NAO Website Technical Discovery Prepared by Stu
Description: NAO Website Technical Discovery Prepared by Stu Mackellar May 2021 Technical Discovery Process Identify technical themes and observations from ongoing research Identify stakeholders covering themes Arrange interviews Definition of scorecard
Related Topics
Download Presentation
"NAO Website Technical Discovery Prepared by Stu" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. NAO Website Technical Discovery Prepared by Stu Mackellar
May 2021<br>
slide2. Technical Discovery Process Identify technical themes and observations from ongoing research
Identify stakeholders covering themes
Arrange interviews
Definition of scorecard criteria to assess potential solutions
Iteration and refinement
Ideation
Identification of candidate solutions
Additional ad hoc interviews
Feedback workshop
Report production
Presentation<br>
slide3. Emerging Technical Themes (from user research) Metadata & Content Discovery
How can content be more easily navigated? Improvements to search and surfacing of related content. Improvements to metadata and introduction of a structured taxonomy.
Content Presentation
Transition away from PDF alone toward HTML first or a dual format approach.
Metrics & Measurement
How effective is the website in exposing and delivering content?
How is the content consumed?
Accessibility & Responsiveness
How can content - particularly visual assets like infographics - be better presented?<br>
slide4. Research Topics<br>
slide5. How do users want to consume content?
Who creates content and what processes surround this? What accessibility requirements are there?
Are there any regulatory or legal requirements? Accessibility What analytics data is currently available?
What is missing?
Are there any privacy implications? Analytics Who is responsible for security within NAO?
Are there any regulatory or legal requirements applicable to the website’s security? Security Content How could search be improved to better expose content?
How could task or user oriented journeys be used to enhance navigation and discoverability? User Experience What skills are available in house?
What is the appetite for building and managing software vs buying?
What’s the NAO technical strategy? Technical<br>
slide6. Content Questions
What are the anticipated consumption trends, i.e. how will users want to consume content?
How to re-organise content to follow user themes or journeys instead of along departmental lines?
Who creates the content and what processes surround this?
How is "multimedia" content produced?
How fast is the production pipeline currently and does this meet demand? Comments
Don’t spend too much time looking into e2e processes - already understood
Look at content types/formats - where are we heading and what is the tech impact?
How will visualisations evolve?
What pipelines will be needed to support the above?
What are the resource implications?
How to explain the implications of these changes on how content is produced?<br>
slide7. User Experience Questions
What would constitute a more modern look & feel?
How could search be improved to better expose content?
How could task or user oriented journeys be used to enhance navigation and discoverability?
How to deal with continuity of existing document links?
Who decides how assets should be presented?
Is there any need or desire to align with a framework, e.g. GDS? Comments
Ongoing IA work
No DRI for digital UX currently
Take UR and use to formulate proposals
No need for specific tech engagement
Will need to consider branding<br>
slide8. Technical Questions
How is the current website built?
What does the current technical team look like?
What skills are available in house?
What is the appetite for building and managing software vs buying?
Is there an NAO technical strategy?
With which technologies and platforms are NAO familiar and Is there a preferred tech stack?
Where are assets hosted?
What are the budgetary constraints? Limited, but some flex. Comments
Most NAO expertise with CMS sites, e.g. WP, Drupal
Headless may not be ideal for NAO reqs
Need to carefully consider NFRs
Need to deal with various subsites too - move into main site?<br>
slide9. Accessibility Questions
What accessibility requirements are there?
What frameworks or guidance is applicable (e.g. WCAG)?
Are there any regulatory or legal requirements?
Are there any metrics available on accessible demands?
How is success measured? Comments
Need to meet pub sec reqs to a large extent
Would it make sense to follow GDS standards?<br>
slide10. Analytics Questions
What analytics data is currently available?
What is missing?
Are there any concrete requirements?
How is access to content recorded?
Are there any privacy concerns or implications?
Who will consume analytic data and how? Comments
Currently not as mature as we’d like
Would like some advice on optimising GA usage, e.g. capturing events
Should we implement GTM? Data Studio?
Need to consider privacy - what are the boundaries?
