Jump to content

Recommended Posts

Posted

Hello all,

 

I am just curious what methods others use to protect teachers laptops when they are at home, other than A/V.

 

At school we have filtering to block malicious sites but at home there is no such protection. I am thinking of setting something up for the hosts file, but I wondered if anyone knew of anything that was more automatic?

 

Cheers,

 

Paul

Posted
other than A/V.

Some of the things I have done...

 

  • Enable AppLocker and setup rules to prevent executables/scripts from running.
  • Install EMET to help protect against zero-day exploits (among other things).
  • Block adverts in Google Chrome (using the URLBlacklist policy) so there is less chance of getting infected via malicious ads.
  • Keep browser plug-ins like Flash Player and Java up-to-date.
  • Install the latest Windows hotfixes as soon as possible after Patch Tuesday.
  • All users have standard accounts. i.e. no teachers in the local admin group.

Posted (edited)

As @MatthewL states, not making them administrators is a start.

 

But also make sure the Stall Laptop AUP covers things like:

 

The Laptop is to be used by the staff member only and not to be used by Siblings, etc.

The Laptop cannot be used for any peer to peer sharing activities.

 

I've personally found that most of the issues are caused by Siblings using the Laptop and visiting Joke sites, game hack sites, serial generators, or using Peer to Peer sharing sites.

 

Just to add, having the Laptops back for Microsoft Updates and using Anti-Virus as others have said.

 

But a lot can be said about the IT awareness of the end user :doh: .

Edited by Davit2005
Posted
Don't make them administrators on their own machines, and make sure that your Windows Lockdown GPO is properly configured. Any malware would require admin rights to install, and UAC should prompt the user for admin credentials when malware tries to install. If they bring the laptops into school each day, then having them back for Windows updates should be irrelevant as long as you have WSUS configured correctly. It could also be worthwhile pushing out a group policy that uninstalls Java as it's rarely needed and has myriad security holes.
Posted

Sophos also has "live protection" which reduces the need to keep its local malware signature database updated, great for roaming clients whose update server is behind the firewall. There are of course other ways of achieving this (publishing the update distribution point on a public facing server for example.

 

I do have to say that with web protection and live update the number of infected staff machines I see is massively less than even three years ago.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...