carnforthhigh Posted November 20, 2013 Posted November 20, 2013 Hi, We have been asked some questions by our 6th Form IT class and wondered what other peoples responses would be. We would be grateful if a few of you fellow edugeekers could post some answers. Thanks 1. What disaster recovery techniques are used? 2. How often is system security reviewed? How often are audits carried out? 3. Is there an email or Internet usage policy? What are the limits for staff and students? 4. How do you monitor for software installation? 5. Does the centre have a policy for use of CCTV? 6. What are the most common risks you face in managing the network? 7. What proportion of your budget do you spend on equipment and software? 8. What do you look for when recruiting and hiring technical staff? 9. How are network and system security delegated? 10. What training do you offer your staff? Once again Thanks
LosOjos Posted November 20, 2013 Posted November 20, 2013 These all seem like things that are going to be specific to your school... tell them the truth? (or at least a slightly embellished/idealistic version of!)
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 We have prepared our answers for them, we just thought it would be interesting to see how others would answer them
IrritableTech Posted November 20, 2013 Posted November 20, 2013 I'm doing a presentation to some of our students this week covering the same info. The teacher in the class needed to cover the "LO2 Understand the issues related to use of information" (OCR I think) He sent me this from the syllabus Legal issues: data protection legislation (e.g. Data Protection Act 1998) Freedom of Information Act 2000 other relevant legislation (e.g. Computer Misuse Act 1990) copyright considerations. Ethical issues: • examples of ethical issues (e.g. moral, whistle blowing, disability, use of information) • codes of practice (e.g. email,internet, internal policies, intellectual property, content) • other (e.g. reporting bad practice or breaches). Operational Issues: • security of information (e.g. backups) • health and safety (e.g. processes,procedures,regulations) • organisational policies • costs (e.g. for development, modification, training, system upgrades) • continuance planning. I think relating it to a real organisation will help their understanding. The only thing I would note is your students should be well aware of the answer to question 3!
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 Our answer to question 3 is "you tell us!" as like you said they should be well aware of this
sippo Posted November 20, 2013 Posted November 20, 2013 Our sixth formers would never ask us questions like that. They're simply not clever enough.
Earthling Posted November 20, 2013 Posted November 20, 2013 Our sixth formers would never ask us questions like that. They're simply not clever enough. Ours can't even understand the phrase, 'We don't provide BYOD facilities here'. On a more serious note, my immediate first answer would be, 'Why do you want to know all of this?' Then I'd discuss with their course teacher just how much of this information should be given to them. Questions 2 and 4 would only get answered in the broadest terms, with Q4 possibly not being answered at all. Question 9 would be filed under 'That's Classified'. Then I'd tell them what I think they should know.
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 It is part of their course they are doing, there teacher did help them put the questions together so its not like they have asked without them knowing.
detjo Posted November 20, 2013 Posted November 20, 2013 lol .. i'd be asking: "and how do you plan to use this information to hack our network?" 2
LosOjos Posted November 20, 2013 Posted November 20, 2013 We have prepared our answers for them, we just thought it would be interesting to see how others would answer them Oh I see, sorry, misunderstood the thread
pantscat Posted November 20, 2013 Posted November 20, 2013 All of them seem like perfectly reasonable questions, especially if any of them are seriously considering a career in IT. I personally found that the IT and computing curriculum didn't give me a true idea of what a career in IT would entail and only really found that out thanks to a really excellent IT teacher that explained about IT infrastructure (back when NT was king) and how things really worked. Some of our sixth formers occasionally show an interest in IT and so we show them the main server room and answer any questions that they might have... probably only happens once a year though! The only thing we don't disclose is budget information or anything that would be deemed "sensitive".
SovietRussia Posted November 20, 2013 Posted November 20, 2013 (edited) 3. Is there an email or Internet usage policy? What are the limits for staff and students? Should they not already know this? If there is one - They would have had to sign it. 6. What are the most common risks you face in managing the network? Students. With Malware USB sticks. Edited November 20, 2013 by SovietRussia
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 3. Is there an email or Internet usage policy? What are the limits for staff and students? Should they not already know this? If there is one - They would have had to sign it. Yes, our answer to them is "You tell us"
Earthling Posted November 20, 2013 Posted November 20, 2013 lol .. i'd be asking: "and how do you plan to use this information to hack our network?" Exactly that.......that would be my first and foremost concern, and never mind their course requirements.
unixman_again Posted November 20, 2013 Posted November 20, 2013 I would hope that the answer to Q4 is "Only IT staff have the access rights to install anything".
SovietRussia Posted November 20, 2013 Posted November 20, 2013 Exactly that.......that would be my first and foremost concern, and never mind their course requirements. I wouldn't even give up information about management (GP, AD), if they want to learn - find it!
