localzuk Posted December 11, 2014 Posted December 11, 2014 SHOULDN'T. Capita is a company made up of people. People make mistakes. Kinda irrelevant when the head of the division is blaming us as users...
synaesthesia Posted December 11, 2014 Posted December 11, 2014 In Phil's defence, I recall being taught to set it up with the S drive hidden (either via GPO or more commonly back then via CC3/4's management console) and very typically only the bursar, head and senco had access to the S drive; as that's where PST files were often stored, + they used the confidential folder, also locked down. Teaching staff didn't need to see the S drive. * Small disclaimer to that; I was never a SIMS installer for Capita but I was called upon to do it/help with it a couple of times. I would have questioned any dubious security practices there and then. As above, it's probably an issue with individuals; for all we know, this problem could have come from inside Capita in the first place and they are choosing to address it on a larger scale which is fair enough. 1
matt40k Posted December 11, 2014 Posted December 11, 2014 Kinda irrelevant when the head of the division is blaming us as users... An appeal to engineers that are installing SIMS on behalf of schools. A number of cases have come through to our support desk complaining about data protection issues because SIMS has not been installed correctly. In the latest complaint from a head all staff had access to the SIMS folder so they could see BACS files, the census etc. We also get a lot of performance problems reported because someone has virtualised the servers and given insufficient resources to SQL. Please do not assume that you can install SIMS simply by asking a few questions on EduGeek. Thanks Don't really read that as blaming, more a word of warning. Kinda like, don't rebuild your domain controller based on a few forum topics. 1
sparkeh Posted December 11, 2014 Posted December 11, 2014 Don't really read that as blaming, more a word of warning. Kinda like, don't rebuild your domain controller based on a few forum topics. Hmm, well I read that as quite condescending. I see that there has been no reply to the fact that a lot of sites setup by Capita engineers were setup exactly as Phil berated us lowly technicians for. 1
matt40k Posted December 11, 2014 Posted December 11, 2014 You can spend months waiting for someone to draft a post like that so it doesn't offend people, mean while the problem still exists. I accept it's kinda condescending, but it's like it an offense to be intoxicated (drunk) and in charge of a cow in Scotland - I'd thought that would have been a known, but you someone has got into trouble so they've have to make that law. You have to accept they have to cater for, the lowest and the highest. If it makes you feel any better, he said Engineer - he didn't say who those engineers are - far as we know he was refering to Capita Engineers haha!!
Jamman960 Posted December 11, 2014 Posted December 11, 2014 I wish capita would take security more seriously themselves, ours was also setup in this way by Capita Independent... I also recently had a Capita consultant moan about me changing one of the default passwords, I'm sure it was originally 123abc or some nonsence
DMcCoy Posted December 11, 2014 Posted December 11, 2014 While it is the Solus server I have recieved an email asking for the following permissions on the Sims server BY CAPITA to us (we support the school). Email from CAPITA "In regards to our recent conversation, please find below a list of permissions that we would recommend getting actioned. This will allow updates to write to the specific folders listed which should minimise any issues you have with your Solus environment and associated applications. C:\program files\sims\ C:\program files\solus3 C:\programdata\solus3 C:\programdata\capita C:\programdata\microsoft\crypto\RSA\Machinekeys - Always begins with 1db - Server C:\programdata\Microsoft\crypto\RSA\Machinekeys” 1db and 172 C:\windows\sims.ini Firewall Ports - 52965, 52966, 8739 Allow access to "everyone" - full control " I would point out there is no need for Everyone access to a single one of these locations Please talk to your own technicians please Phil before pointing the finger. I have often removed "Everyone - Full" from Capita shares and installs. 4
vikpaw Posted December 12, 2014 Posted December 12, 2014 I wish capita would take security more seriously themselves, ours was also setup in this way by Capita Independent... I also recently had a Capita consultant moan about me changing one of the default passwords, I'm sure it was originally 123abc or some nonsence Oh my, don't get me started on the default backdoor password policy. I bet I could hack in to multiple .ICT created setups. Probably from afar if they have SLG!
jimmckenna Posted December 12, 2014 Posted December 12, 2014 An appeal to engineers that are installing SIMS on behalf of schools. We also get a lot of performance problems reported because someone has virtualised the servers and given insufficient resources to SQL. Thanks Hi. what would you consider or what considerations do you advise when in terms of resources for a virtualised server? My LEA virtualised (VMWare) our SIMS server and I am not sure it is performing at it's best. Any suggestions would be helpful !! many thanks!!
Sivadam Posted December 12, 2014 Posted December 12, 2014 (edited) Things don't change much on here! Pity I have retired. I could have had a much more informed input. But why do people do the wrong thing and then blame the software or the suppliers! It seems that somebody else needs to pick up the cudgel I used to wield! Edited December 12, 2014 by Sivadam
GREED Posted December 12, 2014 Posted December 12, 2014 I understand some heads might want this but we have been advised as DPA states as long as necessary which for us is only up to the age of 25, let's say they reach the age of 50 we are not going to get a reference request. It would surely be better to put this feature in then not have it at all, as I understand there is a housekeeping feature but it only deletes documents. At this time we have to either dedicated someone's time for a week or so a year to remove this data or put it into our data protection policy that there is insufficient means to remove this data from the MIS. Just hoping that this feature request would get some attention as would be useful! Data retention guidelines technically state that some elements of student data should remain for +25 years AFTER they have left education, if they fall into certain categories, such as looked after children or SEN. Different elements have different data retention legislation. While it is true to some extent that it is up to the HT to decide what they want to keep, keeping it should require them to keep it up to date and accurate, to ensure they comply with DPA. It is such a difficult mire that I am not surprised SIMS finds this difficult to process and do not see this as a fault as such of the software. @matt40k - wooden spoon... stiring the pot... - - - Updated - - - Things don't change much on here! Pity I have retired. I could have had a much more informed input. But why do people do the wrong thing and then blame the software or the suppliers! It seems that somebody else needs to pick up the cudgel I used to wield! Mike! Hello old chap how are you?! 1
GREED Posted December 12, 2014 Posted December 12, 2014 The thread exists because Phil is wrongly attacking people by saying Capita wouldn't have set things up that way... I only read this as advice based on feedback being received, I don't see any blaming going on...
