Jump to content

Recommended Posts

Posted

What access does a Cashless Cater system Provider need to SIMS.

 

I am being asked for:-

 

Administration Assistant

Admissions Officer

Attendance Manager

School Administrator

System Manager

Third Party Reporting

Personnel Officer

 

At first glance this looks rather a lot.

 

If anyone could provide what access there provider has I would be very grateful.

 

Chilbs

Posted (edited)

System Manager

Personnel Officer

 

Not sure I'd give them System Manager, they could add permissions themselves then which is a bit cheeky. Also not sure why they would need access to staff records like personal details :S

 

EDIT:

Also

Admissions Officer

Attendance Manager

 

seems odd. Also, why don't suppliers export a security group for you to import, it's a really nice feature in Sysman7!

Edited by matt40k
Posted
I would be reluctant to give system Manager Permissions: as Matt40k points out, that essentially gives them access to everything. It seems like a catch all for them so that they don't have to worry about troubleshooting permissions. I would also be reluctant to give Personnel Officer and Attendance Manager. I don't see why a cashless catering system would need the permissions that come with those - maybe Attendance Operator and Personnel Assistant would be more appropriate. Also be careful of the School Administrator group - it sounds innocuous, but its permissions are quite wide ranging and its often confused with Administration Assistant.
Posted

@Disease Did you give them that access?

@stariq I don't believe that they need that level of access to get the job done.

 

It does very much feel like they are asking for a lot I feel like I need to get them to justify themselves as they are asking for Full Access. Even my own user account can only do administration of the system, basic details and lookup timetables of people and rooms. The IT team have deliberately shut ourselves out of certain sections for day to day access as we just don't require it certain things to do our job therefore we do not have access.

Posted

Going to take this higher but my current stance is:-

 

Administration Assistant

Third Party Reporting

 

Then they can ask for specific things after that

 

As Matt40k points out they should give me an export of the exact details they need and nothing more.

Posted
From a legal point of view you need to be aware of the data items they are taking out of your system and satisfy yourself that they are strictly necessary.
Posted
Are they asking for the account to use and login with or is this for using data extraction technology and using the permissions in a more automated way, or through reports? Not that it makes much difference from a legal perspective, @PhilNeal is spot on there.
Posted
I have given them the Administration Assistant and Third Party Reporting. They are going to contact me to discuss.
Posted

Our Cashless catering account has those permissions, but they don't have the password. As it's a scheduled task, we setup the user details for it on the server :)

 

Steve

Posted
This isn't so much a password issue as the school's responsibility as a data controller/processor. If data is passing out from the school to a TP then the school MUST ensure that only data that is required to do the job is passed out and that a contract exists between the school and TP that states what data is being released. The fair processing notice also needs to inform parents/pupils that this is happening also.
Posted
This isn't so much a password issue as the school's responsibility as a data controller/processor. If data is passing out from the school to a TP then the school MUST ensure that only data that is required to do the job is passed out and that a contract exists between the school and TP that states what data is being released. The fair processing notice also needs to inform parents/pupils that this is happening also.

 

Well only can speak for our lot, but servers on-site, and no-one has access remotely etc without us doing it :) Guess it depends on what system/company.

 

Steve

Posted
I hope you didn't create the SIMS account @Steve21!! It's important that steps like @PhilNeal has stated are followed, this how vulnerabilities occur, you shouldn't assume that it is secure just because only you know the password! Just look at Heartbleed, just because large companies like Google assume something is secure does't mean you should. Far as you are aware the schedule task is sucking all the data out all your data then the application is uploading to some server in China. Limiting the scheduled tasks\application isn't going to stop that, but it will at least limit the amount of damage that it could cause. It's not like it's difficult either, few clicks and you've gone from potential releasing an entire schools information - everything from SEN data, to staff bank details and everything inbetween - to a heck of a lot less (still not great of course)
Posted

Nope not myself Matt, but guess my point being a lot of these services need higher than normal permissions (ok maybe not sys etc), but as an example Emerge wanted:

 

• Personnel Officer

• School Administrator

• Senior Management Team

• Third Party Reporting

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...