, system administrator, any other technical contacts and type of processed data must be provided.

Regulations do not allow websites, servers, databases or other IT services to operate without a system administrator. IT services without a system administrator can no longer remain available.

System administrators

System administrators may be internal to the Scuola, if they are SNS contracted staff, or external, if they are technicians employed by external service providers.

The system administrator manages, maintains and updates the processing systems under their responsibility, in order to ensure functionality and security in compliance with current regulations.

The activities of the system administrator include, among others, creating security copies, performing backup and data recovery operations, safeguarding credentials, managing authentication systems and managing authorization systems.

The appointment as system administrator lasts one year, unless otherwise provided for by contract. Any later change must be communicated by the internal service owner.

System administrators are proposed by the fund holder or project manager and are appointed by the Data Controller of the Scuola, namely the Director.

If the system administrator is internal, the designation is made on the basis of the information provided by the fund holder or project manager, after assessing the experience, skills and reliability of the person identified.

If the system administrator is external, the appointment is made as part of the service contract. If the system involves personal data, the service provider must also be appointed as data processor under Article 28 of the GDPR.

For any need, the identifying details of the natural persons appointed as system administrators must be kept directly and specifically.

Training, updates and checks

Internal Scuola staff identified through the mapping as system administrators are offered an information and update programme.

Internal audit activities and checks on the organizational, technical and security measures concerning personal data processing are planned on an annual basis.

Regulatory references

  • EU Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • Italian Legislative Decree no. 196 of 30 June 2003, as amended and supplemented, “Personal Data Protection Code”.
  • Italian Data Protection Authority guidelines on email and Internet, resolution no. 13 of 1 March 2007, published in Official Journal no. 58 of 10 March 2007.
  • Italian Data Protection Authority decision of 27 November 2008, as amended, concerning measures and precautions prescribed to data controllers carrying out processing by electronic means with regard to the assignment of system administrator functions.
  • AGID circular no. 2 of 18 April 2017, concerning minimum ICT security measures for public administrations.
  • GARR Acceptable Use Policy.
  • GARR Incident Management Procedure.

Features

  • Collect information about IT services connected to Scuola funds or projects.
  • Associate each service with an internal service owner and a system administrator.
  • Specify the type of service, such as project website, computing server, web server, database or other IT service.
  • Specify the type of data processed by the service, distinguishing between personal and non-personal data.
  • Periodically validate the information collected through the dedicated Form.
  • Support compliance with IT security, personal data processing and system administrator management requirements.

Requirements

  • Be a fund holder or project manager for one or more servers, websites, databases or IT services.
  • Have the URL, hostname or IP address of the IT service to be mapped.
  • Know the service type and prepare a short description of the service provided.
  • Know the internal service owner, who must have a valid contract with the Scuola.
  • Know the system administrator, their contact details and any other technical contacts.
  • Know the type of data processed by the service and specify whether the data is personal or non-personal.

Designed for

Faculty members, Technical and administrative staff

Get started

  1. Access the dedicated Form for mapping Scuola IT services.
  2. Enter the URL, hostname or IP address of the IT service.
  3. Select the service type among project website, computing server, web server, database or another type.
  4. Enter a short description of the service provided.
  5. Enter the email address of the internal service owner, who must have a valid contract with the Scuola.
  6. Enter the email address and contact details of the system administrator.
  7. Enter any other technical contacts.
  8. Specify the type of processed data, distinguishing between personal and non-personal data.
  9. If the processed data is personal, specify the type of personal data processed.
  10. Carefully check the data entered, because the answers submitted through the Form are processed by an automatic system.
  11. Validate the information every six months, according to Scuola instructions.
  12. To correct an answer that has already been submitted, search for the system email sent by “Google Forms” with the subject “SNS: IT services mapping”.
  13. Open the email received after completing the questionnaire.
  14. Select the “Edit Responses” button.
  15. Correct or update the answers already submitted.

The following instructions must be followed when completing the Form:

  • The term “system administrator” refers to system administrators of servers or virtual machines, webmasters managing websites and database administrators.
  • If the system administrator is internal to the Scuola, they must be a natural person.
  • The “System Administrator eMail” field cannot contain a group email address.
  • To facilitate any urgent action, an email is sent to the system administrator and to all other technical contacts indicated.
  • Port numbers must not be entered in the “IT service URL/IP” field.
  • Both URL and IP address must not be entered together in the “IT service URL/IP” field.
  • The IP address must be entered only if no URL or hostname exists.
  • The protocol, such as “http://” or “https://”, must not be entered in the “IT service URL/IP” and “URL Alias” fields.
  • If the processed data is not personal, the “NON-Personal data” box must be selected in the “Processed data” field.
  • If the “NON-Personal data” box is not selected, the processed data will be considered personal.
  • Services hosted on domains external to the Scuola must not be reported, even if the user is system administrator or webmaster for those services.
  • Software purchased and used on a personal computer must not be entered, because it is not included among the services covered by the mapping.

FAQ

No. IT services without a system administrator can no longer remain available.

URL, hostname or IP address, service type, short description, internal service owner, system administrator, any technical contacts and type of processed data must be provided.

It must be completed by fund holders or project managers for servers, websites, databases and IT services under their responsibility.

Last modification:  03/06/2026