sparkeh Posted December 12, 2014 Posted December 12, 2014 Things don't change much on here! Pity I have retired. I could have had a much more informed input. But why do people do the wrong thing and then blame the software or the suppliers! It seems that somebody else needs to pick up the cudgel I used to wield! Hmm perhaps you haven't read the thread but allow me to summerise: A) Captia representative posts condescending comments about techs installing SIMS incorrectly B) People point out that Capita engineers install SIMS the same way and do other things wrong C) Silence from Captia There that brings you up to speed and as you can see, no cudgel needed or wanted. 4
hardtailstar Posted December 12, 2014 Posted December 12, 2014 Just reecho some comments here, I had a Capita engineer install SIMS from scratch here, he mapped the SIMS drive and installed SIMS, That member of staff has full access to the drive. If Capita are now saying things should be different, could they send an email notice out? I find it strange that they do one thing and we get told another through this forum. 4
PhilNeal Posted December 12, 2014 Author Posted December 12, 2014 Yet another example of Capita's aloof attitude to the DPA I have had a discussion with a senior ICO policy advisor on this subject.
GREED Posted December 12, 2014 Posted December 12, 2014 I have had a discussion with a senior ICO policy advisor on this subject. Care to elaborate Phil? lol
PhilNeal Posted December 12, 2014 Author Posted December 12, 2014 Hi. what would you consider or what considerations do you advise when in terms of resources for a virtualised server? My LEA virtualised (VMWare) our SIMS server and I am not sure it is performing at it's best. Any suggestions would be helpful !! Sorry we don't have that expertise here in our team - it's very specialised knowledge but the correct allocation of resources can make all the difference in the world to performance.
PhilNeal Posted December 12, 2014 Author Posted December 12, 2014 @GREED it's much as I said. The ICO has to be very careful not to be definitive as they act as judge in cases of complaints. We had a senior officer at two of our conferences to explore the issue.
hardtailstar Posted December 12, 2014 Posted December 12, 2014 Sorry we don't have that expertise here in our team - it's very specialised knowledge but the correct allocation of resources can make all the difference in the world to performance. What would be the correct allocation?
GREED Posted December 12, 2014 Posted December 12, 2014 @GREED it's much as I said. The ICO has to be very careful not to be definitive as they act as judge in cases of complaints. We had a senior officer at two of our conferences to explore the issue. I understand that. I would gather, since you are not rushing sweeping changes into SIMS, that the ICO considers your facilities appropriate to meet DPA and data retention needs/guidelines on behalf of your customers?
PhilNeal Posted December 12, 2014 Author Posted December 12, 2014 I certainly didn't intend to cause offence and I'm sure that many many EduGeek members fully understand how to set up SIMS safely. However there are people out there that are installing SIMS that do not understand the main principles. If any Capita engineers have poorly installed software please raise a complaint and it will be investigated thoroughly and action taken. 4
GREED Posted December 12, 2014 Posted December 12, 2014 I certainly didn't intend to cause offence and I'm sure that many many EduGeek members fully understand how to set up SIMS safely. However there are people out there that are installing SIMS that do not understand the main principles. If any Capita engineers have poorly installed software please raise a complaint and it will be investigated thoroughly and action taken. Well said. I'm not sure really how one would take offence at your helpful advice in this thread... 2
hardtailstar Posted December 12, 2014 Posted December 12, 2014 I certainly didn't intend to cause offence and I'm sure that many many EduGeek members fully understand how to set up SIMS safely. However there are people out there that are installing SIMS that do not understand the main principles. If any Capita engineers have poorly installed software please raise a complaint and it will be investigated thoroughly and action taken. Is there an information notice of sheet that has the correct procedures on it? Maybe worth sending to schools??
matt40k Posted December 12, 2014 Posted December 12, 2014 @GREED RE: DPA, we both know the answer as to why there is no feature to delete records, no one wants to be the person who specs it and they don't want to write it. Capita don't believe it makes business sense to do it. That's the honest truth. They'll hide behind the politics, but the true is no-one wants to stick the head over the trenches. It'll come down to the first court case for not following the right to be forgotten. Most likely when a student gets onto SIMS and finds one of the NQTs student records and exposes it school which causes the NQT to quit.
GREED Posted December 12, 2014 Posted December 12, 2014 @GREED RE: DPA, we both know the answer as to why there is no feature to delete records, no one wants to be the person who specs it and they don't want to write it. Capita don't believe it makes business sense to do it. That's the honest truth. They'll hide behind the politics, but the true is no-one wants to stick the head over the trenches. It'll come down to the first court case for not following the right to be forgotten. Most likely when a student gets onto SIMS and finds one of the NQTs student records and exposes it school which causes the NQT to quit. There is a difference between not deleting the records (or worse, the portions of the records) - the responsibility of the schools totally, and not being able to delete the records - the part responsibility of the software vendor as a socially responsible organisation AND the school.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now