Novalee Posted March 19, 2015 Posted March 19, 2015 Hi, I seem to remember reading on here, sometime over the last few years, a link to a news article about a situation in a school which arose from staff computers being left unlocked. Currently trying to show just how important it is to lock computers and this would be helpful - anyone remember it?
Davit2005 Posted March 19, 2015 Posted March 19, 2015 Un-authorised access to SIMS or any other MIS system leading to confidential personal information falling into wrong hands Un-authorised access to confidential files - because as far as the system knows the logged in user is the person acessing the files. Less restrictive filtering
TechMonkey Posted March 19, 2015 Posted March 19, 2015 Hi, I seem to remember reading on here, sometime over the last few years, a link to a news article about a situation in a school which arose from staff computers being left unlocked. Currently trying to show just how important it is to lock computers and this would be helpful - anyone remember it? I haven't got a link but there was an anecdote about a school that was in legal proceedings after a member of staff left a computer unlocked and someone (pupil or staff unknown) forwarded an email that was meant to be confidential. I'll see if I can dig it up.
Novalee Posted March 19, 2015 Author Posted March 19, 2015 I haven't got a link but there was an anecdote about a school that was in legal proceedings after a member of staff left a computer unlocked and someone (pupil or staff unknown) forwarded an email that was meant to be confidential. I'll see if I can dig it up. That sounds like the one! I can't seem to find anything on Google but if you can find it I would be ever so grateful!
GrumbleDook Posted March 19, 2015 Posted March 19, 2015 IIRC it was either me or Ephylon relating something from the eSafety Law in Education group, talking about how having AD sign in to your MIS was not a good idea. The scenario is this. Teacher A is delivering a lesson in the classroom, has the laptop connected to the projector and has screen frozen ash they are taking the class register using a tool in the MIS. Access to the MIS is provided by clicking on an application to start and it immediately signs you in with no further requirement to enter a username or password. Teacher A runs lesson, with a variety of materials being shown to the class. Teacher A has to move round the class to work with learners, but stuff stays on screen so laptop left unlocked. Teacher A has to leave room to deal with something and laptop is left unlocked 'so learners can continue'. Teacher is only just outside but Student Z goes to laptop, opens MIS (or brings it to the front), searches for details of child in that class or another class, and information is displayed on screen ... this could range from attendance through to any statements or medical needs the child has. Out of the schools who have had to sign undertakings with the ICO at least one has been related to improper access to MIS data. In one case the MIS was tied to the AD, and so was the VLE and other things ... so when a member of staff shared their password the children involved had access to everything ... and they *did* access a lot of things ... apparently. Thankfully nothing happened as a result (no bullying, injury, etc) but should the information be used to cause any form of harm the projection is that a serious case could and would be brought. For DPA breaches we are in the hands of the ICO and as yet no fines have been imposed on schools ... only colleges / universities / LAs. Is that what you were looking for?
maniac Posted March 19, 2015 Posted March 19, 2015 This is why a majority of my workstations auto-lock after 10 minutes of in-activity. It annoys the hell out of staff, but if we don't have it the amount of workstations that were left unlocked around the academy was astounding.
Ephelyon Posted March 19, 2015 Posted March 19, 2015 @GrumbleDook, could well have been either of us. I know that's the precise argument as to why SSO for the MIS is not enabled on our site... On a side note, is the data on schools that have had to sign undertakings with the ICO on public record?
elsiegee40 Posted March 19, 2015 Posted March 19, 2015 (edited) @Novalee The story was mine here A Salutory Tale Edited March 19, 2015 by elsiegee40 1
GrumbleDook Posted March 19, 2015 Posted March 19, 2015 @GrumbleDook, could well have been either of us. I know that's the precise argument as to why SSO for the MIS is not enabled on our site... On a side note, is the data on schools that have had to sign undertakings with the ICO on public record? I did a FoI request in my previous job but don't have the data to hand nor can I reuse it (terms of my old contract). Someone could always ask again.
Garacesh Posted March 20, 2015 Posted March 20, 2015 @GrumbleDook, could well have been either of us. I know that's the precise argument as to why SSO for the MIS is not enabled on our site... Not that it helps.. Staff just sign in to SIMS and minimise it >.<
Novalee Posted March 20, 2015 Author Posted March 20, 2015 @Novalee The story was mine here A Salutory Tale Thanks everyone - lots of interesting information here. Thank you @elsiegee40 - I can't click the link though! I'm not having the best tech week haha!
elsiegee40 Posted March 20, 2015 Posted March 20, 2015 @Novalee There's a bug with the browser version of edugeek today. I will copy and paste the text into here via the app!
elsiegee40 Posted March 20, 2015 Posted March 20, 2015 I have, today, been involved at a third party school in sorting out the fallout from an avoidable incident. It involved an unattended computer with an email on the screen and someone photographing it with a mobile phone. The outcome is likely to be a constructive dismissal case against the school and a disciplinary for the person who left their computer unattended. It takes seconds for someone to take a photo. It takes minutes for a screen to lock automatically... possibly never Lock your screen or logoff... it is not worth the risk! Here you go
Novalee Posted March 20, 2015 Author Posted March 20, 2015 Thank you Elsie - what is constructive dismissal against a school? I understand it against a person, but how does that work against an establishment? Just out of curiosity more than anything.
elsiegee40 Posted March 20, 2015 Posted March 20, 2015 (edited) Thank you Elsie - what is constructive dismissal against a school? I understand it against a person, but how does that work against an establishment? Just out of curiosity more than anything. The constructive dismissal case was due to the content of the email displayed on the screen which the subject took exception to. Edited March 20, 2015 by elsiegee40
tommej Posted March 20, 2015 Posted March 20, 2015 Was it this? Computer hacker gains access to work documents of Peterborough academy principal - Peterborough Telegraph
TechMonkey Posted March 20, 2015 Posted March 20, 2015 @Novalee The story was mine here A Salutory Tale Ha, I thought it was you but couldn't for the life of me find it!
Davit2005 Posted March 20, 2015 Posted March 20, 2015 Was it this? Computer hacker gains access to work documents of Peterborough academy principal - Peterborough Telegraph Reading through that story with a pinch of salt as always (actual truth isn't probably going to be let out) A user walking off leaving their PC unlocked and someone else coming along and sending emails under the users logged in account or some one using a password left on a post it, I'd hardly think this would be correctly labeled as a hacking incident . If some one hacked user accounts and passwords etc from a system that might be different story Same a if a password is on a post it note on the desk it wouldn't take much of a hacker to get into the system would it?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now