Cookie consent - currently non-compliant, about to deploy OneTrust WP plugin
One of main needs - what content is being consumed?<br>
slide11. Security Questions
Who is responsible for security within NAO?
Does NAO have its own internal cyber security policy?
Are there any regulatory or legal requirements applicable to the website’s security?
Are there any other specific security concerns or requirements?
How is the level of confidence in the website’s security assessed? Comments
Annual pen testing<br>
slide12. Constraints<br>
slide13. Overarching Constraints Functional
The site must be accessible and available reliably across all device types
PDF reports must be available for the foreseeable future
PDF as a format does not meet all identified user needs
Financial
The budget for the site is relatively small
Technical
There are no in-house full-stack development skills
(although basic WordPress and HTML/CSS skills are available)
There is no appetite or budget to increase the website team size
Operational
The website must meet overarching NAO security requirements
SaaS hosting is the preferred strategic option<br>
slide14. Findings<br>
slide15. Platform Insight The NAO website was originally introduce in 1997 by the then librarian and was hand-coded in HTML. It has since been through various revisions.
The site was migrated to a content management system provided by Alterian prior to 2010. It was then migrated again to WordPress around 2013 by Code For The People. A custom theme and plugin were developed at this stage.
In 2016 the Sage starter theme was introduced, which is the current basis of the site today. The NAO plugin has been refined and continually developed and provides a variety of functionality, including custom post types for reports, widgets for displaying content and workflow elements.
WordPress is a popular and well understood content management system (CMS) and is widely recognised as a market leader. There has been significant investment in the current implementation and its custom functionality, such as themes and plugins, and also integration with NAO workflows and processes.<br>
slide16. Platform Recommendations Goal: Provide a well understood, secure, affordable and functional platform on which NAO content can be effectively distributed to its users
Recommendations:
Continue with the use of WordPress as a platform
Review theme and plugin usage for fitness for purpose and commission updates or replacements where necessary<br>
slide17. Hosting Insight The NAO website is currently hosted by CIVIC, who have also provided various software consultancy services over the past few years.
CIVIC provide a hosted WordPress service, including application of critical security patches and some updates. It is effectively a PaaS (platform as a service) solution. The NAO IT strategy is to move away from on-premise hosting within the next 12-18 months, with SaaS the strongly preferred option, or cloud hosting in Azure otherwise.
Configuration management is seen as a weakness of the current arrangement, particularly from a security perspective. Access control and limited configuration of identity management functionality is concerning. A move to a fully-managed SaaS (software as a service) solution employing federated identity management would be preferred.
The website is currently configured in multi-site mode. This is considered unnecessary and consolidation of the existing sub-sites with the primary site would be simpler with no loss of function.<br>
slide18. Hosting Recommendations Goal: Ensure the NAO website is highly available, cost-effective and manageable by NAO in-house staff
Recommendations:
Explore moving to a WordPress SaaS (Software as a Service) provider
Consolidate the current multi-site setup into a single-site configuration<br>
slide19. Content Insight Website content is predominantly created via a fairly complex workflow which is centred around Adobe’s InDesign software. Any changes to how content is produced or to generated formats will consequently require changes to this process. Numerous opportunities for improvement of the workflow have been identified over recent years and lack of capacity has generally prevented corresponding action. For example, manually uploading content is inefficient and automation of this process would save time and be more repeatable.
Reports are the website’s primary content type and comprise of various components such as a synopsis, an executive summary and the report itself. They are generated in several formats (PDF for web, PDF for print, epub). None of these formats lend themselves particularly to interactivity, linking into the content or finding specific segments of interest.
Various data visualisations are also published. These generally are published from one of two data processing tools: Tableau and Shiny. The visualisations are embedded in the website as independent assets and hosted elsewhere.<br>
slide20. Content Recommendations Goal: Ensure NAO website users are able to find and consume reports and related content easily
Recommendations:
Prototype an HTML report variant (either full, partial or both) by modifying the InDesign workflow to generate HTML from source
Evaluate the Ajar Productions in5 plugin for HTML generation
Prototype concept designs
Explore automated ingestion of content into WordPress using plugins such as WP Media Folder<br>
slide21. Search Insight The website currently has a search function which is prominently displayed at the top of every page. It’s implemented using the Swiftype WordPress plugin.
