Jump to content

Recommended Posts

Posted

Based on a Trust wide move to RM Broadband and RM Safetynet, I've seen how not run a project. Chuck it in and let's see what happens!

Internet speed/reliability wise, it's been good. A few apps died and required configuration updates. The big issue, if filtering. Recently, Youtube restricted mode was turn on and in no time at all a teacher is understandably she can't play a video for teaching. As best I can tell, we have a global setup, with no granularity - no separation between staff and pupils. I'm clear that User Based Filtering isn't turned on. I'm interested to hear from others who have moved to RM SafetyNet and how the project was managed well. In particular, just how much of a project is it to implement UBF and start whitelisting some Youtube videos for key staff?

 

In the immediate term, I'd be interested to hear how I can get a restricted video playing for a teacher. At the moment it feels as it is a Youtube restriction and not a SafetyNet filtering block. I'm wondering if I set up a Google account (we have GSuite but not widely used), whether there is a short term fix.

Posted
We set staff users to staff proxy so they have to login for unrestricted mode. I prefer this as it means staff have to think before they access something potentially NSFW. They can also have one browser logged in to staff proxy and another not which they can display without fear of unwanted stuff showing. RM want to get rid of staff proxy but I like it.
  • Thanks 1
Posted
If your on the new version of RM Safetynet, you can configure up to 4 proxies each with a different level of filtering, so we have our default which the kids used, a staff one which has Youtube and a few other sites unblocked and then an "unfiltered" one which allows facebook and other social media. Group policy then just pushes out the correct proxy address to the user. Previously we used the staff proxy option. UBF is fairly straightforward, the major barrier to us because of the legacy network setup is resetting everyone's password to allow the passwords to be sync'd.
  • Thanks 1
Posted (edited)
Based on a Trust wide move to RM Broadband and RM Safetynet, I've seen how not run a project. Chuck it in and let's see what happens!

Internet speed/reliability wise, it's been good. A few apps died and required configuration updates. The big issue, if filtering. Recently, Youtube restricted mode was turn on and in no time at all a teacher is understandably she can't play a video for teaching. As best I can tell, we have a global setup, with no granularity - no separation between staff and pupils. I'm clear that User Based Filtering isn't turned on. I'm interested to hear from others who have moved to RM SafetyNet and how the project was managed well. In particular, just how much of a project is it to implement UBF and start whitelisting some Youtube videos for key staff?

 

In the immediate term, I'd be interested to hear how I can get a restricted video playing for a teacher. At the moment it feels as it is a Youtube restriction and not a SafetyNet filtering block. I'm wondering if I set up a Google account (we have GSuite but not widely used), whether there is a short term fix.

 

Honestly I'd take it up with whoever manages it at a trust level for multiple reasons, #1 They can provision you with an account in SafetyNet so you can manage your establishment, Safetynet has trust level management and individual school based management and #2 RM SafetyNet has a feature specifically made for student/staff YouTube policies which I found worked pretty well when I used SafetyNet so if you get that admin account for your school you can then add youtube videos to the allowed list. #3 UBF isn't much of a project as it syncs with your schools active directory and you just select which filter lists apply to which groups and when (they have some lists that come with it which are relatively extensive but obviously you're going to want to add your own).

 

Like you said, sounds like the trust has not thought the implementation through at all. :/

Edited by TDupont992
  • Thanks 1
Posted
If your on the new version of RM Safetynet, you can configure up to 4 proxies each with a different level of filtering, so we have our default which the kids used, a staff one which has Youtube and a few other sites unblocked and then an "unfiltered" one which allows facebook and other social media. Group policy then just pushes out the correct proxy address to the user. Previously we used the staff proxy option. UBF is fairly straightforward, the major barrier to us because of the legacy network setup is resetting everyone's password to allow the passwords to be sync'd.

We are on the new version and I can see all 4 point to the same address. UBF sounds straight forward but our NM is just saying it's a 'big' job... and working on other IMHO less critical tasks. I believe I have appropriate access, I guess I need a user guide to move forward, but your setup sounds much like we need.

Posted
We set staff users to staff proxy so they have to login for unrestricted mode. I prefer this as it means staff have to think before they access something potentially NSFW. They can also have one browser logged in to staff proxy and another not which they can display without fear of unwanted stuff showing. RM want to get rid of staff proxy but I like it.

