Jump to content

Recommended Posts

Posted

As others have already said on here; you are the Network Manager. The school employs you to do a job and I imagine your job description will be along the lines "To keep a working and secure system, etc, etc" and "To keep up with developments in the IT field, etc". You know your stuff, so you put in place what is needed. End of story. You don't tell the teachers how to teach, so no one should be dictating how you run the network and secure your system if less qualified than you to do so.

 

Had similar battles in the past here, some have lead to heated discussions but thankfully SMT have always been on my side. One example of giving local admin rights to Laptops that go home; stomped on that many years ago and with the latest round of ransomware attacks I feel vindicated on that one. Recent battle has been regarding Quotas and at the end of it I was on the verge of locking myself in the server room and shutting everything down, walking out and saying to a particular teacher.... you run the network then! But, that would have been childish. ;)

 

Stick to your guns, point to other examples at other schools. We here do not allow anyone to have access to the C: drive which is common practice within a networked server to client environment.

 

Pete

  • Thanks 2
Posted
Tried that... He's still happy to tell me I need to ask her opinion/consult her on changes :/

 

If this was me, I'd be politely explaining that I won't be doing so for the reasons already mentioned. There's no reasonable reason to do so, if he has management issues with her, he needs to find a way of resolving that without a negative impact on your job.

 

Are you in a union? I might be worth seeking their thoughts on this.

Posted

Thanks @FragglePete - sounds like we've had similar experiences there. The 'telling them to run the network' line sounds exactly like what I've been considering the past month...

 

Not in a Union at the moment @stickman - looking at joining one though, for situations like this; which have been occurring too frequently recently. At least they'd be able to help me word things in the correct way etc.

Any recommendations of unions?

 

Thanks!

Posted
Anything security or DPA related, you should get/put in writing (or email) making your personal feelings known about how seriously you take security and anything less than the security settings you suggest will pose a risk. State that you will be happily overruled, but that you will not take personal responsible for any DPA or security breaches that resulted in any requested modifications to your standard group/user security settings. Copy in the head and governors too. File a copy away for yourself too.
  • Thanks 2
Posted
Thanks @FragglePete - sounds like we've had similar experiences there. The 'telling them to run the network' line sounds exactly like what I've been considering the past month...

 

Not in a Union at the moment @stickman - looking at joining one though, for situations like this; which have been occurring too frequently recently. At least they'd be able to help me word things in the correct way etc.

Any recommendations of unions?

 

Thanks!

 

I've always been in Unison, there are other choices but I've no experience of them. It is worth contacting the other local NMs and see who they're with, there can be regional variation so who is best where I am might not be best for you.

Posted
Thanks @FragglePete - sounds like we've had similar experiences there. The 'telling them to run the network' line sounds exactly like what I've been considering the past month...

 

Not in a Union at the moment @stickman - looking at joining one though, for situations like this; which have been occurring too frequently recently. At least they'd be able to help me word things in the correct way etc.

Any recommendations of unions?

 

Thanks!

 

Unison all day long. From my experience's too, they don't often get on too well with HT's. Will back you all day long in this.

Posted
Had a look, but they all seem to say that they won't help if the case has started before you join them unfortunately. Seeing that I'm not in one, they won't be much use for this problem!
Posted (edited)
Had a look, but they all seem to say that they won't help if the case has started before you join them unfortunately. Seeing that I'm not in one, they won't be much use for this problem!

 

Useful for the future though! Even if only for the legal cover they offer, it only takes one false accusation from a student and everything can turn to #### pretty quickly! I feel better knowing that I've got the backup of legal support and experience if a situation like that was to arise.

Edited by stickman
  • Thanks 1
Posted (edited)
You should not have to be in a union or have to argue with network users while trying to implement industry best practice! You secure local system drives not because you are trying to be a barrier to users working it’s because when you come in to work in the morning you and the users have a useable network likewise when you go to bed at night. This is a prime example of the tail wagging the dog, and the cost to the organization of allowing this kind of access needs to be impressed upon the management and users. Ask them to walk into any enterprise and ask for access to the local system drive they would get a policy handed to them and that would be that. Edited by HPlum78
  • Thanks 1
Posted

I think you just need to clarify a few things and maybe change the way you do thing also. Take out the fact that this person has already gotten under your skin and look at it this way. If you are to make a change which affects end users then they should be notified so that nothing comes as a surprise. This will help staff see you as a person who is willing to work with them rather than dictate the way they work. I find that adding something along the lines of "we have carried out upgrade of XYZ but this should not affect the way you able to access files/ carry out your work etc" helps when you make changes that they won't normally notice as it helps to reinforce that you are not working against them. It also gives them the chance to contact you should they need to.

