GrumbleDook Posted April 22, 2009 Posted April 22, 2009 Becta have updated their guidance on data handling and it can be found at Becta Schools - Data handling security guidance for schools. The "Dos and Don'ts" and the Quick Wins are pretty on the button, the language is a chunk simpler and more usable with others but there are still pretty detailed instructions in the various docs. Ray Fleming has also been having a read of them too so expect a blog post from him about it soon. Don't forget to go on the Becta collaboration forums to give feedback as well. 1
GrumbleDook Posted May 6, 2009 Author Posted May 6, 2009 Have people had a chance to look at this yet and what do they think of it compared to the previous docs?
leco Posted May 6, 2009 Posted May 6, 2009 Have people had a chance to look at this yet and what do they think of it compared to the previous docs? Sorry - have downloaded them but haven't had a chance to actually read them yet:( Will post when I have as I'm hoping they may give valuable info.
maniac Posted May 6, 2009 Posted May 6, 2009 I can't remember the old versions of these, but I've scanned through these documents relatively quickly, and they seem very helpfull, well laid out and easier to read than some documents I've downloaded from the BECTA site.
PiqueABoo Posted May 6, 2009 Posted May 6, 2009 (edited) what do they think of it compared to the previous docs? That they've now been written more for the audience rather than cut&pasted out of nasty CESG/whatever docs with all those orders (MUST do blah). Have only skimmed, but they're more accessible and much less silly now. Still there a bit, but it's interesting to see the de-emphasis of the categorisation stuff. Again no especially useful info/suggestions on what may or may not need PROTECTing.. now seems to leave that to "whatever DPA says", but people tend to know what that is so there's probably more mileage in it. The do's & don'ts was a good idea. This bit from RA security caught my eye: "Authentication mechanisms support X.509 client certificates (typically for student access to learning platforms and portals)". Is it fair to assume that's more or less what they think entry-level remote auth. security ought to be i.e. staff access needs more? Edited May 6, 2009 by PiqueABoo
localzuk Posted May 7, 2009 Posted May 7, 2009 The Do's and Don't's is good. It'd be a good place for those of us crafting AUPs etc... One thing to add to that particular document - if a laptop is left somewhere in a school, such as on a desk, it may be physically secure - ie. chained their by a lock, but if the person doesn't lock it, or disables the screensaver/auto-lock then data could be compromised. I think something mentioning that should be in a Do's and Don't's document really.
leco Posted May 7, 2009 Posted May 7, 2009 I agree, the Do's and Don'ts was in a language that anyone could understand. It also mentions, several times, to consult your IT team, not always done but at least they have been told. The Data Encryption one, which I'm currently reading, appears somewhat ambiguous. At one point recommendation is made for whole disc encryption and file/folder level encryption. I'm left a little confused as to which is best or which to implement under what circumstances. However, all may become clear when I've read the whole paper.
elsiegee40 Posted May 7, 2009 Posted May 7, 2009 I missed this it when you posted... I'll spend some time on it over the weekend going through it again. Thanks grumbledook
PiqueABoo Posted May 7, 2009 Posted May 7, 2009 I'm left a little confused as to which is best or which to implement under what circumstances. Well you don't need Becta for that - full disk encryption whenever you can because it's a lot more reliable than some folk will be at a) deciding something needs to be encrypted, and b) actually encrypting it. That's a no-brainer for data on staff laptops, it's servers that are more interesting. Do you or don't you do/risk full disk encryption on those.. the overheads shouldn't matter on a typical server with oodles of MIPs to spare... but if they're seriously physically secure is it worth the trouble given the very low risk of someone running off with one. Same argument applies to server folder encryption. Lots of factors, no one-size answer.
russdev Posted May 7, 2009 Posted May 7, 2009 The Advice sets that within the network is secure once outside the school network is not secure. So servers/desktops are fine but laptops which are taken away from school need to be encrypted Russ
Mr.Ben Posted May 7, 2009 Posted May 7, 2009 Anyone found the install guide for TrueCrypt? The guidlines say its at Open Source Schools, but i can't find it!
