Jump to content

Recommended Posts

Posted (edited)

We have produced a policy which is agreed to by myself and my colleagues entitled "IT Support Privacy and Confidentiality Policy".

 

Basically it states that we don't look at their stuff, and if we see it accidentally, we ignore anything we read and don't act upon it in any way.

 

If we NEED to open someone's home directory or mailbox, we only do it with their permission and record it in a log book stating who provided permission.

 

Does anyone else have a policy and procedures simnilar to this?

Edited by AnnDroyd
Posted

The staff at your school should be aware that the school owns all electronic communications made from the school and that the Head and their appointed repesentatives (you) have access to their electronic communications.

 

It is nice that you log it, but not strictly necessary. The other staff should assume you behave in a professional manner just as you assume they do. Or to put it another way, just because they behave in an unprofessional fasion does not mean everyone else does.

 

You should have an ICT Acceptable Use Policy, agreed by the governors, SMT and Unions, within the school which covers all of this. If not suggest the school contacts their LA for a recommended one.

 

Skunk

Posted

Why do you need this document? I dont see why you need to reassure people. We are all professionals and as such our job concerns what is stored on the network. As a professional I would only look at someones files if i thought there was a reason too and not just because I could. If you want a policy written to cover you for any reason then that is a different matter. Our acceptable use policy states that the network is provided by the school for school work. As such anything stored on it can be checked for content.

 

I'm sure this subject has been covered somewhere on here before and I'm sure someone will point it out?

Posted
We have a policy which is agreed to by myself and my colleagues entitled "IT Support Privacy and Confidentiality Policy".

 

It's written by ourselves to try to reassure people that we don't sit in front of a server reading their emails and documents all day!

 

Basically it states that we don't look at their stuff, and if we see it accidentally, we ignore anything we read and don't act upon it in any way.

 

If we NEED to open someone's home directory or mailbox, we record it in a log book stating why it was necessary and which member or SMT or owner gave us permission.

 

Is this an appropriate way to provide assurance that we act in a professional manner as far as other peoples privacy is concerned?

 

What about the students do you not check what is in there areas?

Posted

I'm afraid, that on our systems staff and pupils do not have 'privacy' - the servers are there for one purpose and one purpose alone - to be used in teaching and learning, and to aid that process. Anything stored on them is accessible by the SMT on demand and by myself whenever I see fit - for example to cull mp3 files that shouldn't be there.

 

The concept of saying that they have privacy simply doesn't come into it as far as I'm concerned. However, this does not mean I simply go reading people's files. I act professionally and only do what I need to do for my job.

Posted

We say to staff ... the laptops, the servers, the internet connection, the printers and consumables ... they are all paid for by the college. If we do not ave reason to believe you are taking the mickey we will not start being the thought police. (We previously had to lock down 'Net access for admin staff as they were truly taking the mickey by using the online music stations ... all day long ... about 10 different ones! ... not including some nice little money earners buying and selling on ebay!)

 

To Students we say ... all school equipment is there for the benefit of your education. Abuse it and you lose it.

 

We tell all what we have the ability to do to ensure that we are happy that noone does take the mickey ... and students know that when their 1.7GB collection of Manga pdf files goes ... it is because we are not happy with them abusing things. It is usually followed up by a friendly warning ... then a not so friendly removal of email and lock down of net access ... and finally a locked down login that only gives them access to run word, excel and powerpoint.

 

We have the power but we only used it when seriously required.

Posted
Be aware that if you do stumble across some types of content (ranging from bullying to child porn and everything in between) you have a duty to report it to the SMT/Police/etc.
Posted
Surely your servers are also used for administrative purposes, and therefore may contain medical, personal, personnel and disciplinary details which are none of your business to be reading? That's why I think it's important to install confidence that IT staff do not read files in other people's folders.

 

As far as kids are concerned, we need to control what they are downloading, saving and sending to their friends to a point, but there's no reason to be trawling through their emails just because we can.

 

Course you should check them, it is possible that one of the children could be a potential victim of paedophilia via the internet what unfortunately seems to be a common recurrence. When you work at a school you have a duty to look after the children who attend.

Posted

All of this is covered under the Data Protection Act & RIPA Act which your school is subject to.

 

We have an acceptable use policy at our school that runs into 65 pages for both staff and students and basically says the we reserve the right to monitor, intercept, and access any electronic communication or file that passes over the network.

 

But as GrumbleDook says as long as they don't take the mickey they have nothing to worry about.

 

In 3 years I have never had a member of staff or student question the AUP and it is also revised on an annual basis.

Posted
Surely your servers are also used for administrative purposes, and therefore may contain medical, personal, personnel and disciplinary details which are none of your business to be reading? That's why I think it's important to install confidence that IT staff do not read files in other people's folders.

 

As far as kids are concerned, we need to control what they are downloading, saving and sending to their friends to a point, but there's no reason to be trawling through their emails just because we can.

 

Course you should check them, it is possible that one of the children could be a potential victim of paedophilia via the internet what unfortunately seems to be a common recurrence. When you work at a school you have a duty to look after the children who attend.

 

That almost sounds as if you are saying we should look at every single file and read every single email just in case ...

 

This is neither practical or reasonable. That is what filters were created for and that is why most schools employ someone as Child Protection Officer. If you want to do your best for duty of care for the student make sure you work in concert with the CPO as they have been on a heap more courses than you or I are liely to have been on, and will be able to say what is reasonable on the grounds of eSafety.

