Jump to content

Recommended Posts

Posted

Our Current SIMS server is a VM with C: and S: drives.

 

The S:\ drive is shared with share permissions "Everyone FULL CONTROL"

 

Staff who require SIMS are added to a global security group called SIMS and this group has FULL Control on the S:\ drive.

 

 

I don't believe the system should be this open, but the Server was created by our Local SIMS support team a few years ago.

 

I've emailed them for advice on how to secure it a bit tighter and after three weeks of chasing via email I've still not got any information on this.

 

 

Can anyone advise if the S:\ drive for SIMS can be secured a bit tighter...

 

 

Thanks.

Posted

These days the only people who really need access to the S drive are those that use legacy apps, like Exams Organiser, Options, or Nova, and those staff that produce the census and CTF files. Inside the sims folder you can restrict permissions on the folders as follows:

Exams - Exams Officer and anyone who uses Exams Organiser

Options - Anyone using options

STAR - Anyone generating CTF files and whoever does the census returns

SNOVA - Timetabler

Attend - Lesson Monitor users if they are using the standard template letters

 

Other than that, if they are using only SIMS.net, which is going to be most teaching staff, they don't actually even need the S: drive mapped.

  • Thanks 3
Posted

This has been on my list of things to look at for a while after a couple of staff went, "oh I'm out of space for my photos, there's a load of space, I'll dummp them over there!"

 

Thanks for this!

  • Thanks 1
  • 2 weeks later...
Posted

Well after waiting several weeks for a reply from our LEA this is the response on how to secure the S:\ drive permissions:

 

We have now received a response from Capita and they are recommending full control for the whole drive for SIMS users. See below:

 

Thank you for contacting SIMS Support. Based on the information on the case, below is a summary of the issue. If any information was missed or incorrect, please let us know.

 

Capita Hosted School (Yes/No) :No

Route Taken : S Drive

Issue/Query : Permissions queries

Number of users affected : unknown

Number of machines affected : unknown

Troubleshooting steps tried : unknown

Solution, advice and/or next steps to take/check : We usually suggest "full control" permissions so that it avoids any errors but if you really want to avoid that then you will at least need Read, Write, List folder contents and Modify as the files in there require those actions when being used and updated from SIMS.

 

If you still wish to proceed, you could try restricting access as suggested above for your curriculum users. If this doesn’t work, you can always revert.

Posted
That info is severely out of date from Capita! The problem is that there is sensitive data that must not be accessible by everyone! Such as the Staff Workforce Census data.
  • Thanks 1
Posted
That info is severely out of date from Capita! The problem is that there is sensitive data that must not be accessible by everyone! Such as the Staff Workforce Census data.

 

I agree their response is a joke - but what to do? Point them to this thread??!

Posted
I agree their response is a joke - but what to do? Point them to this thread??!

 

Escalate and ask for a breakdown of which modules require access to which folder trees. They must have that information. From there you can restrict folders based on people's group membership in SIMS.

 

We've been running granular permissions on S for years without ill effect, it's not hard.

  • Thanks 1
Posted

I had an issue where one member of staff could see a particular part of SIMS, but it wasn't documented in the spreadsheet or in the permissions tree as an option.

 

Capita told me:

 

I'm afraid we do notprovide support for individual permissions within the permissions tree. I haveattached the permissions spreadsheet though that has details of the groups andwhat permissions they provide so you can go through this and see what group theusers may have that are allowing them to see this group.

 

How useful , NOT when they provide the software!

Posted
Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers.
  • Thanks 1
Posted
Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers.

 

What if you leave them in the security group but remove the S:\ drive mapping?

Posted
Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers.

 

Have a look at the connect.ini you are sending out via SOLUS3, it needs to point directly to the SQL server/instance and not a redirected one to the S: drive's UNC path.

  • Thanks 1
Posted

A quick update - I've gone back to the dev team to refine the KB.

@ITGURU - what we can't do is provide support for an infinite number of permission permutations in an infinite number of routes. I'll advise the team to express this more clearly.