There has been strong and consistent feedback from both internal and external users that the search functionality does not work as well as it could. Multiple users have reported resorting to generic Google web search as an alternative entry point to NAO content.
Additional content navigation tooling exists internally for NAO users. The Back Catalogue Analyser, built by the analytics team, is one of the most prominent of these. It has been suggested that, while not a panacea, this tool could contribute toward provision of an improved externally-facing search function.
The use of enhanced search functionality, such as autocomplete and faceted filtering have been suggested as another approach to improving search performance and these have been incorporated into the concepts designed during this discovery work.<br>
slide22. Search Recommendations Goal: Provide an enhanced search experience across the NAO website
Recommendations:
Evaluate the ElasticPress plugin for WordPress to provide autocomplete and faceted filtering
Explore the plugin’s advanced configuration options to optimise of various search characteristics<br>
slide23. Tagging Insight Content is tagged within WordPress as part of the publication workflow. The taxonomy is hard-code within WordPress and is thus maintained by the external comms team. Each content item can have multiple tags.
There also exists a separate taxonomy internally, which is used for a variety of purposes. There is a current ongoing effort to improve this through consistency of language and simplification of the overarching structure. This taxonomy is considered the master and the system of record is SharePoint.
The lack of consistent tagging of internal and external facing content has caused confusion and there’s a strong desire to consolidate into a single source of truth. Different terminology is used for the same concepts publicly and internally in some cases and this has also resulted in confusion on occasion.<br>
slide24. Tagging Recommendations Goal: Make it easier for users to find the NAO content they’re looking for and other related content
Recommendations:
Use a single, unified taxonomy and consistent terminology to annotate content with metadata
Ensure the taxonomy’s design is flexible and enables support for hierarchical layers of tags
Explore the viability of synchronising SharePoint master taxonomy data to WordPress
Explore automated tagging of content through analysis of text and extraction of references to other NAO reports using tools such as the Back Catalogue Analyser<br>
slide25. Data Insight Many reports are based on or contain statistical analysis of underlying data sets, which are sourced from one or more government departments. There is often a degree of aggregation and processing needed to ensure related data sets are consistent and standardised. This function is performed in-house by data and analytics teams.
Data is generally held in a data warehouse and processed using a variety of tools. Tableau and Shiny are the two commercial products which are integrated with the website. There is an internally developed data service and an associated REST API which are used as the basis for several bespoke tools.
There is an aspiration toward publication of raw data sets, which is something that has been previously discouraged within NAO, for various reasons. Some small data sets are currently published alongside visualisations in CSV format. Other options that have been previously considered include provision of a public API, either by making the existing internal API publicly accessible or by creating a new one, and making CSV data sets more widely available.<br>
slide26. Data Recommendations Goal: Expose the underlying data sets that are used within NAO reports and visualisations
Recommendations:
Explore exposing the existing internal REST API publicly with additional access controls if necessary
Alternatively or additionally, explore the feasibility of providing CSV exports of the raw data used to generate reports and visualisations<br>
slide27. Analytics Insight Currently the website is integrated with Google Analytics. Data is made available in Google Data Studio, which is performing well for existing use cases. A review of the Google Analytics implementation and overall analytics pipeline is desired and will likely be outsourced to external experts. Metrics include page views and downloads. The MonsterInsights analytics plugin is already enabled on the site and its efficacy is unclear.
There is a desire to enhance analytics capabilities with additional metrics, such as content engagement (progress, view time) and capturing progress through specific user journeys. There is a tension between the need for content engagement metrics and the use of PDFs as the primary consumption format, due to the offline nature of PDF documents. Adobe have made some progress toward enhancing PDF usage tracking, which may warrant further investigation.