GrumbleDook Posted May 7, 2009 Author Posted May 7, 2009 I think that the guide (which was in the previous version of the guidance) was meant to be put up on the Open Source School site ... I'll check with Miles and co. 1
GrumbleDook Posted May 7, 2009 Author Posted May 7, 2009 Anyone found the install guide for TrueCrypt? The guidlines say its at Open Source Schools, but i can't find it! Apologies are given for this ... the guidance is awaiting some formatting / conversion to be web friendly and in hand with the folks at Open Source Schools. A version of it will be attached onto this thread tomorrow in the interim. There is a version of the guide in the previous guidance that I can send over if you are desperate but I would say to wait until tomorrow.
leco Posted May 7, 2009 Posted May 7, 2009 Well you don't need Becta for that - full disk encryption whenever you can because it's a lot more reliable than some folk will be at a) deciding something needs to be encrypted, and b) actually encrypting it. That's a no-brainer for data on staff laptops, So are you saying that I should encrypt full discs on all staff laptops, figuring that they will be off the network at some point or other? Whilst on the network their files may or may not be encrypted as they come from an unencrypted file server within the school (and incidentally the Regional GfL). Now I am totally confused:confused:
GrumbleDook Posted May 7, 2009 Author Posted May 7, 2009 The mobile device should have disk level encryption as it can be taken off-site and is at risk of increased access and loss of device. On-site you should use encryption or additional protection on those areas that require it (eg storage of SEN data) but no requirement for disk-level encryption because there is little chance of physical access to the machine. The additional protection may be to consider increased control and ownership over folder / file permissions or to place in password protected folders (therefore require authentication at login and then a password to access the folder. The main reason for encryption is the high risk of loss of mobile devices and storage. 1
leco Posted May 7, 2009 Posted May 7, 2009 Thanks GrumbleDook I really must get my head round this folder permission thing. I guess it is possible to set permissions on certain folders on the file server, so that only certain individuals have access? Only two teacher laptops have local user access, all of the others have network only. However the rest do have offline file and folder access, so do I still need to have disc encryption for the laptops? Also disc encryption for the USB pen drives that they all use? How do I prevent the teachers, for instance, from transferring the files from the laptop, via the USB, to their home computers? Minefield, can of worms, ease of use, slow machines..... it's all getting a bit heavy, when all the teachers want to do is write the end of year reports. I do understand the issues just not sure how to explain it all to my users not to mention implement it all.
PiqueABoo Posted May 7, 2009 Posted May 7, 2009 (edited) The Advice sets that within the network is secure once outside the school network is not secure. Yes. But. The real-world isn't binary, you need to engage brains and adjust to fit (and I'm sure the Becta authors would agree). For instance machines can end up outside the school without consent. This guidance applies to Primaries too and I can think of a couple of local cases where after breaking into the office and presumably not finding the petty cash box or anything else especially interesting they've settled for office computers, some of which have contained personal data.. and of course that's data on the little ones which typically generates about 100 times the public concern/panic compared to teenagers. Thus in my corner of the world, the LEA who tend to implement and look after most of the SIMS boxes for Primaries are starting to use full system encryption on them. That makes perfect sense to me. So are you saying that I should encrypt full discs on all staff laptops, figuring that they will be off the network at some point or other? Yes or at least make that a starting point and see if you can find any credible reasons why you shouldn't do that for any particular staff laptops. Realistically this isn't that hard to do and it's not hard for the users either, so my view is that it's worth doing even when the risk in any given case is relatively small. Edited May 7, 2009 by PiqueABoo 1