Posted

@PhilNeal @ITGURU Whilst I completely agree that permissions must be done to an individual school, what capita can do (and I don't believe have done in the last 5 years - someone correct me if i'm wrong but I've not located a knowledge base article tonight when searching, nor previously) is:

 

a) advise schools what legacy folders are safe to delete/remove from a capita point of view, whilst advising schools to think about their own data retention

b) provide guidance on how sims currently uses it's shared drive

 

I know we've still got a copy of Star for DOS and related data files sitting on our S: drive - pretty sure even with the 7+ years data retention we likely need to keep data for, that those files could be removed - and by keeping them may be a data protection risk? (were the old star for dos dbase files encrypted? - i'm guessing not) - yet those files currently live in a folder where there are live folders for novat/p, options. I suspect if there was a clear document listing what is still used, and people were able to tidy up legacy folders that working out the appropriate permissions should be something that would be more then feasible for any competent network admin to do...

Posted
A quick update - I've gone back to the dev team to refine the KB.

@ITGURU - what we can't do is provide support for an infinite number of permission permutations in an infinite number of routes. I'll advise the team to express this more clearly.

@PhilNeal

It's quite normal for software suppliers to advise the permissions required on their software folders.

 

Why is there an infinite number of permission permutations? There is not an infinite number of folders installed to the S:\ - it's your software, you should know what you put there.

 

Ransom-ware is A REAL THREAT to schools and as such we should not just be told to give all SIMS users FULL PERMISSION - it simply does not wash anymore. If you read back through the thread you will see that one LEA has issued what seems like good advice - did this not come from CAPITA? If not and they worked this out on their own, can your extensive resources not be channelled to help schools out in securing our data in the folders of your systems?

 

I look forward to your reply to this and to @minimoo 's questions.

  • Thanks 1
Posted (edited)

I think the problem @kennysarmy is that some of the folders can be named different things, depending on how SIMS/FMS have been set up. I know we found that some of our FMS data was being saved in a different place than was usual for the area when I went through doing this, as an example.

 

However, that said, advice on permissions doesn't need to be that specific. It can be more "the folder used to export your BACS runs is used by XYZ users, consider limiting NTFS permissions to those users only. This folder is often called Blah, Bleh or Bloo".

 

Advice on the security of this stuff is incredibly important, and Capita are dropping the ball here by not offering thorough advice - especially in light of our Data Protection obligations, and the up coming GDPR stuff.

Edited by elsiegee40
Put the GDPR letters in the right order
  • Thanks 1
Posted
@kennysarmy - the question from @ITGURU was about permissions within SIMS not access to folders in the operating system

 

I know (?)

 

I don't think I mentioned operating systems....

 

To be clear - I would love some guidance on securing the folders WITHIN the SIMS folder on the file server (The mapped S:\ drive)

 

Thanks.

Posted
the question from @ITGURU was about permissions within SIMS not access to folders in the operating system

Until ITGURU posted, this thread was to do with the S:\ drive permissions. Could we have some official guidance on this please?

  • Thanks 1
Posted
For our SIMS training databases I created an SQL script that sets all those file paths within SIMS, it should be reasonably simple to reverse it so it gets the values and package it as a DBDiagnosis script so schools can see what folders SIMS is currently configured to use. I think that if Capita were to do this I'm sure it would be a helpful tool in this sort of discussion as guidance could tell schools to run the DBDiag script and substitute the results in to a standard document giving advice on what to secure etc.
Posted

@kennysarmy @PhilNeal Sorry - as I think I missed the change of topic from ITGuru last night and thought we were still on the same topic - i.e. that Phil was saying that they couldn't support schools setting up S: drive permissions as ad groups / requirements etc are different... In any case, given that some things e.g. the attendance module - originally defaulted to saving files to S:\SIMS\ATTEND\Templates and the old DBase Data files live at S:\SIMS\ATTEND [i know this might vary for some schools], it would be good one day to see some clear guidance to allow these folders to be safely cleared down.

 

I think in the modern sims that equates to the only things that may likely still be using a shared driver are a) attendance templates/letters, b) CTF files - both in and outwards c) documentation (from solus file server deployment) d) exams hold/in/out directories e) BACs FMS transfers f) Workforce census g) school census h) school census results reports i) NovaP data j) Options data k) Nova-T data l) a simsconnect.ini (used by solus 3) / FDS ini for fms (if multiple db's) and that anything else can probably be removed. From a personal point of view - given that S:\SIMS\*.pdf used to be where manuals + applications were stored (but I think this has moved to a sub-Documentation folder for us at least) - i'm not sure if all the documentation has moved.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...