Is that logging in with a school Google account. I've learnt all our pupils have an account but not many staff. It's all being managed by a capable GSuite qualified teacher, but realistically the admin needs moving to someone else. With just four weeks of my contract left, I'll have to see if they will be interested.

Posted
Like you said, sounds like the trust has not thought the implementation through at all. :/

That's for sure! Unfortunately the MAT escalation isn't an option right now - can't say why here, but big changes in who does the IT support coming for next term.

Posted

UBF requires a little bit of work with a bit of planing.

 

You'll need to install the Unify sync tool on one server and then the password filter on all DC's. Passwords for all users will then need to be reset and then UBF will work when pointed to the correct UBF proxy.

 

That's why we make use of the 4 proxies at the moment as due to some peculiarities to our network I can't just reset all passwords at the moment (long story), so various groups point to the different proxies set via group policy.

Posted

User based filtering is an absolute requirement these days - if you're not doing it (without a really good risk assessed reason) you're not going to be meeting your safeguarding obligations under the Keeping Children Safe in Education statutory guidance.

 

KCSIE itself doesn't say you have to be able to identify your users, but it does signpost to the UK Safer Internet Centre's guidance which does explicitly say you have to identify users and have age appropriate differentiated filtering. If you're not meeting the Safer Internet Centre's guidance, you really need to have carried out a risk assessment showing why you think you don't need to.

Posted
User based filtering is an absolute requirement these days - if you're not doing it (without a really good risk assessed reason) you're not going to be meeting your safeguarding obligations under the Keeping Children Safe in Education statutory guidance.

 

KCSIE itself doesn't say you have to be able to identify your users, but it does signpost to the UK Safer Internet Centre's guidance which does explicitly say you have to identify users and have age appropriate differentiated filtering. If you're not meeting the Safer Internet Centre's guidance, you really need to have carried out a risk assessment showing why you think you don't need to.

 

We have RM Safety Net. We dont have user-based filtering. RM tell us that they can, if necessary, identify users when issues arise. We have age appropriate filtering in that staff have access to a staff proxy which unblocks contents, and students do not.

I find Safety net very good and very responsive if there is a problem.

  • Thanks 1
Posted
RM tell us that they can, if necessary, identify users when issues arise.

 

I'd be fairly interested in how they can do that - they will be able to tell what IP address requests come from, but figuring out which user was using that IP at the time isn't going to be trivial.

 

In any case, I'm definitely of the opinion that this isn't good enough - if you have to jump through a load of hoops to figure out which user was looking at some concerning content, that's simply never going to happen except in the most serious cases. You should be getting regular automated safeguarding reports from your system telling you which individuals (not IP addresses) you need to be concerned about. If your filter can't do this, replace it with one that can - it isn't as though there's a shortage of good filtering systems out there at the moment.

Posted
Like the one you work for, maybe? :)

 

If you like, but there are plenty of others too.

 

I just know from experience that our reports flag up all sorts of things which are important for safeguarding, yet if you had to put in some effort to figure out who the user is you probably wouldn't bother. I'm sure this is true of other vendors' systems too - my point isn't about trying to sell you one specific solution, I'm trying to point out that there are significant safeguarding opportunities that are being missed if you can't get regular safeguarding reports that provide a zero-effort identification of the users.

 

The fact that you said "RM tell us they can" suggests to me that you have never asked them to, whereas to most of our schools this is routine stuff and they find the information very useful.

 

The UKSIC guidance specifically says your filters should identify users and provide safeguarding reports. I know it's open to some interpretation, but I'm pretty sure they didn't mean "well you can probably figure out who the user is if you put lots of effort in".

 

 

(Note: there are specific cases where our customers decide not to identify users. However, I've never seen this being done on a "whole network" basis and would strongly advise against that if any customer suggested it. Usually its a short-term measure, providing an interim solution to a problem while a long term fix is being implemented).

Posted
I'm not affiliated with any provider but I tend to agree with @SteveHill on this. Personally on this sort of thing I've not found Ofsted even probed the topic in the inspections I've been part of. From a MAT perspective, I think it'll very much depend on individual views. I've not visited it for a while, but perhaps it is an area covered under https://360safe.org.uk/ - it's something that is a useful framework to review where your school is at and where it could aim for.
  • Thanks 1
Posted
If you like, but there are plenty of others too.