localzuk Posted May 8, 2009 Posted May 8, 2009 Thanks GrumbleDook I really must get my head round this folder permission thing. I guess it is possible to set permissions on certain folders on the file server, so that only certain individuals have access? Only two teacher laptops have local user access, all of the others have network only. However the rest do have offline file and folder access, so do I still need to have disc encryption for the laptops? Also disc encryption for the USB pen drives that they all use? How do I prevent the teachers, for instance, from transferring the files from the laptop, via the USB, to their home computers? The answer is simple - do the laptops go off site? Is there a possibility of them containing data that needs to be secured? If yes to both then disk level encryption is needed. USB keys - some of the software available allows you to control USB access if I recall correctly - ie. only allow disks which are encrypted to be used, and if one that isn't encrypted, it disallows access until it is encrypted. I'm sure I didn't dream that (but might have done!). Minefield, can of worms, ease of use, slow machines..... it's all getting a bit heavy, when all the teachers want to do is write the end of year reports. I do understand the issues just not sure how to explain it all to my users not to mention implement it all. This is the crux of the problem, the explanation for staff. In schools, there is a culture of insecurity as far as I can see. People don't take it seriously. Offices with filing cabinets full of data are left unlocked, laptops are left with MIS systems on screen and unlocked etc... There needs to be a major shift in the way staff think, and I think this is an issue which needs addressing. How to get teachers to listen? 1
leco Posted May 8, 2009 Posted May 8, 2009 Not just how to get teachers to listen though - they do listen (in my school anyway) but do not understand what is meant. Plus if something slows down their machines or their access, thus slowing the lesson, then it's the network at fault and I must do something about it. Speed is such a relative thing.
GrumbleDook Posted May 8, 2009 Author Posted May 8, 2009 Miles has sent over the instructions for TrueCrypt and I have attached them. They will also be put onto the Open Source Shools site shortly and I will put a notice up in this thread when that is done. Eventually that will be the place to look (especially for updates to the instructions).How_to_install_and_setup_TrueCrypt.pdf 1
Jobos Posted May 8, 2009 Posted May 8, 2009 I wonder why Becta have chosen to use version 5.1 when the current version is 6.1?
russdev Posted May 8, 2009 Posted May 8, 2009 RE : Version Would be when it was written as this was in the first incarnation of the documents. Over my comment to do with in the network what I was referring to was comment of encrypting servers which said wasn't need for due to being in the network. Anything that might go out side the network should be encrypted. Russ
PiqueABoo Posted May 8, 2009 Posted May 8, 2009 what I was referring to was comment of encrypting servers which said wasn't need for due to being in the network. Some of those Primary SIMS boxes the local LEA are encrypting are perfectly real servers and the proportion of those can only get bigger (SIMS memory footprint almost doubled with the SQL 2K5 upgrade, if a school wants attendance etc. in classrooms you've got to run it on a server OS because of TCP/IP connection limits, they've got to add software for the same parental access to info as Secondaries albeit with a couple more years grace). The main difference is that they're likely to be smaller pedestal servers not bolted into racks, and the average physical security of that stationary cupboard or stuffed under a desk in a school office or whatever probably won't be as good as the typical Secondary equivalent. Relative budgets, space and so on.. Ultimately I think it would be unwise to exclude anything containing personal data from being a *potential* candidate for full encryption unless it has credible physical security. To be honest my starting position for server encryption was A Cold Day In Hell[tm], but I struggled to think of any really convincing objections besides this one: You can't restart it unless someone will be present to type in a password (or whatever).
PiqueABoo Posted May 8, 2009 Posted May 8, 2009 Miles has sent over the instructions for TrueCrypt and I have attached them. Mmmm... looking at the 981MB example, when it comes to USB I *completely* fail to see any mileage in faffing about with TrueCrypt for pensticks now when you can readily get ones with on-board encryption for reasonable prices e.g. £15 for 4GB, £25 for an 8GB. 1
GrumbleDook Posted May 8, 2009 Author Posted May 8, 2009 Yep, saw a good number of providers of secure USB sticks at InfoSec and they are good if you are picking up new USB sticks ... but remember that there are plenty USB sticks around already that teachers use ... you can't just throw them away so make the most of them.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now