Dashboards (primarily in Google Data Studio) are the primary consumption method for analytic data. Export to CSV for ad hoc analysis would be of additional benefit. Data Studio may support this to some extent although no research has yet been done to assess its capabilities in this area.<br>
slide28. Analytics Recommendations Goal: Provide NAO with better visibility of how content is consumed
Recommendations:
Review existing Google Analytics configuration and optimise to provide more granular tracking Assess whether the MonsterInsights plugin is adding value
Assess content groupings as a technique for capturing progress through specific user journeys
Review Data Studio usage and explore whether dashboards can be enhanced to deliver new metrics<br>
slide29. Accessibility Insight The website was the subject of a recent accessibility audit, for which it received a score of 7 out of 10.
The site scores reasonably well against a selection of high profile accessibility assessment tools. For example, it has an 85% compliance score at www.webaccessibility.com.
Anecdotally, there are some known issues with the responsiveness of the site on some device types, particularly smaller screens. Some of the embedded assets which use HTML iframes also have a higher degree of accessibility issues.<br>
slide30. Accessibility Recommendations Goal: Ensure NAO content can be consumed effectively by users with additional needs and on all device types
Recommendations:
Identify tactical targets for improvement based on the latest audit results and automated scans using standard accessibility tools
Optimise WordPress templates to increase responsiveness of iframe content to improve visualisations<br>
slide31. SEO Insight Google tooling is also used to some extent already to measure search engine optimisation performance, although this is obviously skewed toward a Google perspective. A WordPress plugin called Yoast is currently active on the site and its efficacy is unclear. No specific SEO concerns have been raised during research, although confidence in the status quo is uncertain.<br>
slide32. SEO Recommendations Goal: Ensure NAO content ranks high in search engine listings for relevant keywords and related searches
Recommendations:
Optimise existing WordPress templates to ensure that tags and any additional metadata that are introduced are exposed to search engines using standard protocols
Review content production workflows to ensure content is optimised for SEO
Review efficacy of the Yoast plugin<br>
slide33. Security & Compliance Insight The website must be compliant with various privacy legislation, including:
GDPR/DPA
PECR
Its cookie implementation is not currently compliant with PECR, although there are ongoing efforts to rectify this.
Given that the website does process some personally identifiable information (PII), a PII log should be kept and a data privacy impact assessment should be undertaken. No evidence of these was found.<br>
slide34. Security & Compliance Recommendations Goal: Ensure the NAO website protects sensitive data, is highly resistant to common threat vectors and complies with all applicable legislation
Recommendations:
Explore implementation of identity federation to provide seamless, integrated access control
Conduct a data protection impact assessment (DPIA) and create a personally identifiable information (PII) log
Continue ongoing efforts to implement compliant cookie handling<br>
slide35. Delivery Models<br>
slide36. Software as a Service (SaaS) Description: Procure a website platform as a commoditised service which is hosted and managed by the supplier on the customer’s behalf<br>
slide37. Outsourced Development Description: Engage a supplier to create and maintain a website solution independently based on NAO requirements. Can be structured as an ongoing relationship with one supplier or as discrete units of work, potentially across many suppliers.<br>
slide38. Augmented Development Description: Work collaboratively with a supplier to create a website solution based on NAO requirements. Generally requires building a good working relationship with a single supplier.<br>
slide39. Appendix Alternative options<br>
slide40. Platform Goal: Provide a well understood, secure, affordable and functional platform on which NAO content can be effectively distributed to its users<br>
slide41. Hosting Goal: Ensure the NAO website is highly available, cost-effective and manageable by NAO in-house staff<br>
slide42. Content Goal: Ensure NAO website users are able to find and consume reports and related content easily<br>
slide43. Search Goal: Provide an enhanced search experience across the NAO website<br>
slide44. Tagging Goal: Make it easier for users to find the NAO content they’re looking for and other, related content<br>
slide45. Data Goal: Expose the underlying data sets that are used within NAO reports and visualisations<br>
slide46. Analytics Goal: Provide NAO with better visibility of how content is consumed<br>
slide47. Accessibility Goal: Ensure NAO content can be consumed effectively by users with additional needs and on all device types<br>
slide48. SEO Goal: Ensure NAO content ranks high in search engine listings for relevant keywords and related searches<br>
slide49. Security & Compliance Goal: Ensure the NAO website protects sensitive data, is highly resistant to common threat vectors and complies with all applicable legislation<br>
May 2021<br>
slide2. Technical Discovery Process Identify technical themes and observations from ongoing research
Identify stakeholders covering themes
Arrange interviews
Definition of scorecard criteria to assess potential solutions
Iteration and refinement
Ideation
Identification of candidate solutions
Additional ad hoc interviews
Feedback workshop
Report production
Presentation<br>
slide3. Emerging Technical Themes (from user research) Metadata & Content Discovery
How can content be more easily navigated? Improvements to search and surfacing of related content. Improvements to metadata and introduction of a structured taxonomy.