 

I just know from experience that our reports flag up all sorts of things which are important for safeguarding, yet if you had to put in some effort to figure out who the user is you probably wouldn't bother. I'm sure this is true of other vendors' systems too - my point isn't about trying to sell you one specific solution, I'm trying to point out that there are significant safeguarding opportunities that are being missed if you can't get regular safeguarding reports that provide a zero-effort identification of the users.

 

The fact that you said "RM tell us they can" suggests to me that you have never asked them to, whereas to most of our schools this is routine stuff and they find the information very useful.

 

The UKSIC guidance specifically says your filters should identify users and provide safeguarding reports. I know it's open to some interpretation, but I'm pretty sure they didn't mean "well you can probably figure out who the user is if you put lots of effort in".

 

 

(Note: there are specific cases where our customers decide not to identify users. However, I've never seen this being done on a "whole network" basis and would strongly advise against that if any customer suggested it. Usually its a short-term measure, providing an interim solution to a problem while a long term fix is being implemented).

 

Bolded is key, safeguarding is such a wide issue with so many aspects that it needs to be as seamless and streamlined as possible, so many potential risks that one extra step for each becomes a large staircase.

Posted
OK - sarcasm aside - thanks for that BTW - very professional. We dont do the reporting etc, they do. We have had them in to explain how and what they do re "dodgy" stuff and as I say, Ofsted and the MAT seem quite happy.

As for regular reports - I have never needed to ask for this sort of report in the 10 years I have been at this school

 

Sorry Witch I don't think he was being sarcastic and he is right on receiving regular reports about users and their activity.

Posted
Sorry Witch I don't think he was being sarcastic and he is right on receiving regular reports about users and their activity.

 

He is right I am sure but the phrasing was...well anyway...we dont get any reports like that.

Posted
He is right I am sure but the phrasing was...well anyway...we dont get any reports like that.

 

Well without being at all sarcastic you should!

  • Thanks 1
Posted

How well schools across the UK use their online safety systems to help them to do their safeguarding is certainly quite variable - it's not helped by the extremely vague KCSIE statutory guidance (which is 112 pages long, only 3 of which discuss the huge topic of online safety). The guidance from the Welsh Government is much better, frankly, and I think everyone would do well to have a read through it even if you're not based in Wales - it gives much more rigorous guidance about what kinds of content different age groups should have access to, and focusses on education rather than prohibition.

 

In England, the guidance (KCSIE) says you've got to do something "appropriate", and allows schools to decide what that means based on their own risk assessments, but it does signpost to the UKSIC guidance as an example of what schools might choose to do. To my mind, since the UKSIC guidance has been signposted, schools really need to treat this as the default minimum - if you're not going to meet that guidance you need to have carried out a risk assessment which explains why you don't think its necessary.

 

In the past, Ofsted haven't been very consistent at looking at what schools are doing in this regard - you certainly don't need to try very hard if you just want a tick from Ofsted, rather than making sure you meet your statutory obligations (although I've also heard of cases where Ofsted inspectors have assessed a school's internet filtering based on some fairly crazy criteria!). In May, the UKSIC noted that the new Education Inspection Framework included references to "online safety", but I must admit that I couldn't find those references when I read it myself!

 

Also remember that this is increasingly not just about online safety and blocking access to "dodgy websites" - the online activities of students can provide early warning of a lot of offline concerns - self harm / depression, abuse, drug use, etc. "Internet filters" are now being seen as another tool to help with general safeguarding, and the online safety industry is certainly embracing this challenge, moving towards profiling the users to provide warnings of all kinds of things to allow early intervention by staff.

 

So there's certainly a range of how well a school can utilise these systems, ranging from "doing the bare minimum to scrape through an Ofsted inspection", to "doing the statutory minimum", all the way up to "using all the tools at their disposal to ensure the best outcomes".

 

All these are of course my own opinions based on working closely with schools, discussing with other online safety businesses and reading as much published guidance as possible (both official and unofficial). I don't, however, actually work in a school - everyone's welcome to their own opinions and I think everyone learns from having those opinions voiced and discussed.

Posted
I have consulted with the MAT and they have consulted with whoever deals with this and they all agree that in a junior school such as mine, user-level reporting is not necessary.

 

Sorry Witch - they're wrong! But if you've got it in writing then at least you're covered I suppose.

Posted
Sorry Witch - they're wrong! But if you've got it in writing then at least you're covered I suppose.

 

I'm told that the official advice is foggy and not very specific. If someone could point me to the more specific stuff I would be very happy

Posted (edited)

@witch Steve Hill already has.

