Jump to content

Moving Staff shares/home drives to Google Drive - Thoughts?


Recommended Posts

Posted

Hi all

 

I would like to hear some thoughts and feedback on the idea of moving all staff shares and home drives to Google Drive.

 

We have already implemented this for students and so far it has been a success. We tell the students that it's their responsibility for managing their work/data on Google Drive, and that is fine.

 

However, my immediate feelings on doing the same for staff concerns me deeply. Especially as I am designated data controller/holder for the corporation; by using Google Drive for all staff data, I am basically giving up this role, as this role becomes Google's.... and that to me seems dangerous. Concerns such as the loss of direct access to our data, not knowing where our data is, the simple fact that we will be no longer be in direct control of it and we lose control of a backup and recovery process.

 

Would love to hear your views. Has anyone done this for staff?

 

Thanks

Posted

I don't think it would be a good idea with staff as the data they handle is much more sensitive than what pupils use and having it on your own servers gives you full control over the data and it's backups. Also if for any reason you lost internet access the staff would at least have easy access to their data.

 

There's always pro's and con's do this type of change but personally I think staff data should be stored locally.

Posted

Staff data… hmm… you could infringe European rules (grey area) regarding this as you can't determine the location of your sensitive data.

Ok, staff may cite that they're not storing banking details or suchlike., but if you're a state run school, they are - in a way - storing test results and student coursework, that could be classed as government data…

 

On top of that, what happens to classes when you have a total connection drop… like when local workmen doing roadworks sever the connection with their jcb?

Local storage for staff prevails…

Posted

Concerns such as the loss of direct access to our data, not knowing where our data is, the simple fact that we will be no longer be in direct control of it and we lose control of a backup and recovery process.

 

Could you expand on this? We have done this with a lot of (not all) staff data and I haven't experienced any of these problems. I know where the data is (clearly I've never "seen" the disks that it is held on), I can access it, I can recover it, I can change permissions.

Posted
Cloudberry backup has option for maintains on site and cloud mirrors.

 

Can Cloudberry mirror the data to the Google Drive accounts of the users? - I'd be happier if there was a mirror of the local data which was then sync'ed to the staff Google Drive accounts

 

Staff data… hmm… you could infringe European rules (grey area) regarding this as you can't determine the location of your sensitive data.

Ok, staff may cite that they're not storing banking details or suchlike., but if you're a state run school, they are - in a way - storing test results and student coursework, that could be classed as government data…

 

On top of that, what happens to classes when you have a total connection drop… like when local workmen doing roadworks sever the connection with their jcb?

Local storage for staff prevails…

 

This is exactly what concerns me.

 

Could you expand on this? We have done this with a lot of (not all) staff data and I haven't experienced any of these problems. I know where the data is (clearly I've never "seen" the disks that it is held on), I can access it, I can recover it, I can change permissions.

 

What concerns me CyberNerd is that you are placing a lot of trust with the cloud service provider.

 

A worst case scenario: What happens if one day you can't access the data anymore? You end up on the phone to the cloud provider and meanwhile everyone is screaming 'what's happening' and why can't they access their work anymore. The backups? The backups you are also entrusting with them. You are not in control of any of these processes anymore. You are placing a huge amount of trust in something that only appears to you as a user interface.

 

Not to say that you are going about anything wrong, it's purely out of interest; but have you or anyone else in your department made it clear to the head that the IT department is no longer in direct control of the data? I feel that if a school or any organisation wants to go down this route, this would be the first thing that I would make very clear.

Posted

What concerns me CyberNerd is that you are placing a lot of trust with the cloud service provider.

 

A worst case scenario: What happens if one day you can't access the data anymore? You end up on the phone to the cloud provider and meanwhile everyone is screaming 'what's happening' and why can't they access their work anymore. The backups? The backups you are also entrusting with them. You are not in control of any of these processes anymore. You are placing a huge amount of trust in something that only appears to you as a user interface.

 

Not to say that you are going about anything wrong, it's purely out of interest; but have you or anyone else in your department made it clear to the head that the IT department is no longer in direct control of the data? I feel that if a school or any organisation wants to go down this route, this would be the first thing that I would make very clear.

 

It is about as likely as Micsosoft issuing a file system update that corrupts all my data, then issuing another that corrupts all my backups. It Just isn't going to happen: Google would bankrupt themselves. You have put trust in your storage provider, even onsite, that they won't loose your data. Unless you're going to only use open source, and read every single line of code before you do something then we are in exactly the same situation.

Posted

Well done cybernerd… you've just quoted the guys at codespaces… without (I guess) reading about their demise. They put everything in the cloud, without updating their disaster recovery plan (if they even had one)

 

Also, check out the current thread on here about intouch. Philneal has got serious problems with a VMware stack going corrupt. I don't wish to rubberneck but cybernerd… you stating how likely is it… is what will get you into hot water.

 

Plan to recover from failure… then you won't have failed to plan

I still sleep well at night… having planned for those ‘SHTF’ scenarios… because it's never if, but when…

Posted
Well done cybernerd… you've just quoted the guys at codespaces… without (I guess) reading about their demise. They put everything in the cloud, without updating their disaster recovery plan (if they even had one)

 

Also, check out the current thread on here about intouch. Philneal has got serious problems with a VMware stack going corrupt. I don't wish to rubberneck but cybernerd… you stating how likely is it… is what will get you into hot water.

 

Plan to recover from failure… then you won't have failed to plan

I still sleep well at night… having planned for those ‘SHTF’ scenarios… because it's never if, but when…

 

It's all down to probability. Probability of me or one of the techs screwing up vs Google screwing up. Probability of My DR plan failing vs Google's.

Does your DR plan get audited to ISO27001 and SOC2 every year ? Google does.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...