 

If someone comes to you to make changes because they only know this as the only way(for example "I NEED admin rights"), start by asking what it is they need to do rather than what they want. Clearly state that you are not stopping them from doing any work but it needs to be done in the best way for ensuring that everything is secure and can be backed up where possible. Ideally this can be done in a meeting (with senior members is possible) follow that up with an email stating what is possible to help them achieve what they need.

 

Unfortunately the people above should be consulted about changes that will affect them or how they can use computers as it is much better to give people notice of changes before it happens rather than them logging in and just finding drives or access have been removed. This doesn't necessarily mean that they have say in what you are doing, but more they are informed about the changes you are making (and why) and also how to carry out their tasks if they will be affected by changes you have made.

 

Personally I think you should head down the road of making staff access universal so that you troubleshoot any problems easily. In my last place I used the line that unfortunately you had to cater for the lowest level of IT skill with staff and that was what the security settings were based on. Although you can adjust it for other members of staff there was too much of an overhead to manage individual access. Staff grumbled but accepted it.

 

If you still get forced to make changes you don't agree with by above then as others have said, put it in an email that you do not agree with it so if anything goes wrong you have the paper trail to cover you bum.

  • Thanks 1
Posted
I think you just need to clarify a few things and maybe change the way you do thing also. Take out the fact that this person has already gotten under your skin and look at it this way. If you are to make a change which affects end users then they should be notified so that nothing comes as a surprise. This will help staff see you as a person who is willing to work with them rather than dictate the way they work. I find that adding something along the lines of "we have carried out upgrade of XYZ but this should not affect the way you able to access files/ carry out your work etc" helps when you make changes that they won't normally notice as it helps to reinforce that you are not working against them. It also gives them the chance to contact you should they need to.

 

If someone comes to you to make changes because they only know this as the only way(for example "I NEED admin rights"), start by asking what it is they need to do rather than what they want. Clearly state that you are not stopping them from doing any work but it needs to be done in the best way for ensuring that everything is secure and can be backed up where possible. Ideally this can be done in a meeting (with senior members is possible) follow that up with an email stating what is possible to help them achieve what they need.

 

Unfortunately the people above should be consulted about changes that will affect them or how they can use computers as it is much better to give people notice of changes before it happens rather than them logging in and just finding drives or access have been removed. This doesn't necessarily mean that they have say in what you are doing, but more they are informed about the changes you are making (and why) and also how to carry out their tasks if they will be affected by changes you have made.

 

Personally I think you should head down the road of making staff access universal so that you troubleshoot any problems easily. In my last place I used the line that unfortunately you had to cater for the lowest level of IT skill with staff and that was what the security settings were based on. Although you can adjust it for other members of staff there was too much of an overhead to manage individual access. Staff grumbled but accepted it.

 

If you still get forced to make changes you don't agree with by above then as others have said, put it in an email that you do not agree with it so if anything goes wrong you have the paper trail to cover you bum.

 

No wiser words spoken, do you want to come work with me lol?

Posted
I'd put your foot down and say it's not feasible to do that for one member of staff, and cite the reasons for doing in the first place. Security, data protection, saving the school time & money in repairs etc.

 

Agree, if you allow one member of staff others may see this and start asking same question.

Posted

Seems like I may have won this battle (I hope). After repeatedly emphasising the fact I am not preventing this member of staff from doing her job, nor am I making it more difficult, the headteacher has told me to 'leave it with him' and he'll have a chat with her.

Hopefully that's the last I hear. But the principle is still there that no matter what I do, this individual always has to complain...:mad:

Posted
Just remind the HT that he hired you for your skills and knowledge. If he then undermines you, disregarding your experience and knowledge, why in the world did he hire you in the first place?
  • Thanks 1
Posted (edited)
C: drive is for techies to install stuff that colleagues may need to run but not see or edit. Any data created in programs is directed to network shares to ensure it is backed up regularly and securely. We routinely housekeep PC hard drives and they are wiped/reconfigured as required. There is no good reason for any ordinary user to have any additional access/visibility to C: drive - this isn't their home environment, it is the workplace therefore they should understand that there are differences between the machine on their desk and their PC at home. None of our staff, including Leadership, have access to C: drive - only the IT techies. Securing the hard-drives of PCs also helps us to ensure that PCs function as colleagues expect them to when they have a lesson to teach! Edited by kathabell
Posted (edited)
but schools are the most peculiar of working environments I've found...(!)

