Jump to content

Recommended Posts

Posted

Hi All,

 

I'm new in post at a Secondary School, taken charge of a Network that is in a real mess but its going to be fun to sort out. :p This is a new sector for me working in Education, so be gentle, but I have an issue that is playing on my mind.....

 

I've been instructed that we must have Electronic Registration that is to be done twice a day in place by Sept '08. We're using SIMS.net here on the Admin network, (I should really say Domain because it's not two physical networks but just two seperate Domain's one for Admin and one for Curriculum).

 

Teachers need to do Registration around the school electronically, but of course this is all on the Admin network. Teachers laptops and classroom PC's are on the Curriculum network. One infrastructure, but the device is either configured for Admin or Curriculum if that makes sense.

 

So, we're trying to get a Capita rep in to talk to us about solutions, but I've got a few ideas bouncing around my head to solve this issue . I'd appreciate any input or suggestions from you guys and gals that could point me in the right direction.

 

Many thanks

 

Pete

Posted

We moved away from a two domain network to one DOMAIN network to allow teachers to access Sims.net.... - if you're not planning lesson by lesson registration then Sims.net is free solution as you don't need to buy Lesson Monitor!! You should already have attendance 7 installed which allows staff to take registration by AM / PM on their timeline on the homepage.

 

Alternatively you could buy other software e.g. Pars etc... but why pay, and I'd prefer if we keep everything centrally under one MIS.

 

Any questions, let me know ... or PM me.

  • Thanks 1
Posted

Also consider hardware-based solutions (I must admit that I like our system from Nedap Education) that do not rely on computers as much.

 

Our system has 'registrators' located by each door which store up presence marks and then send them off to a SQL server every so often. The advantage of this is that if there is network discruption the data isn't lost (it jsut waits) and the rugged, dumb, nature of the boxes means that they tend not to break down.

 

I'm happy to talk about the PreAbXS solution.

  • Thanks 1
Posted

that set up is the same at our school - two domains

what i have done is created a user on the curric domain and in the logon script map a drive to the admin domain and the shared sims folder, on the batch file you can insert the admin/username and password (the admin username must be a user on the admin domain) so they don't need to type it in. then sims will pick up the data on the admin side and once they have finished takin the register get the teachers to log out(for security reasons). if it makes sense:P

  • Thanks 1
Posted
@FragglePete: depending on how many clients wish to use Sims.net why not setup TS server so it can be accessed remotely via rdp from the curriculum workstations via a group shortcut which only the staff have access to. This way it keeps the costs down and you don't have to merge the 2 domains.
Posted

Thanks for your replies. Glad I stumbled across this little forum! :D

 

Some of the ideas suggested have mirrored what I've considered already. I've had experience in setting up a Windows TS Solution many moons ago and am favouring this idea; getting a new server on Admin network with lots of RAM and getting them to use that to log into the admin network from the curriculum network.

 

The single domain solution is also something I'm liking; simple and cheap to do but there is still a faction of people who prefer to keep the two seperate 'networks', and I've heard about some Schools wanting to get back to the two networks from one.

 

I've been seeing things about 'Web Parts' for SIMS; don't know if I'm barking up the wrong tree, but a web based solution that connects into SIMS where the teachers can access securely through a web browser would be ideal. Am I correct or incorrect in my assumption?

 

I'll look at PARS, something else to have a read up on.

 

Cheers all ;-)

 

Pete

Posted

FragglePete: " Teachers need to do Registration around the school electronically, but of course this is all on the Admin network. Teachers laptops and classroom PC's are on the Curriculum network. One infrastructure, but the device is either configured for Admin or Curriculum if that makes sense."

 

Yes, exactly! You certainly need to make a choice to give up data security or choose a system that can work with Admin and networks in isolated form as you are now. There is at least one system that in this forum has been discussed (Bromcom) which appears to deal with your situation - http://www.edugeek.net/forums/showthread.php?t=12801&page=3 contact: John Condon

 

See also the full thread under 'Flat Networks' to read what was discussed with huge risks for going to 'flat networks'. My recommendation is - don't go anywhere near it!!!

Posted (edited)
FragglePete: " Teachers need to do Registration around the school electronically, but of course this is all on the Admin network. Teachers laptops and classroom PC's are on the Curriculum network. One infrastructure, but the device is either configured for Admin or Curriculum if that makes sense."

 

Yes, exactly! You certainly need to make a choice to give up data security or choose a system that can work with Admin and networks in isolated form as you are now. There is at least one system that in this forum has been discussed (Bromcom) which appears to deal with your situation - http://www.edugeek.net/forums/showthread.php?t=12801&page=3 contact: John Condon

 

See also the full thread under 'Flat Networks' to read what was discussed with huge risks for going to 'flat networks'. My recommendation is - don't go anywhere near it!!!

