Best Practices - Digital Signage
What is Digital Signage?
Digital signage can be as simple as a screen in a department common area with rotating slides highlighting faculty and student work, or can incorporate dynamic content like real-time transit info, class schedules, or dining menus.
At Harvard, schools and units use different types of signage from multiple hardware and software providers. This page outlines some risks and best practices for mitigating them.
Potential Risks
| Category | Why It Matters |
|---|---|
Cybersecurity |
|
Privacy |
|
Content Management |
|
Operational |
|
Physical Safety |
|
Brand and Reputational |
|
Accessibility |
|
Recommended Best Practices
Cybersecurity Measures
- Limit administrative access to the signage management system using strong, unique passwords and multi-factor authentication (MFA).
- Place signage devices on a separate, secure network segment isolated from sensitive university data and systems.
- Keep operating systems and signage software up-to-date with the latest patches to protect against exploits of known vulnerabilities.
- Implement tools to monitor for unauthorized access or unusual activity on signage systems, with alerts for rapid response. Regularly review access logs to detect anomalies or unauthorized activity.
- Restrict the types of files and sources that can be displayed to minimize malware infection risks.
Clear Content Governance
- Establish a formal process for content creation, review, and approval, with clear roles and responsibilities.
- Ensure content is always current and relevant by using calendar-based workflows
- Educate content contributors on university policies, copyright, and content standards.
Privacy Protection
- Ensure transparency by clearly informing the public, through visible notices, whenever signage contains cameras or sensors.
- Implement checks to ensure private or sensitive data (e.g., contact information, grades, or health info) isn’t posted.
- For interactive screens: Only collect anonymized data, if any, and avoid storing personally identifiable information unless necessary and legally permissible.
Operational Reliability
- Consider backup power sources (UPS) and redundant signage in critical locations, especially for emergency alerts.
- Use secure remote management tools to update or fix signage quickly when issues arise. Replace when no longer supported.
- Configure signage to default to a safe, neutral message (such as university branding or contact info) if connectivity is lost.
Physical Security
- Install signs where they’re visible but not prone to theft, tampering, or accidental damage.
- Use lockable enclosures and shatterproof materials for high-traffic areas.
Accessibility
- Design all displayed content to meet digital accessibility standards (e.g., readable fonts, sufficient color contrast, audio cues where needed).
- Provide QR codes, short links, or contact info for those needing accessible versions or additional help.
- Regularly test signage content using accessibility checklists or involve people with disabilities in usability testing.
Need Help?
Contact your school IT support group for assistance.
Related Resources
Register a device on the wired network (HarvardKey required)
Register a device on the wireless network (HarvardKey required)
Best practices for applying updates
Tips for creating strong passwords
Download a PDF checklist of best practices (HarvardKey required)