kennysarmy Posted February 9, 2017 Posted February 9, 2017 Our Current SIMS server is a VM with C: and S: drives. The S:\ drive is shared with share permissions "Everyone FULL CONTROL" Staff who require SIMS are added to a global security group called SIMS and this group has FULL Control on the S:\ drive. I don't believe the system should be this open, but the Server was created by our Local SIMS support team a few years ago. I've emailed them for advice on how to secure it a bit tighter and after three weeks of chasing via email I've still not got any information on this. Can anyone advise if the S:\ drive for SIMS can be secured a bit tighter... Thanks.
Popular Post localzuk Posted February 9, 2017 Popular Post Posted February 9, 2017 This is the advice I was sent by our local SIMS team: [h=3]Introduction[/h]For many years, since SIMS was first used in schools, a network drive (normally S:\) has been made available for all staff, and full access given to allow SIMS to run. Over time we have provided some guidance on securing some of the folders containing some of the more sensitive data, although Acceptable Use Policies should be in place and cover staff accessing and using data appropriately. With the implementation of SOLUS3 for SIMS upgrades, it is less of a need for all staff to have an S: drive mapped as the configuration files for SIMS and FMS can point straight to the server and database rather than redirecting to a file on the S: drive. This is now possible as SOLUS3 can push replacement config files to each workstation in the event of a server being replaced with one using a different name. SOLUS3 is installed in most schools now, but not all. If schools wish to restrict access to either the entire S: drive, or elements of it then this guidance can be used to help achieve this. [h=3]How to Restrict Access[/h]Access is controlled by allocating users, or groups of users permissions to folders. To make the administration of this easier it is advisable to create network (Active Directory) groups on the server and adding staff to those groups. When there are staff changes permissions are managed by changing the members in the groups rather than having to change permissions on each of the appropriate folders. Each school may have slightly different requirements, but as a suggestion, the following groups could be used as a starting point: · SIMSUsers - Any SIMS users who need access to an S: Drive · SIMSFinance - SIMS FMS users requiring access to files used by FMS · SIMSCensus - Access for staff completing the termly School Census · SIMSSWC - For staff involved in the annual School Workforce Census · SIMSCTF - For staff dealing with the import and export of CTF files [h=3]Relevant Folders (In a standard installation)[/h]SIMSArea mapped as S: Where SOLUS3 is installed consider if all staff need access to files on S: drive. For federated schools where cross site access to SIMS has been set up, and for Finance users where there is more than one FMS database is used (Academies and schools managing CLP finances) an S: drive mapping is still required. Consider changing the folder permissions to be restricted to a SIMSUsers group rather than an allStaff group and only including staff who need access to S: drive in this group. Staff who will still need access to an S: drive include: · Staff who run reports from SIMS or FMS and need to save the output for further work, such as the texting or email@school reports. · Staff who run reports that include embedded logos stored on the S: drive. · Staff who are involved in completing end of year procedures. · In Secondary schools Exams Officers and Timetablers will also require access to the S: drive. S:\TABS Used for Finance TABS files. Tabs files contain details of salary payments to staff. Consider restricting to full access for Finance Staff only. S:\SIMS\Transfer\IN, OUT & READ Used for invoice files sent to County for payment (non Local Chequebook Schools) and reconciliation files containing details of salary payments to staff. Consider restricting to full access for Finance Staff only. S:\Journals or S:\SIMS\Journals (or similar) Finance journals. Consider restricting to full access for Finance Staff only, although this folder does not usually contain sensitive/individual data. S:\Form11 Queries or S:\SIMS\Form11 Queries Finance returns files. Consider restricting to full access for Finance Staff only. S:\SIMS\SchoolWorkforceCensus School Workforce Census files. Contains individual’s total base pay, allowances, absences etc. Consider restricting to full access for staff dealing with this return. S:\SIMS\STAR\ASCOut Termly School Census files. Consider restricting to full access for staff dealing with this return. S:\SIMS\STAR\CTFIN & CTFOut Used during the importing and exporting of CTF files, and may contain sensitive pupil data. Consider restricting to full access for staff who deal with the transfer of pupil data via CTF files. 5
Linfit Posted February 9, 2017 Posted February 9, 2017 These days the only people who really need access to the S drive are those that use legacy apps, like Exams Organiser, Options, or Nova, and those staff that produce the census and CTF files. Inside the sims folder you can restrict permissions on the folders as follows: Exams - Exams Officer and anyone who uses Exams Organiser Options - Anyone using options STAR - Anyone generating CTF files and whoever does the census returns SNOVA - Timetabler Attend - Lesson Monitor users if they are using the standard template letters Other than that, if they are using only SIMS.net, which is going to be most teaching staff, they don't actually even need the S: drive mapped. 3
PotNoodleTech Posted February 9, 2017 Posted February 9, 2017 That's a great overview localzuk, cheers for posting it!