 

I think this stems from the way teachers in general conduct their lessons...

 

In a lesson a teacher must have absolute authority - their word being law, otherwise - the more wayward pupils may well disrupt both the lesson and other pupils' learning. Some teaching staff have been known to confuse this with access rights (It's my PC in my room - so I want access!) without realising that they really don't need it.

 

I think it's really down to understanding the difference between the two - it may take a lot of explaining, but if you can get teaching staff (and more importantly - management) to understand why they don't need it, it'll save having this fight over and over.

Edited by korifugi
emphasis
Posted

I agree with you there @korifugi!

I've found in all the schools I've worked in, staff do seem to get very attached to IT hardware we provide. Especially laptops. Relying on it as their only machine in some instances, forgetting that it is loaned to them by the school as an aid to do their job. Not for them to sync their iPod with for when they want to go to the gym... :ohwell:

Posted
staff do seem to get very attached to IT hardware we provide

 

I've found sense of ownership can be a good thing in general, you usually end up with much less damage (certainly in the case of a room), however - sometimes staff can be a little reluctant to come forward with their laptop if they've knackered it, as they're meant to be the ONLY user and are more responsible for it than a room full of kit.

 

Just try getting the damned thing off them to fix it though - I usually throw a pack of malted milks in the other direction and steal it while they're distracted.

  • Thanks 1
Posted
I think it's mostly about hating change, to many of us things are a minor change, because we understand how things work, but to someone who's just memorised a specific way of doing things, it's a big deal.
  • Thanks 1
Posted

Yes - teaching staff in particular are reluctant to change. I think that is, as you say, down to routines they get into.

Come in, unlock laptop (notice how I didn't say turn on), open SIMS and email, do register. It's all a set order, whereas when we say 'okay, now there's this new thing to add to your routine' they're reluctant to accepting it. Usually because they don't directly see or understand the benefits etc.

 

But back on the original topic, that's no reason why they should dictate the change. As mentioned multiple times in this thread; we're the technical experts. Keeping things current is one of the things we're employed to do, and unfortunately that involves implementing new things...!

  • 2 weeks later...
Posted

Resurrecting this... Turns out I was wrong!

This isn't over yet and the saga continues!

 

At one point in my meeting today (and I quote) the HT actually said "I think we should let her have it how she wants"

After some more debating, he's going away to 'think some more'.

 

Am I taking this too far, for what it is? Or should I be standing my ground as much as I am here? More than anything now, it's the principal to me... That she shouldn't be made any different just because she's kicked off and teaches IT.

 

I used the argument about if she was able to access it, then malicious software could etc etc. but apparently "that hasn't happened in 6 years" and "she has enough IT knowledge not to click on something malicious"...

 

I'm getting so frustrated by the whole situation...

Posted
Am I right in thinking all she wants to do is 'see' the C drive? No special permissions except to see it? If so I don't see much of an issue to enable with a specifically targeted policy to her to be honest and if your worried about anything, get it in writing that they understand they have gone against the IT policy for this one member of staff and accept responsibility for all inherent foreseeable and unforeseeable risks.
Posted

Yes, I have a GPO set to hide the drive from 'Computer'. They also don't have full write permissions to everywhere, but as I said - I feel it's more the principal?

I'm not preventing her doing her job, it's a work laptop, it shouldn't be configured as she wants just because she's complaining? IMO...

 

If it does go down that route, then I'll definitely get it in writing from the HT. Because if it does go wrong and there's a security mishap due to that; I don't want to be in a position where it's my fault!!

Posted

I agree, it is crazy, I can't see any logic behind her wanting this, but trojans, viruses, malware and ransomware can still affect a machine even with the C drive hidden, it's mostly a preventative measure for ensuring a user don't mess around with files they shouldn't.

 

Personally, I wouldn't like doing it, but if I was told to, unless I could see a law breaking or network breaking reason not to, I would comply.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...