Content Presentation
Transition away from PDF alone toward HTML first or a dual format approach.
Metrics & Measurement
How effective is the website in exposing and delivering content?
How is the content consumed?
Accessibility & Responsiveness
How can content - particularly visual assets like infographics - be better presented?<br>
slide4. Research Topics<br>
slide5. How do users want to consume content?
Who creates content and what processes surround this? What accessibility requirements are there?
Are there any regulatory or legal requirements? Accessibility What analytics data is currently available?
What is missing?
Are there any privacy implications? Analytics Who is responsible for security within NAO?
Are there any regulatory or legal requirements applicable to the website’s security? Security Content How could search be improved to better expose content?
How could task or user oriented journeys be used to enhance navigation and discoverability? User Experience What skills are available in house?
What is the appetite for building and managing software vs buying?
What’s the NAO technical strategy? Technical<br>
slide6. Content Questions
What are the anticipated consumption trends, i.e. how will users want to consume content?
How to re-organise content to follow user themes or journeys instead of along departmental lines?
Who creates the content and what processes surround this?
How is "multimedia" content produced?
How fast is the production pipeline currently and does this meet demand? Comments
Don’t spend too much time looking into e2e processes - already understood
Look at content types/formats - where are we heading and what is the tech impact?
How will visualisations evolve?
What pipelines will be needed to support the above?
What are the resource implications?
How to explain the implications of these changes on how content is produced?<br>
slide7. User Experience Questions
What would constitute a more modern look & feel?
How could search be improved to better expose content?
How could task or user oriented journeys be used to enhance navigation and discoverability?
How to deal with continuity of existing document links?
Who decides how assets should be presented?
Is there any need or desire to align with a framework, e.g. GDS? Comments
Ongoing IA work
No DRI for digital UX currently
Take UR and use to formulate proposals
No need for specific tech engagement
Will need to consider branding<br>
slide8. Technical Questions
How is the current website built?
What does the current technical team look like?
What skills are available in house?
What is the appetite for building and managing software vs buying?
Is there an NAO technical strategy?
With which technologies and platforms are NAO familiar and Is there a preferred tech stack?
Where are assets hosted?
What are the budgetary constraints? Limited, but some flex. Comments
Most NAO expertise with CMS sites, e.g. WP, Drupal
Headless may not be ideal for NAO reqs
Need to carefully consider NFRs
Need to deal with various subsites too - move into main site?<br>
slide9. Accessibility Questions
What accessibility requirements are there?
What frameworks or guidance is applicable (e.g. WCAG)?
Are there any regulatory or legal requirements?
Are there any metrics available on accessible demands?
How is success measured? Comments
Need to meet pub sec reqs to a large extent
Would it make sense to follow GDS standards?<br>
slide10. Analytics Questions
What analytics data is currently available?
What is missing?
Are there any concrete requirements?
How is access to content recorded?
Are there any privacy concerns or implications?
Who will consume analytic data and how? Comments
Currently not as mature as we’d like
Would like some advice on optimising GA usage, e.g. capturing events
Should we implement GTM? Data Studio?
Need to consider privacy - what are the boundaries?
Cookie consent - currently non-compliant, about to deploy OneTrust WP plugin
One of main needs - what content is being consumed?<br>
slide11. Security Questions
Who is responsible for security within NAO?