 

Cue - flat network versus divided network debate again!

We have a flat network - saves all the hassle, never had any issues and certainly don't feel we have "given up data security"

 

In answer to the OP question - get everything onto one flat network and use SIMS attendance - it's free as it's already there and it seems to work really well (we implemented it 2 years ago.)

Edited by jcollings
Posted
You certainly need to make a choice to give up data security.......

.......with huge risks for going to 'flat networks'. My recommendation is - don't go anywhere near it!!!

 

What has having one domain or network got to do with giving up data security?

 

No permissions = no access, simple, be it Microsoft, Unix or Novell.

 

If network permissions are set up correctly, there is absolutely NO security risk involved in having students and staff on one domain.

 

If a network manager is not capable of setting up a secure network, then they are in the wrong job!!!!!

 

The greatest risk comes from teachers letting students use their computer whilst the teacher is still logged in, it doesn't matter how many domains or networks you have then.

 

Graham

Posted

InTheDark: "What has having one domain or network got to do with giving up data security?

 

No permissions = no access, simple, be it Microsoft, Unix or Novell.

 

If network permissions are set up correctly, there is absolutely NO security risk involved in having students and staff on one domain.

 

If a network manager is not capable of setting up a secure network, then they are in the wrong job!!!!!

 

The greatest risk comes from teachers letting students use their computer whilst the teacher is still logged in, it doesn't matter how many domains or networks you have then."

 

If you believe in a hacker-free world then yes!

 

Otherwise you need to check out UK's the most comprehensive guide specifically for educational establishments on this issue - "UCISA - Information Security Toolkit - Edition 3.0 by JISC"

 

http://www.ucisa.ac.uk/ist/agree/

 

Take a look at Section L: "Network management " and note repeated key word 'segragated' - meaning ZERO access between the groups eg students, staff and third parties etc...

 

There are also plenty references to BS7799. I would have thought to comply with the Data Protection Act a school needs to meet BS7799 as the Data Security standard. I hardly think a system vulnerable to 'man in the middle'' attack for children sensitive information or if central data security relies on every teacher keeping his/her password safe will meet BS7799 or compliance to Data Protection Act.

 

I hope it helps.

Posted

If you believe in a hacker-free world then yes!

 

Take a look at Section L: "Network management " and note repeated key word 'segragated' - meaning ZERO access between the groups eg students, staff and third parties etc...

 

 

No it didn't help.....

 

If someone is going to hack a system, there is NOTHING anyone can do about it (ask NASA, the FBI, Barclays Bank, eBay, Microsoft, to name a few), but given the resources a school has to work with, financially and man power, a SINGLE domain/network can be adequately secure.

 

Where the network(s) are “segregated”, do both of them have access to the internet, if so then they are no more secure than a single network, so why bother to have two?

 

What is the point in having two network infrastructures, two domains, when teachers allow students to use their network account “just to finish off some course work”.

 

Over the last 15 years or so, I’ve only ever worked for one company that could justify having a separate network infrastructure from their main corporate network. That was for the fraud department of a multinational bank, they had their own network, own servers, own infrastructure, and most importantly no internet access.

Posted (edited)

InTheDark: "I’ve only ever worked for one company that could justify having a separate network infrastructure from their main corporate network. That was for the fraud department of a multinational bank, they had their own network, own servers, own infrastructure, and most importantly no internet access."

 

Pls add to your list of 1, everyone one of thousands of schools in Australia, France (and probably whole of Northern Europe).

 

A visiting Australian network manager in a school from Melbourne kindly pointed out to me a document by Victoria Education Department which clearly states that schools must keep networks isolated. Data security/data protection act and civil liberties appear to be a high profile issue across Australia.

 

Since then I discovered that starting with France all civil liberty conscience countries have very strict rule in schools to keep admin and curriculum network isolated. In France you get fined 30,000 Euros and an imprisonment for infinging data security rules.

 

If yo uwant an access admin from curriclum, you just need to use the right product that allows 'tunneling' - see John COndon's entries for details under the thread 'flat networks'.

Edited by Tiger
colour
Posted

I hate to fan the flames of seperate vs. flat domains. But I think we really need to differentiate between seperate networks (e.g. seperate physical wires or well implemented vlans) and what I think most of you are talking about with is just seperate domains.

 

At the IP level I suspect they are usually the same network, which dosn't really protect you from hackers....

