Jump to content

Recommended Posts

Posted

I've just been told by a supplier that under the new Ofsted inspections if your hard drives aren't encrypted you lose a point.

 

Has anyone else heard this?

Posted

We were inspected in May and Ofsted never came anywhere near the IT side of things so they wouldn't know.

 

As an academy on the other hand (and as a maintained school by the LA audit's actually) our backup procedures came under scrutiny and the Academies Financial Handbook mentions that all backups should be securely stored (and I'm pretty sure it mentions encrypted too).

Posted
Technically this is true under the new framework but in reality most ofsted inspectors are not qualified to actually inspect schools and seem to award points arbitrarily based upon some sort of political judgement. As usual they never came near our IT dept when we last saw them.
Posted (edited)

For small and easily stolen/misplaced devices (such as laptops, tablets and any removable media) then yes, they should be encrypted if used to store confidential information. For desktop machines this isn't as necessary AFAIK since they are somewhat harder to steal short of a full late night break-in. For extra protection, desktops can be forced to save files on a network drive so the data is actually held in your locked and bolted server room, no data leaves with the stolen device.

 

EDIT - I should note that even with files stored on a network drive, temp files containing sensitive data can still be generated and not cleared properly or files accidentally saved in the wrong place. Full disk encryption helps to mitigate the loss of these files if the device is stolen.

Edited by CAM
Posted
I wonder what that supplier is trying to flog you :)

 

Ben

 

Yes, that was my immediate thought too!

 

I shall be mentioning the replies here about recent Ofsted inspections when they call back.

Posted

There is NO mention of the word encrypt or encryption anywhere in the OFSTED School Inspection Handbook Sept 2012. There is also no mention of it in "The Framework for School Inspections" published in April 2013.

 

However... in the Sept 2012 Briefing for Inspectors, encryption is mentioned... as in a lack thereof can be constituted an indicator of inadequate eSafety practice (refer to "Inspecting e-safety", Ref 120196, rel. Apr2013)

 

I suspect that it's down on paper to satisfy the ICO for whom encryption is considered a necessity for Data Protection purposes, but in reality no inspector is clued up / qualified enough to determine on-site whether you've encrypted relevant devices or not other than just taking your word for it / making note that the word "encryption" crops up somewhere in your eSafety policies.

 

So, make of all that what you will. We ALL know that any laptops / usb sticks / devices likely to be leaving school property SHOULD be encrypted...

  • Thanks 1
Posted
I've just been told by a supplier that under the new Ofsted inspections if your hard drives aren't encrypted you lose a point.

 

Has anyone else heard this?

Rubbish!

 

We have just had Ofsted in at our Governor school and it wasn't even discussed. It sounds like a sharp salesmansip to me. (being polite about the sales drone here)

Posted
There is NO mention of the word encrypt or encryption anywhere in the OFSTED School Inspection Handbook Sept 2012. There is also no mention of it in "The Framework for School Inspections" published in April 2013.

 

Rubbish!

 

We have just had Ofsted in at our Governor school and it wasn't even discussed. It sounds like a sharp salesmansip to me. (being polite about the sales drone here)

 

It's under the e-safety section:

Ofsted | Briefings and information for use during inspections of maintained schools and academies

in the file called "inspecting e-safety.doc"

 

It states "Indicators of inadequate practice: Personal data is often unsecured and/or leaves school site without encryption."

Technically this will score you a 4.

 

but like I said: The VAST majority of inspectors don't seem to understand their own frameworks, or completely ignore them.

Posted (edited)

The mention of encryption comes under "Indicators of Inadequate Practice" and says:

 

 Personal data is often unsecured and/or leaves school site without encryption.

 

This is not the same as encrypting all your hard drives!

 

As mentioned earlier, stuff that goes offsite should be encrypted and everyone should be aware of that. Stuff onsite, has to be secured, but not necessarily encrypted.

 

EDIT

 

Ofsted definition of encryption from the same document (my bold)

Computer programme that scrambles data on devices such as laptops and memory sticks in order to make it virtually impossible to recover the original data in event of the loss of the device; schools often use this to protect personal data on portable devices.
Edited by elsiegee40
Posted
Yeah. I though this is what we were talking about - encrypting hard drives ?

There are hard drives on PCs in the school and these do not need to be encrypted. Portable devices would be laptops and memory sticks etc

We dont encrypt anything and all the staff have laptops which go off-site. Ofsted didnt mention it.

I have mentioned it many times with no success

Posted
There are hard drives on PCs in the school and these do not need to be encrypted. Portable devices would be laptops and memory sticks etc

We dont encrypt anything and all the staff have laptops which go off-site. Ofsted didnt mention it.

I have mentioned it many times with no success

 

I know. The whole ofsted thing is utter BS because if they never stick to the critera schools can only ever get an arbitrary score.

Posted
There are hard drives on PCs in the school and these do not need to be encrypted. Portable devices would be laptops and memory sticks etc

We dont encrypt anything and all the staff have laptops which go off-site. Ofsted didnt mention it.

I have mentioned it many times with no success

 

Whilst it isn't related to OFSTED, I would urge you to review this practice to satisfy the ICO as declaring a data breach when one of those devices gets lost and ends up in the wrong hands won't do the school much good either.

Posted
We were "done" a few weeks ago got outstanding and the only thing they wanted from IT was the wireless password. All staff however do have istorage encryped USB sticks just for good practice really.
Posted
We were "done" a few weeks ago got outstanding and the only thing they wanted from IT was the wireless password.

 

You made them sign an AUP before letting them on the guest network, right?

 

(Not kidding - no AUP, no access here).

Posted (edited)

I've not heard of Oftsed getting funny about data encryption, however I do know that the Schools Financial Value Standard talks about getting business critical data offsite on a daily basis... if you're taking removable media offsite, then yes you have to encrypt it, as per the Data Protection Act (enforced by the ICO). This is only relevant to LA maintained schools however and not often mentioned to key staff in schools as the Governors fill it in.

 

The Academies Financial Handbook did mention secure locations for backup, but then went on to talk about floppy disks for backup... in the 2013 revision it doesn't seem to worry much about backup of data at all.

Edited by Vintage82
  • 2 months later...
Posted

Of course this is good practice.

BUT, my school has been had an Ofsted recently (outcome: Good) and they didn't ask about any encryption whatsoever !

Posted
Of course this is good practice.

BUT, my school has been had an Ofsted recently (outcome: Good) and they didn't ask about any encryption whatsoever !

 

 

yep. Sounds about right.

Technically you can only get an inadequate.

Ofsted inspectors don't understand the framework they judge schools on.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...