Does NAO have its own internal cyber security policy?
Are there any regulatory or legal requirements applicable to the website’s security?
Are there any other specific security concerns or requirements?
How is the level of confidence in the website’s security assessed? Comments
Annual pen testing<br>
slide12. Constraints<br>
slide13. Overarching Constraints Functional
The site must be accessible and available reliably across all device types
PDF reports must be available for the foreseeable future
PDF as a format does not meet all identified user needs
Financial
The budget for the site is relatively small
Technical
There are no in-house full-stack development skills
(although basic WordPress and HTML/CSS skills are available)
There is no appetite or budget to increase the website team size
Operational
The website must meet overarching NAO security requirements
SaaS hosting is the preferred strategic option<br>
slide14. Findings<br>
slide15. Platform Insight The NAO website was originally introduce in 1997 by the then librarian and was hand-coded in HTML. It has since been through various revisions.
The site was migrated to a content management system provided by Alterian prior to 2010. It was then migrated again to WordPress around 2013 by Code For The People. A custom theme and plugin were developed at this stage.
In 2016 the Sage starter theme was introduced, which is the current basis of the site today. The NAO plugin has been refined and continually developed and provides a variety of functionality, including custom post types for reports, widgets for displaying content and workflow elements.
WordPress is a popular and well understood content management system (CMS) and is widely recognised as a market leader. There has been significant investment in the current implementation and its custom functionality, such as themes and plugins, and also integration with NAO workflows and processes.<br>
slide16. Platform Recommendations Goal: Provide a well understood, secure, affordable and functional platform on which NAO content can be effectively distributed to its users
Recommendations:
Continue with the use of WordPress as a platform
Review theme and plugin usage for fitness for purpose and commission updates or replacements where necessary<br>
slide17. Hosting Insight The NAO website is currently hosted by CIVIC, who have also provided various software consultancy services over the past few years.
CIVIC provide a hosted WordPress service, including application of critical security patches and some updates. It is effectively a PaaS (platform as a service) solution. The NAO IT strategy is to move away from on-premise hosting within the next 12-18 months, with SaaS the strongly preferred option, or cloud hosting in Azure otherwise.
Configuration management is seen as a weakness of the current arrangement, particularly from a security perspective. Access control and limited configuration of identity management functionality is concerning. A move to a fully-managed SaaS (software as a service) solution employing federated identity management would be preferred.
The website is currently configured in multi-site mode. This is considered unnecessary and consolidation of the existing sub-sites with the primary site would be simpler with no loss of function.<br>
slide18. Hosting Recommendations Goal: Ensure the NAO website is highly available, cost-effective and manageable by NAO in-house staff
Recommendations:
Explore moving to a WordPress SaaS (Software as a Service) provider
Consolidate the current multi-site setup into a single-site configuration<br>
slide19. Content Insight Website content is predominantly created via a fairly complex workflow which is centred around Adobe’s InDesign software. Any changes to how content is produced or to generated formats will consequently require changes to this process. Numerous opportunities for improvement of the workflow have been identified over recent years and lack of capacity has generally prevented corresponding action. For example, manually uploading content is inefficient and automation of this process would save time and be more repeatable.
Reports are the website’s primary content type and comprise of various components such as a synopsis, an executive summary and the report itself. They are generated in several formats (PDF for web, PDF for print, epub). None of these formats lend themselves particularly to interactivity, linking into the content or finding specific segments of interest.
Various data visualisations are also published. These generally are published from one of two data processing tools: Tableau and Shiny. The visualisations are embedded in the website as independent assets and hosted elsewhere.<br>
slide20. Content Recommendations Goal: Ensure NAO website users are able to find and consume reports and related content easily
Recommendations:
Prototype an HTML report variant (either full, partial or both) by modifying the InDesign workflow to generate HTML from source
Evaluate the Ajar Productions in5 plugin for HTML generation
Prototype concept designs
Explore automated ingestion of content into WordPress using plugins such as WP Media Folder<br>
slide21. Search Insight The website currently has a search function which is prominently displayed at the top of every page. It’s implemented using the Swiftype WordPress plugin.