 

Cheers

Jona

Posted

When I came to my school almost 5 years ago we had two seperate domains, one curriculum & one admin. A trust relationship had been established to allow SIMS access for teaching staff running on the curriculum domain to access SIMS (for Lesson monitor registration). Some admin staff and SMT had access to both domains and all got regularly got confused about which they were accessing and for what reason, leading to all sorts of issues with data & document version control.

 

When the Admin (SIMS) server died a horrible death 3 years ago (slowly cooked in a steel box) I took the opportunity to move everything onto a single domain; it was easy to do and has greatly simplified everyone's access. Correct use of permissions and 'access based enumeration' in Server 2003 provides as much security as we had before; as someone pointed out earlier the biggest risk to our data comes from the staff member who is casual about their password and/or cannot be bothered to lock their computer when leaving it unattended. This risk remains regardless of how many domains you have.

Posted

I can seen I've re-ignited a debate here.

 

I can see the benefits of a single domain, but also like having the two which has just been highlighted in a recent 'security' incident here. A number of files and folders were renamed by someone with the Staff area of the Curriculum network. Obviously a pupil having access to a staff login. Not a major issue, but if it was access to the SIMS area.......

 

I've run a script to expire all staff passwords on the curriculum network to ensure that all staff reset their passwords and will send out a gentle reminder that pupils are not to use their logins and must protect their passwords.

 

As always, the weakest element here is the human element.

 

Pete

Posted
broc: "Correct use of permissions and 'access based enumeration' in Server 2003 provides as much security as we had before; as someone pointed out earlier the biggest risk to our data comes from the staff member who is casual about their password and/or cannot be bothered to lock their computer when leaving it unattended. This risk remains regardless of how many domains you have."

 

Yes, 'Password' is a user level security risk and this is totally irrelevant to 'network based' security. It is no better than a front door key for you house with no other security measure.

 

As a network manager we need to focus on network vulnerability to hacking. In Northern Europe and Australia the rules are simple - keep two segregated networks. Use of domains still means a 'flat network' is deployed and through IP level hackers can walk through domains!

 

FragglePete: " I can see the benefits of a single domain, but also like having the two which has just been highlighted in a recent 'security' incident here. A number of files and folders were renamed by someone with the Staff area of the Curriculum network. Obviously a pupil having access to a staff login. Not a major issue, but if it was access to the SIMS area....... "

 

Well put! This is pricely why you should keep two isolated networks and only a "tunnel access" between Curriculum Network and Admin Network. All data security/civil liberty conscientous Northern Europians and Australians do.

 

With 'tunnel access' restriction in place, even with password no one on Curriculum Network can access other files or wide range of sensitive information on Admin Network. Only authorised "client software" can access strictly limited information eg student attendance registration, behaviour and marks etc.. as per the subject of this thread which you started.

 

Finally ...

As always, the weakest element here is the human element.

 

You do not need to leave it to the weakest element! A Network Manager's job is remove just such risks!

Posted
Thanks for your replies. Glad I stumbled across this little forum! :D

 

I've been seeing things about 'Web Parts' for SIMS; don't know if I'm barking up the wrong tree, but a web based solution that connects into SIMS where the teachers can access securely through a web browser would be ideal. Am I correct or incorrect in my assumption?

 

Pete

 

Pete,

 

Firstly; Please check my comments by speaking to Capita direct for updated information. I understand Sims have webparts out allready allowing various functions, in fact you can visit their site for a live demo site through sharepoint with the various webparts. This demo site has recently been updated so a little better than their first attempt.

 

We have our own MOSS 2007 (sharepoint) VLE hosted internally. We are looking at getting the webparts very soon. This access can all be acheived via a browser. I think in feb some time they will be offering profiles (sims pupil reports) and attainment info through this. I also understand the realtime reporting for parents can be gained from this route also... see http://news.bbc.co.uk/1/hi/education/7176741.stm

 

As for the single and split networks, this is clearly a topic that will never have agreement.

 

I can understand the most secure method is to keep networks apart, perhaps one step further may be to keep the servers in a steel container, locked, placed in a 20m deep hole and concrete the hole in, then put some nasty dogs on guard??? Some types of Security can be seem extreme for some but normal day tasks for others!

 

I think given todays security available and the need to keep business efficiant (we are here for the pupils, paid for by tax payers) merged networks are clearly being a more accepted choice! But we should not forget we must protect pupils too, that said we can only protect to a certain level- how many schools have a least one health and safty issue somewere!! I put a bet we all have quite a few - known or unknown!!

 

My personal choice is now to merge our networks, we can leave the leaking security risks to MOD laptops left in pubs and data disks lost in the post!!

