Jump to content

Anyway to monitor internet use at home?


Recommended Posts

Posted (edited)

The term, 'duty of care' is absolutely the right way to be going about our role. It has even been suggested, and I have some personal experience of this, that Ofsted are picking up on things related to eSafety, primarily with the children/students, but in my mind, why should it stop there. I want to protect the staff too. I don't want them to have a cloud over their head because something made its way onto the school laptop and showed inappropriate material in the classroom - all because the logging wasn't in place that would have triggered an alert...

 

Is anyone else feeling that our jobs are getting a bit harder, those nasty people out there seem too clever to be wasting their time with depraved pursuits.

 

I'm so thankful for the Edugeek forums where we can help each other to stay ahead of the game.

 

Here's to you guys :thumb::thumb:

Edited by mrwoberts
Posted

Bit of contradiction here - when talking about BYOD I thought we where talking about true BYOD where you have no control over device. You're talking about managed devices where you can - say - wipe them? Or push out software? Or are you just talking about wifi managed?

 

It's getting a bit off topic now, but yes on most BYOD devices we can push out software. Clearly I couldn't force a home content filter on these.

Posted
Re logs and monitoring - if a tree falls...

 

There are logs already. You have the internet history, you have av which will normally have http scanning, again more logs, you have backup logs of any files they save as they get saved to the network.

 

Internet history is no use for anything - any user can delete their own history simply by going in and deleting the relevant file. Our AV doesn't log things unless there are issues with malware.

 

What we wouldn't have is logs of staff accessing inappropriate material on school devices. If such an accusation was made, we would have one word against another without any evidence. Logs provide that evidence of innocence or guilt.

 

There is absolutely a difference between monitoring and logging. Monitoring is proactive. It is looking at things. Logging is passive. It creates potential evidence in the future, should ever a need for it appear.

 

You clearly have policy sorted, by the sounds of a random question they have asked in the original post, they dont - or its not as advanced as yours

 

They definitely need policy to cover this, so if it isn't, it needs to be created and ratified by governors.

Posted

You'll be surprised how many people are caught out by caches. Anyway, i dont see this as a tech problem more of a policy - tech wise this is solve in oh so many ways. You've solved it for the pupils. Like @mrwoberts said, it makes sense to extend it, its just its a policy thing and you cant assume folks are as advanced policy wise as @localzuk.

 

Tech is easy, procedures are hard

Posted

There's not really a story behind it. The deputy head asked me to write out the e-safety policy, I pretty much copied what was on the council's website but tailored it for us.

 

In the e-safety policy it states we reserve the right to log all websites accessed at home for your safety and the safety of our students.

 

Because of this the deputy has asked that I pick 3 members of staff at random per year and go through their history to check they're not going on anything bad I guess. He has then asked me to create a log to show we have checked X,Y & Z.

 

Seems all a little overkill to me and I did tell him my concerns but because it's in the e-safety policy IT MUST be done apparently :doh:

Posted

Because of this the deputy has asked that I pick 3 members of staff at random per year and go through their history to check they're not going on anything bad I guess. He has then asked me to create a log to show we have checked X,Y & Z.

 

1) Disable their laptops

2) When they bring them to you, copy their internet history

3) "fix" the laptops

4) report back to deputy job completed.

Posted
Ah k, just use av web logs, job done. If you find something, then look at securus or something like you would for kids - just get them to want to do it rather then being overly enthusiastic
Posted

That's a bit better... thanks @abillybob

 

Ok, in my view, and I know this might be over-kill, but checking at random times per year isn't pro-active enough for me. I prefer to stop inappropriate browsing habits the moment they come up on my rader - in actual fact, I've had a case in the past whereby something slipped passed the AV, mentioning no names, aaaaaaachooooo sophos oooooooo. The only way I spotted it was when they brought the laptop back into the school and the filtering kept blocking requests for certain sites!! That was the trigger I needed to take action. It wasn't necessarily the teachers fault, but I did need to look at their laptop asap.

 

For me, this is still a work in progress, finding the best tools that prevent such activity, and finding the tools/scripts to flag up any unsual activity.

Posted

@abillybob

 

Just remember what @localzuk mentioned before, that true browsing history can very very easily be hidden. In fact, most browsers now have a 'incognito' type of feature where nothing is stored once the window is closed!

 

You're going to need something a bit more substantial. Thanks for raising this thread, it's made me think a bit more about an area I'd perhaps just assumed was sorted.