Posted
Surely your servers are also used for administrative purposes, and therefore may contain medical, personal, personnel and disciplinary details which are none of your business to be reading? That's why I think it's important to install confidence that IT staff do not read files in other people's folders.

 

As far as kids are concerned, we need to control what they are downloading, saving and sending to their friends to a point, but there's no reason to be trawling through their emails just because we can.

 

We are all covered by the Data Protection Act, and as such we legally have to follow it. You don't need a policy to cover something that is already covered by the law.

Posted

The policy is not just there for your piece of mind but to also inform staff of your duties in accordance to the DPA, FoIA and other such pieces of legislation.

 

However, the DPA does not cover the reading of all emails, something which when you do it for a student or group of students you could be accused of gaining information prior to grooming (there are cases about this!).

 

If you take Jonathon's view he wants to make sure that staff and students are aware that they, and the school, are taking reasonable steps to make sure that information is only accessed when appropriate (something that is covered in the DPA) and that they log it (good working practices).

 

There are many laws that apply to schools but we still sign pieced of paper to say that we agree with what the school is commenting on or rules it has set out.

 

IMHO this seems no different to signing to say you agree to abide by H&S rules of the school ... something that is embedded in most job contracts.

Posted

IMHO, if you need your department to sign a specific piece of paper to re-assure staff that you're working and not just sitting there reading their emails, then you have a wider trust/confidence issue (and in that situation, the presence of that bit of paper probably does nothing to reassure them).

 

Our users (staff and students) know that we can see everything in their area, plus their Internet activity (and putting the occasional sacrificial lamb in detention helps to re-iterate this!), however they also trust that we don't go looking unless we need to. Our AUP (plus the DPA) states, as many others already listed, that the resources belong to the school and will be used how we see fit.

 

For staff, this includes checking the contents of areas / Internet activity if we believe that resources are being misused or that something inappropriate is happening (either child protection related, or simply time wasting) but does not include looking at their holiday snaps because we think their daughter is cute. With students, we will always check their areas before granting extra space and we run monthly web-activity reports on all the students.

 

(do I over-use brackets, by the way?)

Posted
I agree, however does it really need another policy document? How about an AUP line which reads "IT Staff, the SMT and others at their discretion can view files and Internet activity in accordance with the requirements of their job" or something similar...
Posted

The point is, that it is extra work for no real gain. It makes people think that there has been a problem with it and therefore you needed this policy. This is just one of those situations where I think informal is better than formal.

 

Otherwise we would need policies for caretakers opening lockers etc... It just makes extra work for no real gain.

Posted
we don't wave it in front of them. It's just there if anyone asks.

So you haven't told your users that you can and do monitor content and activity? You need to rectify that at once - you can only take action (internal discipline or legal) following what you find if you have told the users beforehand that you check. Get something in your AUP which says that you do this, then expand upon it in your internal policy if you wish, but your users MUST know that Big Brother is watching.

Posted
We don't monitor what staff do, that's the point! The policy is saying that we'll only go into their folders with their specific permissions, and the log sheet supports that.

We don't spend any time monitoring staff either, but you need to have something in place which says that you CAN. Heaven forbid this would actually happen, but suppose that in the regular course of your job you find something nasty in a staff member's folder, perhaps you notice a dubious filename in the backup log or something. If your AUP states that you can view these files, you can open that file, see that it's illegal, fire the teacher and pass it over to the Police and CPS. Without that in your AUP, all you can do is go and ask that teacher "excuse me, Mr X, I'd like your permission to look in your MyDocs folder as I want to see if that mpeg is pornographic".

 

Even if you don't monitor staff activity, you need to state that you can. A statement to the effect that you're doing it "as part of your responsibilities" covers you should you suspect something nasty, but also says that you don't go looking in there just for kicks and giggles.

 

It's a shame that we need to think along these lines, but that is sadly the world in which we live today.

Posted

Something that may be pertinent here is that all schools are under the jurisdiction of the RIP Act and as such, a notice has to be presented to users at log on to state that in accordance with the law, the school and the ISP of the school (usually either your county council and/or the RBC for your area) could be and do monitor the use of the internet.

 

All computers in Somerset have the same notice on them.

Posted
Not sure they have to get that message every logon do they, localzuk? Surely a signed AUP is sufficient? Please do correct me if I'm wrong here...
Posted
Not sure they have to get that message every logon do they, localzuk? Surely a signed AUP is sufficient? Please do correct me if I'm wrong here...

 

Somebody could forget to sign an AUP or it could be mis-filed / lost. If they click to say they accept everytime they log on you are covered. Also covers you if anybody external uses the connection, i.e. external visitors, anybody else who might use it.

Posted

One thing we are doing this year (or will do when we can get it out to them) is include a class list for each form. Once all the AUP agreement forms are back in the Form tutor hands it back, we file the originals, a user-defined field in SIMS is updated (AUP Date - the date that an AUP was last returned signed) and the class-list is placed in a folder tha can be easily accessed by any member of the team or any staff that requests a look (usually because some student will say 'I never signed it')

 

All external visitors have to sign the AUP Agreement Statement before they get access to a temporary account, unless specifically agreed and logged with me.

 

We also have on our AUP Agreement Statement an opt-out clause for the use of student photos by the school. This is something that will also be logged on SIMS at the same time.

Posted
We don't monitor what staff do, that's the point! The policy is saying that we'll only go into their folders with their specific permissions, and the log sheet supports that.

 

Think the point nick was trying to make you don't hve to active monitor to be monitoring it.

 

You have a filter system in place i assume that log internet access by using that and not telling staff you arr breaking the law as the system logs usage which means it is monitoring.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...