Jump to content

Recommended Posts

Posted

Hi,

 

We are looking at purchasing Tasc Insight Parent Portal Software. Before making any commitments, we felt it wise to assess the security of the product. It is our understanding that the software is installed on a Windows Server running IIS. Firewall rules would then be altered to allow external access to the IIS site for parents. We are a little concerned that by providing this inbound access, we may become vulnerable to additional exploits.

 

Has anybody got any advice relative to security and this product? We are thinking of installing it on a Windows Server 2012 R2 which is also our Forest Root Server.

 

Thank you,

Posted

Been running it fine for 3 years on our web server, no problems so far.

 

We use SSL as this was requested by a parent.

 

We have it running on windows 2008 R2, I would personally run it on a dedicated web server PC.

  • Thanks 1
Posted

As the access is provided via a box running IIS you have a certain responsibility to ensure that it is suitably hardened, that only the relevant ports are made available and that you have a healthy patch / release management regime.

 

This is true of any web service though, but especially important as you assess the risk to data which is being served / accessed via this machine.

 

The same is true of VLEs, CMIS ePortal, etc ...

  • Thanks 3
Posted
Been running it here for a few years now with no problems, dedicated 2008r2 running iis7, ssl also in use, only allow 443 traffic through for that server in firewall rules and also use their two tier authentication. Great value for £1 per student, plus a bit extra if you want the parents evening booking system which works well here.
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...