Posted

We have SECURUS installed on all devices, including staff laptops which can be taken home. Staff sign an agreement stipulating that the laptop is for work use only and the AUP states that laptops are have SECURUS installed and that it logs their activity. We also have Sophos installed which has web protection built in, to reinforce the idea that these are school laptops, and should be used for work and not personal use.

 

I would highly recommend, if you're going down the monitoring/logging route, that you install some kind of web filter on staff devices to prevent accidental or unknowing access to dodgy sites (or potential misuse by family members/flat mates etc). You don't want staff to feel that they are being entrapped, but rather protected from false allegations of misuse.

 

Would be interested to know whether our setup would be considered overkill/illegal? Getting knowledge in this area is particularly difficult as there doesn't seem to be a cut and dried policy we can all follow.

Posted

How much do you spend on SECURUS? I think that's the reason why there is no cut and dry policy. Some schools I think its required, others I think it would be a waste of money. I think for @abillybob he just needs to tick the web filtering option on the AV and check the logs rather then throwing tech at it.

 

RE: work only - If overlooking a member of staff checking their bank accounts or printing a few A4 pages gets them engaged, I think its worth it. Its just, at the other end of the spectrum, you've got folks like Netflix - a tech company - saying their biggest security hole isn't someone hacking them, its from their own staff going on some hacked\crooked website. So no, don't think its overkill.

Posted

SECURUS was an expensive outlay, but the ongoing cost per year isn't too bad now. I'm looking at other solutions (E-Safe) which would be a price hike. I think you're right though, if there's a no cost option that satisfies the needs of the school then that's the route to go down.

 

REL Work only. Absolutely, light personal use is fine, no issues with that. I would hope that the AV/web protection does it's job properly and SECURUS is never needed.

Posted

My 2 pence - I've used securus when I worked at a high school and it flagged up questionable content. You got a lot of false positives, especially when people started searching for Clitheroe (a local town)!! but overall was a good product.

 

Personally I would change the policy to say everything is monitored in school and that at home the laptops / device should be used mostly for work related tasks. I'm just gonna check the AUP I draughted up and let you know what it says...

Posted (edited)

This is my staff policy introduction:

 

Introduction

The school has provided computers for use by staff as an important tool for teaching, learning and administration of the school. Use of school computers, by members of staff is governed at all times by the following policy. Please ensure you understand your responsibilities under this policy and direct any questions or concerns to the IT Technician or IT Coordinator in the first instance.

 

All members of staff have a responsibility to use the school’s computer system in a professional, lawful and ethical manner. Deliberate abuse of the school’s computer system may result in disciplinary action (including possible termination of contract) and civil and/or criminal liability.

 

Please note that use of the school network is intended to be as permissive and flexible as possible under current UK legislation and DfE guidelines. This policy is not intended to arbitrarily limit the ways in which members of staff can use the system, but to ensure compliance with the legal responsibilities of the school and staff, to safeguard the reputation of the school and to ensure the safety of all users. Please respect these guidelines, many of which are in place for staff protection.

 

Lastly, the school recognises that the distinction between computer use at work and at home is increasingly blurred, with many of us now using our own computers for work. While the school neither wishes nor intends to dictate how home computers are used, staff should consider that the spirit of this policy applies whenever undertaking an activity that stems from employment with the school.

 

Under Conduct:

• Staff must ensure all Internet activity is appropriate to staff professional activity, including research for professional purposes. Where the system is made available for personal use, the same principles apply.

 

Finally:

Privacy

• Use of the school computer system, including email accounts and storage areas provided for staff use, may be subject to monitoring by the school to ensure compliance with this ICT Policy and applicable laws. In particular, the school does keep a complete record of all websites visited on the Internet by both pupils and staff; however, usernames and passwords used are NOT monitored or recorded.

• Staff should avoid storing sensitive personal information on the school computer system that is unrelated to school activities (such as personal passwords, photographs, or financial information).

• The school may also use measures to audit use of computer systems for performance and diagnostic purposes.

Edited by Joanne
  • 3 weeks later...
Posted

We use a Palo Alto firewall here, so we install our firewall client (GlobalProtect) on all laptops - they are then forced to go through our filter and everything is logged.

 

Staff laptops are for work, not for home use so they are restricted to our filters at all times - but it doesn't just stop them from websites it protects them against dodgy sites!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...