ItsOggy Posted February 9, 2017 Posted February 9, 2017 This has been on my list of things to look at for a while after a couple of staff went, "oh I'm out of space for my photos, there's a load of space, I'll dummp them over there!" Thanks for this! 1
kennysarmy Posted February 20, 2017 Author Posted February 20, 2017 Well after waiting several weeks for a reply from our LEA this is the response on how to secure the S:\ drive permissions: We have now received a response from Capita and they are recommending full control for the whole drive for SIMS users. See below: Thank you for contacting SIMS Support. Based on the information on the case, below is a summary of the issue. If any information was missed or incorrect, please let us know. Capita Hosted School (Yes/No) :No Route Taken : S Drive Issue/Query : Permissions queries Number of users affected : unknown Number of machines affected : unknown Troubleshooting steps tried : unknown Solution, advice and/or next steps to take/check : We usually suggest "full control" permissions so that it avoids any errors but if you really want to avoid that then you will at least need Read, Write, List folder contents and Modify as the files in there require those actions when being used and updated from SIMS. If you still wish to proceed, you could try restricting access as suggested above for your curriculum users. If this doesn’t work, you can always revert.
localzuk Posted February 20, 2017 Posted February 20, 2017 That info is severely out of date from Capita! The problem is that there is sensitive data that must not be accessible by everyone! Such as the Staff Workforce Census data. 1
kennysarmy Posted February 20, 2017 Author Posted February 20, 2017 That info is severely out of date from Capita! The problem is that there is sensitive data that must not be accessible by everyone! Such as the Staff Workforce Census data. I agree their response is a joke - but what to do? Point them to this thread??!
kennysarmy Posted February 20, 2017 Author Posted February 20, 2017 @PhilNeal Is there anything you can add? Regards
pete Posted February 20, 2017 Posted February 20, 2017 I agree their response is a joke - but what to do? Point them to this thread??! Escalate and ask for a breakdown of which modules require access to which folder trees. They must have that information. From there you can restrict folders based on people's group membership in SIMS. We've been running granular permissions on S for years without ill effect, it's not hard. 1
PhilNeal Posted February 20, 2017 Posted February 20, 2017 I've asked the service desk manager to take a look at the response. 1
ITGURU Posted February 20, 2017 Posted February 20, 2017 I had an issue where one member of staff could see a particular part of SIMS, but it wasn't documented in the spreadsheet or in the permissions tree as an option. Capita told me: I'm afraid we do notprovide support for individual permissions within the permissions tree. I haveattached the permissions spreadsheet though that has details of the groups andwhat permissions they provide so you can go through this and see what group theusers may have that are allowing them to see this group. How useful , NOT when they provide the software!
TwistedHelixis Posted February 20, 2017 Posted February 20, 2017 Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers. 1
kennysarmy Posted February 20, 2017 Author Posted February 20, 2017 Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers. What if you leave them in the security group but remove the S:\ drive mapping?