There has been strong and consistent feedback from both internal and external users that the search functionality does not work as well as it could. Multiple users have reported resorting to generic Google web search as an alternative entry point to NAO content.
Additional content navigation tooling exists internally for NAO users. The Back Catalogue Analyser, built by the analytics team, is one of the most prominent of these. It has been suggested that, while not a panacea, this tool could contribute toward provision of an improved externally-facing search function.
The use of enhanced search functionality, such as autocomplete and faceted filtering have been suggested as another approach to improving search performance and these have been incorporated into the concepts designed during this discovery work.<br>
slide22. Search Recommendations Goal: Provide an enhanced search experience across the NAO website
Recommendations:
Evaluate the ElasticPress plugin for WordPress to provide autocomplete and faceted filtering
Explore the plugin’s advanced configuration options to optimise of various search characteristics<br>
slide23. Tagging Insight Content is tagged within WordPress as part of the publication workflow. The taxonomy is hard-code within WordPress and is thus maintained by the external comms team. Each content item can have multiple tags.
There also exists a separate taxonomy internally, which is used for a variety of purposes. There is a current ongoing effort to improve this through consistency of language and simplification of the overarching structure. This taxonomy is considered the master and the system of record is SharePoint.
The lack of consistent tagging of internal and external facing content has caused confusion and there’s a strong desire to consolidate into a single source of truth. Different terminology is used for the same concepts publicly and internally in some cases and this has also resulted in confusion on occasion.<br>
slide24. Tagging Recommendations Goal: Make it easier for users to find the NAO content they’re looking for and other related content
Recommendations:
Use a single, unified taxonomy and consistent terminology to annotate content with metadata
Ensure the taxonomy’s design is flexible and enables support for hierarchical layers of tags
Explore the viability of synchronising SharePoint master taxonomy data to WordPress
Explore automated tagging of content through analysis of text and extraction of references to other NAO reports using tools such as the Back Catalogue Analyser<br>
slide25. Data Insight Many reports are based on or contain statistical analysis of underlying data sets, which are sourced from one or more government departments. There is often a degree of aggregation and processing needed to ensure related data sets are consistent and standardised. This function is performed in-house by data and analytics teams.
Data is generally held in a data warehouse and processed using a variety of tools. Tableau and Shiny are the two commercial products which are integrated with the website. There is an internally developed data service and an associated REST API which are used as the basis for several bespoke tools.
There is an aspiration toward publication of raw data sets, which is something that has been previously discouraged within NAO, for various reasons. Some small data sets are currently published alongside visualisations in CSV format. Other options that have been previously considered include provision of a public API, either by making the existing internal API publicly accessible or by creating a new one, and making CSV data sets more widely available.<br>
slide26. Data Recommendations Goal: Expose the underlying data sets that are used within NAO reports and visualisations
Recommendations:
Explore exposing the existing internal REST API publicly with additional access controls if necessary
Alternatively or additionally, explore the feasibility of providing CSV exports of the raw data used to generate reports and visualisations<br>
slide27. Analytics Insight Currently the website is integrated with Google Analytics. Data is made available in Google Data Studio, which is performing well for existing use cases. A review of the Google Analytics implementation and overall analytics pipeline is desired and will likely be outsourced to external experts. Metrics include page views and downloads. The MonsterInsights analytics plugin is already enabled on the site and its efficacy is unclear.
There is a desire to enhance analytics capabilities with additional metrics, such as content engagement (progress, view time) and capturing progress through specific user journeys. There is a tension between the need for content engagement metrics and the use of PDFs as the primary consumption format, due to the offline nature of PDF documents. Adobe have made some progress toward enhancing PDF usage tracking, which may warrant further investigation.
