Jump to content

Recommended Posts

Posted

I had a request today from one of our suppliers to send them the username and password for an affected user for the system. It got me thinking about suppliers in education and how many still don't seem to understand good security practices. I've dealt with another a while back who wanted us to email over all the personal details of our students via a normal email.

 

Why is security so low on the agenda still?

Posted
Why is security so low on the agenda still?

 

I think a lot of the time, it comes down to pure ignorance; they simply do not understand the security implications of what they're asking you. I can't count the number of times I've argued with people both inside and outside of the school about emailing sensitive data; their argument usually amounts to "of course my email is secure, I have to login with a username and password!"

Posted
On the flip side of that I have had an argument from someone who refused to send/receive any information via email because you couldn't be sure it was sent to the right person and you didn't know if it would get there. He also didn't seem to acknowledge that the system they were using meant that any letters we sent meant we could wait up to a week for a simple request or in the case were they were on holiday /off sick it would would sit on their desk until they got back. Oh and apparently letters never got lost and were much more secure. I gave up trying to explain why email would be a better solution after he complained about his email problems but refused to speak to his IT department. *To be fair it was a non IT role but I still couldn't understand their view*
Posted
It makes you wonder why we all still insist on Email being any sort of communication, given largely that its unsecure outside of using things like encryption, which people do not bother with only very rarely.
Posted
It makes you wonder why we all still insist on Email being any sort of communication, given largely that its unsecure outside of using things like encryption, which people do not bother with only very rarely.

 

It makes you think why that on the whole uts not been made more secure…

Posted

Why is security so low on the agenda still?

 

The path of least resistance. I would imagine they can get away with it with most schools, so they don't bother. It'll only be once the data owners collectively start getting narky about sending unencrypted data around the place that it will change.

Posted
My impression is that too many systems are the result of "back room development". Someone has a great idea and develops it, but they don't realise that there are certain security and data protection functions that must exist. I went to supplier only last week that had me seriously worried as there was little or no concept of basic security... and as for the test-development cycle, they were trying to sell me a system I was using as a programmer 30 years ago.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...