 

"Online safety

84. As schools and colleges increasingly work online, it is essential that children are

safeguarded from potentially harmful and inappropriate online material. As such,

governing bodies and proprietors should ensure appropriate filters and appropriate

monitoring systems are in place. Additional information to support governing bodies and

proprietors keep their children safe online is provided in Annex C. "

 

This is from Keeping Children Safe in Education which is the statutory guidance.

 

Basically as Steve has already said when you read the KCSiE guidance and the UKSIC guidance alongside the Prevent documentation if you're not logging against individual users and receiving reports then you're going to need some very convincing risk assessments to cover why you're going against the guidance on these matters.

 

If you never see any information on who went where online whilst at school and you don't use user based filtering then you're failing on many levels - if you're not using user based filtering you cannot say who did what, you cannot provide age appropriate filtering and you cannot be sure what they are doing when a member of staff cannot see their screen.

 

If the students log onto the device using individual credentials then there's no reason not to keep track of their behaviour and monitor/report on it. If they don't then they need to be given individual accounts and if they're too young for this then they can use systems like Clever badges to log in.

 

I do find it quite worrying how blasé some primaries seem to be about monitoring the usage of their students.

 

None of this is any kind of a criticism of you though @witch !

Edited by Primus
Posted

Not that every pupil doesn't know the password of at least 1 person in their class, because it's 123456, or they shouted it, or the teacher shouted it, or they told them because they wanted to be friends.

 

Why is fingerprint reading still bad/expensive?

Posted

Pieces of essential reading:

Keeping Children Safe in Education: This is the DfE's statutory guidance that all schools in England must follow by law. This guidance is pretty vague, just saying that "appropriate" filtering and monitoring must be in place. It doesn't define what "appropriate" means, but does say that it should be driven by a risk assessment. It signposts to the UK Safer Internet Centre's "Appropriate Filtering and Monitoring" guidance as an example of what a school might do.

 

Appropriate Filtering and Monitoring: This is a set of documents published by the UK Safer Internet Centre to put a bit of meat on the bones of KCSIE. This is a pretty good resource - it includes some brief guidance and self certification information from many of the filtering/monitoring vendors describing how their systems can fulfil this guidance. There's nothing in KCSIE that says you have to follow this guidance, but it does cite it as an example so in my opinion schools should consider this to be the baseline and if they feel there's a good reason for not meeting this baseline they should carry out a risk assessment explaining why. In reality, the vast majority of filtering systems on the market support user identification, so I think a school will struggle to sensibly justify why they have chosen one of the few that don't do this when they come to do a risk assessment.

 

Recommended web filtering standards for schools in Wales: This only applies to schools in Wales, but is well worth a read by everyone. This recognises that a school's role is not only to keep children safe while in school, but also to give them the skills they need to be safe outside of school to. So the focus is much more about education rather than prohibition. It also provides a much more rigorous guidance as to what types of content to restrict, and what to allow, for different age groups.

 

Prevent Duty Guidance: Not a huge amount of value here in my opinion - the bits relevant to this discussion really just say that schools need filtering.

 

At the end of the day, it is up to the school though. The key message is that the school should be doing a risk assessment to decide what they need their filtering and monitoring systems to do, and obviously there's a cost:benefit argument to be had here. But if you are choosing to increase the risk for no good reason then that's obviously a problem and you're going to struggle to complete a risk assessment that justifies doing that - I'd have to argue that this is exactly what a school is doing if they opt to not identify users across their entire network, and not to run regular safeguarding reports without a very good reason.

 

Filters are not 100% reliable and you'll never know if people are accessing things that you would've expected the filter to block unless you run reports. There are also things you don't want to block, but do want to be notified about, and you can't do that without regular reporting.

 

We had a recent discussion with an Ofsted inspector on this subject, who indicated that good routine reporting (and acting on those reports) is what Ofsted wants to see, but as I previously mentioned I'm not convinced about the consistency and rigour of Ofsted inspections in this regard.

 

 

Obviously there's plenty of people on edugeek who are pretty knowledgeable and experienced on the subject, and I'm certainly always happy to answer questions, give advice based on my experience and our interpretation of the legislation and good practice, discuss the technical practicalities, etc. I don't pretend to be familiar with every filtering system out there, but I'm always happy to give "generic" advice and don't just tell everyone to buy our products. :)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...