Jump to content

Recommended Posts

Posted

I really don't understand the mentalilty of some of these answers. God forbid the students should learn something eh? It's not like they're at school to learn or anything is it? Oh... wait...

 

I don't see the problem with these questions. Some of them perhaps should be answered in broad terms, especially given that they are trying to learn something for a curriculum assignment so would need answers framed in a context suitable for that anyway.

 

If anyone really thinks that students knowing that something called "a GPO" (or "SCCM" or whatever) is how you install software genuinely puts your network security at risk then your network security simply isn't adequate anyway. This is kinda like the big fear some people have over letting students know that a command prompt exists... On a properly secured network it should not be an issue, and if your network isn't properly secured then the answer is to secure it, not to pray that no one notices the emperor has no clothes.

  • Thanks 4
Posted
If your network isn't properly secured then the answer is to secure it, not to pray that no one notices the emperor has no clothes.

 

Absolutely. Security by obscurity is no security at all really...

Posted
God forbid the students should learn something eh?

 

I don't think it really has anything to do with dampening their education, or wanting to. The tendency, for IT techs, is to feel very protective of the network. This is amplified by the rogues we all know exist in schools - especially so in the higher years, simply because they (the rogues) are, generally, smarter and more daring. Unfortunately, this can have a negative impact on the more well behaved kids that genuinely do want to learn.

 

Based on the Y11 IT curriculum content I have seen, my initial thought was 'why would they need to know anything like this for their coursework?' - but Y12 might be a far cry from Y11.

Personally, I certainly wouldn't 'give up the information' without thoughts of possible consequences, which could be huge!

In the end, whether I answered the questions in the OP or not would depend entirely who was asking. If i felt the kids were trustworthy enough with the info then I would be happy to help. Others I have met in schools wouldn't stand a chance!

Posted (edited)
I don't think it really has anything to do with dampening their education, or wanting to. The tendency, for IT techs, is to feel very protective of the network. This is amplified by the rogues we all know exist in schools - especially so in the higher years, simply because they (the rogues) are, generally, smarter and more daring. Unfortunately, this can have a negative impact on the more well behaved kids that genuinely do want to learn.

 

I've worked in schools, so I do know what you're talking about.

 

Having said that I currently work with devs. They are definitely smarter, more aware of the measures taken to protect the network, have more experience, and the ongoing 'friendly' tussle for control of the network and security is far, far more intense than anything I've ever experienced in a school.

 

I still don't see how any of the questions above could provide them with any information to poke holes in even one of my security measures. If telling someone the DR plan, or what I look for in an assistant, is going to help them penetrate my network I stick by my original statement - I should be looking for a new job.

 

Now if they started asking for passwords, or to borrow my security token, or to get access to my server room without me present that would be a different matter.

 

Based on the Y11 IT curriculum content I have seen, my initial thought was 'why would they need to know anything like this for their coursework?' - but Y12 might be a far cry from Y11.

 

My initial thought was 'great, someone actually taking an interest in real IT rather than the dross they pass off as a curriculum, wonder if I could sort out an apprenticeship'. But each to their own.

Edited by jamesb
Posted
Hi, We have been asked some questions by our 6th Form IT class and wondered what other peoples responses would be. We would be grateful if a few of you fellow edugeekers could post some answers. Thanks

 

1. What disaster recovery techniques are used?

 

Backup to Disc then Backup to tape. Second server room. Large site with distributed storage of assets.

 

2. How often is system security reviewed? How often are audits carried out?

 

Full strategic reviews : 3 years. We operate configuration change control which may trigger review.

 

3. Is there an email or Internet usage policy? What are the limits for staff and students?

 

Yes. Limits are under review, currently 5GB mail, 50GB storage for students.

 

4. How do you monitor for software installation?

 

Various, from scanning storage for .exe's and various monitoring tools.

 

5. Does the centre have a policy for use of CCTV?

 

Yes.

 

6. What are the most common risks you face in managing the network?

 

Data loss via "pressing wrong keys error". Data security via people taking personal data offsite using unsecured devices/services.

 

7. What proportion of your budget do you spend on equipment and software?

 

Do you mean the school budget? ISTR 2%.

 

8. What do you look for when recruiting and hiring technical staff?

 

Specific skills + ability to learn + a customer service focus.

 

9. How are network and system security delegated?

 

Not sure I understand the question.

 

10. What training do you offer your staff?

 

Very little if it is not associated with H&S, safeguarding or development of teaching staff. We allocate some budget to books and encourage staff to allocate time to develop their skills.

Posted
I've worked in schools, so I do know what you're talking about.

 

Having said that I currently work with devs. They are definitely smarter, more aware of the measures taken to protect the network, have more experience, and the ongoing 'friendly' tussle for control of the network and security is far, far more intense than anything I've ever experienced in a school.

Poor you, I used to do that, devs are a nightmare on a network, you get the feeling like you are running on a treadmill made of black cats, under a ladder while seeing yourself in the remains of a pallet load of mirrors you have just smashed. Its bad enough in schools where they are learning but chaos when the people actually have a pretty good idea of how some of the stuff actually works.

 

On topic, with broad answers I see no issues with the questions asked.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...