 

We need to merge the networks as we have so many tasks completed on both networks; a "tunnelling " approach would be such a mess to manage!! I think a well designed security structure and sims access rights will do the trick fine, I think like someone pointed out the networks are joined at the internet allready anyhow - thats just a large network!!

Posted
benIT: "We need to merge the networks as we have so many tasks completed on both networks; a "tunnelling " approach would be such a mess to manage!! I think a well designed security structure and sims access rights will do the trick fine, I think like someone pointed out the networks are joined at the internet allready anyhow - thats just a large network!!"

 

All of sudden it appears as if decision on 'flat networks' vs "isolated networks" has become a personal choice or throw of a dice. Far from it.

 

As a network manager and school SMT one needs make a decision on the basis of:

1. Strict requirements to comply to Data Protection Act by the schools

2. Implied recommendation by DCSF/Becta to comply with BS7799 as data security standard

3. Take a good look at existing guide for education establishment http://www.ucisa.ac.uk/ist/agree/

4. Use your own professional judgment in protecting 'vulnerable part of community' (ie children) for any consequence of infringment of data security against them.

 

And good luck.

Posted
All of sudden it appears as if decision on 'flat networks' vs "isolated networks" has become a personal choice or throw of a dice. Far from it.

 

As a network manager and school SMT one needs make a decision on the basis of:

1. Strict requirements to comply to Data Protection Act by the schools

2. Implied recommendation by DCSF/Becta to comply with BS7799 as data security standard

3. Take a good look at existing guide for education establishment http://www.ucisa.ac.uk/ist/agree/

4. Use your own professional judgment in protecting 'vulnerable part of community' (ie children) for any consequence of infringment of data security against them.

 

And good luck.

 

Well, as our network is a 'standard build' following the specifications of our LEA, I would say that they have investigated the data protection act and its needs. They decided that all somerset schools should go single network, single domain. I would trust an LEA to make decisions, as they have a legal team who look into these things.

 

On the electronic registers front, one thing you will need to look at is fire alarms. How will you enable registers to be taken in the case of an alarm going off?

Posted

@Tiger: You have a fair point about the segregation of networks and you should probably make it impossible to see the sensitive data from computers that are used by pupils. However, if you put a tunnel in, you immediately bypass the efforts made by segregating. You would also not be able to follow all the new fangled plans to make information freely available to parents/guardians via the web.

 

There will always be a trade off between the extent to which you secure your data and the accessibility of that data. I think what people have been saying is that SMT and the IT management team must come to a decision that best suits the needs of the school whilst not exposing the schools data to any unnecessary security risks.

Posted (edited)

As Tiger dropped my name into the conversation a couple of times I thought I'd best at least chip in a little bit.

There are quite a few different ways to securely provide information access across Admin/Curriculum networks that do not involve merging the two domains.

Our solution is but one method of implementation and wouldn't, as Ric_ mentioned, prevent you from utilising any other web portal for parental data sharing (this does of course wholly depend on 'what' you are using for said portal).

A properly configured/developed/designed solution should fulfill your school needs without causing any undue increase in Admin workload. Ideally the whole thing should be, once implemented, effectively invisible to all but the highest level admin user. Our own cross network solution is, to the teaching staff, completely invisible and restricts access such that only those processes that are relevant to attendance registration are capable of utilising the 'tunnel'.

 

Nothing is completely secure however and, as others have already said, any system is only as strong as its weakest link and this debate will go on and on and on..

Edited by Bromcom_John
Posted
All of sudden it appears as if decision on 'flat networks' vs "isolated networks" has become a personal choice or throw of a dice. Far from it.

 

As a network manager and school SMT one needs make a decision on the basis of:

1. Strict requirements to comply to Data Protection Act by the schools

2. Implied recommendation by DCSF/Becta to comply with BS7799 as data security standard

3. Take a good look at existing guide for education establishment http://www.ucisa.ac.uk/ist/agree/

4. Use your own professional judgment in protecting 'vulnerable part of community' (ie children) for any consequence of infringment of data security against them.

 

And good luck.

 

Tiger,

 

I certainly dont think split or single networks/domains should be a role of the dice, But at the end of the day the choice (as per my job description) lays on my shoulders.

 

As you rightly say, there are many sources of information that must be considered before making choices, but ultimatly we may all look at that information in a different way - regardless of SMT or the like.

 

We recently has a goverment audit team in school for a week solid, looking at the finest detail of school operations - finance, Disaster recovery plan etc, they were very thorough (we heard same stories from other schools in the area). My question is why would such a audit not reveal the single network being a problem? furthermore if dual networks are the goverments advice - its would clearly be backed by all LEA's, the truth is its not, i have worked for 3 LEAs - none of them had any advice to advise against, just that its secure!!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...