Jump to content

Recommended Posts

Posted

Hi,

 

I seem to remember reading on here, sometime over the last few years, a link to a news article about a situation in a school which arose from staff computers being left unlocked.

 

Currently trying to show just how important it is to lock computers and this would be helpful - anyone remember it?

Posted

Un-authorised access to SIMS or any other MIS system leading to confidential personal information falling into wrong hands

 

Un-authorised access to confidential files - because as far as the system knows the logged in user is the person acessing the files.

 

Less restrictive filtering

Posted
Hi,

 

I seem to remember reading on here, sometime over the last few years, a link to a news article about a situation in a school which arose from staff computers being left unlocked.

 

Currently trying to show just how important it is to lock computers and this would be helpful - anyone remember it?

 

I haven't got a link but there was an anecdote about a school that was in legal proceedings after a member of staff left a computer unlocked and someone (pupil or staff unknown) forwarded an email that was meant to be confidential. I'll see if I can dig it up.

Posted
I haven't got a link but there was an anecdote about a school that was in legal proceedings after a member of staff left a computer unlocked and someone (pupil or staff unknown) forwarded an email that was meant to be confidential. I'll see if I can dig it up.

 

That sounds like the one! I can't seem to find anything on Google but if you can find it I would be ever so grateful!

Posted

IIRC it was either me or Ephylon relating something from the eSafety Law in Education group, talking about how having AD sign in to your MIS was not a good idea.

 

The scenario is this.

 

  • Teacher A is delivering a lesson in the classroom, has the laptop connected to the projector and has screen frozen ash they are taking the class register using a tool in the MIS. Access to the MIS is provided by clicking on an application to start and it immediately signs you in with no further requirement to enter a username or password.
  • Teacher A runs lesson, with a variety of materials being shown to the class.
  • Teacher A has to move round the class to work with learners, but stuff stays on screen so laptop left unlocked.
  • Teacher A has to leave room to deal with something and laptop is left unlocked 'so learners can continue'.
  • Teacher is only just outside but Student Z goes to laptop, opens MIS (or brings it to the front), searches for details of child in that class or another class, and information is displayed on screen ... this could range from attendance through to any statements or medical needs the child has.

 

Out of the schools who have had to sign undertakings with the ICO at least one has been related to improper access to MIS data.

In one case the MIS was tied to the AD, and so was the VLE and other things ... so when a member of staff shared their password the children involved had access to everything ... and they *did* access a lot of things ... apparently.

 

Thankfully nothing happened as a result (no bullying, injury, etc) but should the information be used to cause any form of harm the projection is that a serious case could and would be brought.

For DPA breaches we are in the hands of the ICO and as yet no fines have been imposed on schools ... only colleges / universities / LAs.

 

Is that what you were looking for?

Posted
This is why a majority of my workstations auto-lock after 10 minutes of in-activity. It annoys the hell out of staff, but if we don't have it the amount of workstations that were left unlocked around the academy was astounding.
Posted

@GrumbleDook, could well have been either of us. I know that's the precise argument as to why SSO for the MIS is not enabled on our site...

 

On a side note, is the data on schools that have had to sign undertakings with the ICO on public record?

Posted
@GrumbleDook, could well have been either of us. I know that's the precise argument as to why SSO for the MIS is not enabled on our site...

 

On a side note, is the data on schools that have had to sign undertakings with the ICO on public record?

 

I did a FoI request in my previous job but don't have the data to hand nor can I reuse it (terms of my old contract).

 

Someone could always ask again.

Posted
I have, today, been involved at a third party school in sorting out the fallout from an avoidable incident.

 

It involved an unattended computer with an email on the screen and someone photographing it with a mobile phone. The outcome is likely to be a constructive dismissal case against the school and a disciplinary for the person who left their computer unattended.

 

It takes seconds for someone to take a photo. It takes minutes for a screen to lock automatically... possibly never

 

Lock your screen or logoff... it is not worth the risk!

 

Here you go

Posted
Thank you Elsie - what is constructive dismissal against a school? I understand it against a person, but how does that work against an establishment? Just out of curiosity more than anything.
Posted (edited)
Thank you Elsie - what is constructive dismissal against a school? I understand it against a person, but how does that work against an establishment? Just out of curiosity more than anything.

 

The constructive dismissal case was due to the content of the email displayed on the screen which the subject took exception to.

Edited by elsiegee40
Posted

 

 

Reading through that story with a pinch of salt as always (actual truth isn't probably going to be let out)

 

 

A user walking off leaving their PC unlocked and someone else coming along and sending emails under the users logged in account or some one using a password left on a post it, I'd hardly think this would be correctly labeled as a hacking incident . If some one hacked user accounts and passwords etc from a system that might be different story

 

Same a if a password is on a post it note on the desk it wouldn't take much of a hacker to get into the system would it?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...