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 I would hope that the answer to Q4 is "Only IT staff have the access rights to install anything". Exactly that, specifically IT Technical Staff!! not even the IT Teachers
jamesb Posted November 20, 2013 Posted November 20, 2013 No idea if this'll help you or not, but thought I'd answer from my own (non-school) perspective. 1. What disaster recovery techniques are used? Off-site warm room with fifty seats for 'essential' staff (definition of essential is somewhat controversial) in case of office incidents. For anything less than the building burning down our live network is provided by an MSP, mirrored between two data centers in different parts of the country. 2. How often is system security reviewed? How often are audits carried out? Bi-annually for security reviews on the live network, annually for our ISO 27001 audit. On the dev network (my area) security reviews are an ongoing process. 3. Is there an email or Internet usage policy? What are the limits for staff and students? Two, depending on which network you are on at the time. The live network policy is a lot more stringent than the dev network policy due to information sensitivity. They both essentially boil down to 'don't be a moron'. 4. How do you monitor for software installation? On dev we use Spiceworks to reduce the instances of iTunes and similar. On live no software can be installed, everything is provided by app streaming or browser so workstations are nothing more than terminals. 5. Does the centre have a policy for use of CCTV? Yup. We don't have it anywhere other than shared areas. 6. What are the most common risks you face in managing the network? Air conditioning breaking down in my case. Just recently I had a server burn out when the server room hit 90 degrees over the weekend. 7. What proportion of your budget do you spend on equipment and software? Less than 10%. 8. What do you look for when recruiting and hiring technical staff? It depends entirely on the role. Usually it's a case of hiring developers so generally the right experience on the CV. Speaking for myself if I were hiring an assistant I'd be more interested in general experience, adaptability and a demonstrated enthusiasm for the area. 9. How are network and system security delegated? Me. 10. What training do you offer your staff? Whatever's appropriate to their role and required by project, carried out by external training providers. Once again Thanks No problem. I wouldn't even give up information about management (GP, AD), if they want to learn - find it! I work with sensitive data, and I'm quite happy to tell people about any of our security practices (in fact twice a year I have to do so, as well as documenting them). If a little information about group policy is going to let someone break into my network I should really be looking for a new job rather than trying to keep them ignorant. 2
SovietRussia Posted November 20, 2013 Posted November 20, 2013 I work with sensitive data, and I'm quite happy to tell people about any of our security practices (in fact twice a year I have to do so, as well as documenting them). If a little information about group policy is going to let someone break into my network I should really be looking for a new job rather than trying to keep them ignorant. So am I happy to share, I was refering to the fact that they are students, and might want to do some research than listen to me harp on.
jamesb Posted November 20, 2013 Posted November 20, 2013 So am I happy to share, I was refering to the fact that they are students, and might want to do some research than listen to me harp on. I partly agree, although I'd give them the basics as a jumping off point. Research is all well and good, but if they've never heard of Active Directory it could be a long, frustrating and pointless search.
carnforthhigh Posted November 20, 2013 Author Posted November 20, 2013 Thanks jamesb, just out of interest what kind of company do you work for?
jamesb Posted November 20, 2013 Posted November 20, 2013 Thanks jamesb, just out of interest what kind of company do you work for? No problem at all. One of the government corporations (i.e. set up through legislation, regulated by it but not tax payer funded), the Pension Protection Fund.
pete Posted November 20, 2013 Posted November 20, 2013 We do something similar here. Once a year, I teach a lesson on some of the topics covered in the OP using real-world examples from the school network, as well as bigger networks such as Google, Amazon etc. Where possible I tell the truth or an abstracted version if they'll have trouble grasping the concept.
tech_guy Posted November 20, 2013 Posted November 20, 2013 Here's my answers: 1. What disaster recovery techniques are used? A. Praying and swearing with a lot of crying. 2. How often is system security reviewed? How often are audits carried out? A. All the ********* time. 3. Is there an email or Internet usage policy? What are the limits for staff and students? A. Yes, but nobody reads them. Limits - are you serious? We have staff setting fire to themselves in the playground if you stick a quota on anything! 4. How do you monitor for software installation? A. We don't allow software installation. Students use chalk and a piece of slate. 5. Does the centre have a policy for use of CCTV? A. Yes, but everyone ignores it. We have outbreaks of mooning. 6. What are the most common risks you face in managing the network? A. Caffeine overdosing. 7. What proportion of your budget do you spend on equipment and software? A. Not enough. It's never enough. Even if they gave me £100k a year it would never be enough. Rant over. 8. What do you look for when recruiting and hiring technical staff? A. Arms. And legs. And a head. They help. 9. How are network and system security delegated? A. If you're the IT Bod it's your job. Same rule applies to anything with a plug on the end. 10. What training do you offer your staff? A. How to deliver the best ever Chinese Burn. 2
gwendes Posted November 20, 2013 Posted November 20, 2013 If a little information about group policy is going to let someone break into my network I should really be looking for a new job rather than trying to keep them ignorant. ^THIS (plus, lol)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now