Dashboards (primarily in Google Data Studio) are the primary consumption method for analytic data. Export to CSV for ad hoc analysis would be of additional benefit. Data Studio may support this to some extent although no research has yet been done to assess its capabilities in this area.<br>
slide28. Analytics Recommendations Goal: Provide NAO with better visibility of how content is consumed
Recommendations:
Review existing Google Analytics configuration and optimise to provide more granular tracking Assess whether the MonsterInsights plugin is adding value
Assess content groupings as a technique for capturing progress through specific user journeys
Review Data Studio usage and explore whether dashboards can be enhanced to deliver new metrics<br>
slide29. Accessibility Insight The website was the subject of a recent accessibility audit, for which it received a score of 7 out of 10.
The site scores reasonably well against a selection of high profile accessibility assessment tools. For example, it has an 85% compliance score at www.webaccessibility.com.
Anecdotally, there are some known issues with the responsiveness of the site on some device types, particularly smaller screens. Some of the embedded assets which use HTML iframes also have a higher degree of accessibility issues.<br>
slide30. Accessibility Recommendations Goal: Ensure NAO content can be consumed effectively by users with additional needs and on all device types
Recommendations:
Identify tactical targets for improvement based on the latest audit results and automated scans using standard accessibility tools
Optimise WordPress templates to increase responsiveness of iframe content to improve visualisations<br>
slide31. SEO Insight Google tooling is also used to some extent already to measure search engine optimisation performance, although this is obviously skewed toward a Google perspective. A WordPress plugin called Yoast is currently active on the site and its efficacy is unclear. No specific SEO concerns have been raised during research, although confidence in the status quo is uncertain.<br>
slide32. SEO Recommendations Goal: Ensure NAO content ranks high in search engine listings for relevant keywords and related searches
Recommendations:
Optimise existing WordPress templates to ensure that tags and any additional metadata that are introduced are exposed to search engines using standard protocols
Review content production workflows to ensure content is optimised for SEO
Review efficacy of the Yoast plugin<br>
slide33. Security & Compliance Insight The website must be compliant with various privacy legislation, including:
GDPR/DPA
PECR
Its cookie implementation is not currently compliant with PECR, although there are ongoing efforts to rectify this.
Given that the website does process some personally identifiable information (PII), a PII log should be kept and a data privacy impact assessment should be undertaken. No evidence of these was found.<br>
slide34. Security & Compliance Recommendations Goal: Ensure the NAO website protects sensitive data, is highly resistant to common threat vectors and complies with all applicable legislation
Recommendations:
Explore implementation of identity federation to provide seamless, integrated access control
Conduct a data protection impact assessment (DPIA) and create a personally identifiable information (PII) log
Continue ongoing efforts to implement compliant cookie handling<br>
slide35. Delivery Models<br>
slide36. Software as a Service (SaaS) Description: Procure a website platform as a commoditised service which is hosted and managed by the supplier on the customer’s behalf<br>
slide37. Outsourced Development Description: Engage a supplier to create and maintain a website solution independently based on NAO requirements. Can be structured as an ongoing relationship with one supplier or as discrete units of work, potentially across many suppliers.<br>
slide38. Augmented Development Description: Work collaboratively with a supplier to create a website solution based on NAO requirements. Generally requires building a good working relationship with a single supplier.<br>
slide39. Appendix Alternative options<br>
slide40. Platform Goal: Provide a well understood, secure, affordable and functional platform on which NAO content can be effectively distributed to its users<br>
slide41. Hosting Goal: Ensure the NAO website is highly available, cost-effective and manageable by NAO in-house staff<br>
slide42. Content Goal: Ensure NAO website users are able to find and consume reports and related content easily<br>
slide43. Search Goal: Provide an enhanced search experience across the NAO website<br>
slide44. Tagging Goal: Make it easier for users to find the NAO content they’re looking for and other, related content<br>
slide45. Data Goal: Expose the underlying data sets that are used within NAO reports and visualisations<br>
slide46. Analytics Goal: Provide NAO with better visibility of how content is consumed<br>
slide47. Accessibility Goal: Ensure NAO content can be consumed effectively by users with additional needs and on all device types<br>
slide48. SEO Goal: Ensure NAO content ranks high in search engine listings for relevant keywords and related searches<br>
slide49. Security & Compliance Goal: Ensure the NAO website protects sensitive data, is highly resistant to common threat vectors and complies with all applicable legislation<br>