Advanced Search
Search Results
491 total results found
Securing login credentials [Mandatory]
Users should be made aware to keep login credentials such as User IDs and Passwords confidential and not share them.
Password policies[Mandatory]
Appropriate password policies should be defined covering password expiration period, password complexity and allowed login attempts. Adoption of the NIST password policy guidelines is recommended.
Multi-Factor Authentication[Mandatory]
Multi-Factor Authentication (MFA) is strongly recommended as the primary authentication method for government institutions in Rwanda. It provides a high level of security by requiring users to present multiple independent factors for identity verification, sig...
Biometrics[Recommended]
Biometrics can be considered as an additional layer of authentication where it is available and where it is cost effective. Government institutions may explore the use of biometrics, such as fingerprint or facial recognition, for situations where high-security...
Entry into force
This guideline shall come into force on the date of its signature by the Chief Executive Officer of RISA.
Entry into force
This guideline shall come into force on the date of its signature by the Chief Executive Officer of RISA.
Introduction
This document outlines guidelines for the development and management of websites and portals of Government of Rwanda institutions with a focus on standardization as well as making them user centric and secure. These guidelines are mandatory and apply to all ...
Scope and Objectives
This document provides mandatory policies and guidelines for Government of Rwanda websites at both Central Government and institutions, local government and embassies with the aim of making government websites user-centric, high quality, accessible and secure....
Development Lifecycle [Mandatory]
The Website development lifecycle should follow a systematic process in line with RISA software lifecycle guidelines. Key stages including Planning & Requirements gathering, Architecture & Design, Content Creation & Aggregation, Development & Implementation, T...
User-centered design [Mandatory]
Websites should be designed with the user in mind. Websites should be easy to use, navigate, and understand, and that the content should be organized in a logical and intuitive way. The website should be tested on multiple browsers to ensure consistency of lay...
Performance [Mandatory]
Websites should be designed to perform well on all devices and platforms, including desktops, laptops, tablets, and smartphones. They should also be optimized for fast loading times.
Security [Mandatory]
Websites should be designed with security in mind. This includes using secure hosting, encryption, and authentication protocols to protect user data and prevent unauthorized access. They should conform to RISA Security by Design guidelines.
Data Protection & Privacy [Mandatory]
Websites should respect user privacy and comply with Rwanda’s law on data protection and data privacy and all other relevant data protection regulations. This includes providing clear and concise privacy policies, obtaining user consent for data collection and...
Branding [Mandatory]
Websites should be designed to reflect the Government of Rwanda's branding and must be aligned with the template provided by RISA for all Government websites to ensure a consistent user experience across Government websites.
Search Engine Optimization [Recommended]
GoR websites must be optimized for search engines to ensure that they appear high in search results for relevant queries.
Testing and Evaluation [Mandatory]
Websites should be tested and evaluated regularly to ensure that they meet the above guidelines and are functioning effectively. This includes conducting usability tests, accessibility tests, and security audits.
Accessibility [Recommended]
Websites should follow RISA Software Accessibility Guidelines which are based on W3C’s Web Content Accessibility Guidelines (WCAG) to make the website inclusive and accessible to users with disabilities.
Multi-language support [Recommended]
Consider providing multi language support particularly Kinyarwanda as part of increasing accessibility.
Social media integration [Recommended]
Websites should be integrated with official social media channels of the institution to provide users with other channels for interaction.
Domain name [Mandatory]
All websites of Government institutions should be registered under the .gov.rw subdomain while those in the academic sector should be under .ac.rw.