Esteban_Child_of_the_Sun Posted February 20, 2017 Posted February 20, 2017 Following this post I thought I would remove my teachers from the Sims security group in AD and remove the S drive mapping but the teachers are not able to use Sims after doing this. I assume I need to change something in Solus3, any pointers. Have a look at the connect.ini you are sending out via SOLUS3, it needs to point directly to the SQL server/instance and not a redirected one to the S: drive's UNC path. 1
PhilNeal Posted February 21, 2017 Posted February 21, 2017 A quick update - I've gone back to the dev team to refine the KB. @ITGURU - what we can't do is provide support for an infinite number of permission permutations in an infinite number of routes. I'll advise the team to express this more clearly.
minimoo Posted February 21, 2017 Posted February 21, 2017 @PhilNeal @ITGURU Whilst I completely agree that permissions must be done to an individual school, what capita can do (and I don't believe have done in the last 5 years - someone correct me if i'm wrong but I've not located a knowledge base article tonight when searching, nor previously) is: a) advise schools what legacy folders are safe to delete/remove from a capita point of view, whilst advising schools to think about their own data retention b) provide guidance on how sims currently uses it's shared drive I know we've still got a copy of Star for DOS and related data files sitting on our S: drive - pretty sure even with the 7+ years data retention we likely need to keep data for, that those files could be removed - and by keeping them may be a data protection risk? (were the old star for dos dbase files encrypted? - i'm guessing not) - yet those files currently live in a folder where there are live folders for novat/p, options. I suspect if there was a clear document listing what is still used, and people were able to tidy up legacy folders that working out the appropriate permissions should be something that would be more then feasible for any competent network admin to do...
kennysarmy Posted February 22, 2017 Author Posted February 22, 2017 A quick update - I've gone back to the dev team to refine the KB. @ITGURU - what we can't do is provide support for an infinite number of permission permutations in an infinite number of routes. I'll advise the team to express this more clearly. @PhilNeal It's quite normal for software suppliers to advise the permissions required on their software folders. Why is there an infinite number of permission permutations? There is not an infinite number of folders installed to the S:\ - it's your software, you should know what you put there. Ransom-ware is A REAL THREAT to schools and as such we should not just be told to give all SIMS users FULL PERMISSION - it simply does not wash anymore. If you read back through the thread you will see that one LEA has issued what seems like good advice - did this not come from CAPITA? If not and they worked this out on their own, can your extensive resources not be channelled to help schools out in securing our data in the folders of your systems? I look forward to your reply to this and to @minimoo 's questions. 1
localzuk Posted February 22, 2017 Posted February 22, 2017 (edited) I think the problem @kennysarmy is that some of the folders can be named different things, depending on how SIMS/FMS have been set up. I know we found that some of our FMS data was being saved in a different place than was usual for the area when I went through doing this, as an example. However, that said, advice on permissions doesn't need to be that specific. It can be more "the folder used to export your BACS runs is used by XYZ users, consider limiting NTFS permissions to those users only. This folder is often called Blah, Bleh or Bloo". Advice on the security of this stuff is incredibly important, and Capita are dropping the ball here by not offering thorough advice - especially in light of our Data Protection obligations, and the up coming GDPR stuff. Edited June 20, 2017 by elsiegee40 Put the GDPR letters in the right order 1
PhilNeal Posted February 22, 2017 Posted February 22, 2017 @kennysarmy - the question from @ITGURU was about permissions within SIMS not access to folders in the operating system
kennysarmy Posted February 22, 2017 Author Posted February 22, 2017 @kennysarmy - the question from @ITGURU was about permissions within SIMS not access to folders in the operating system I know (?) I don't think I mentioned operating systems.... To be clear - I would love some guidance on securing the folders WITHIN the SIMS folder on the file server (The mapped S:\ drive) Thanks.
Arthur Posted February 22, 2017 Posted February 22, 2017 the question from @ITGURU was about permissions within SIMS not access to folders in the operating system Until ITGURU posted, this thread was to do with the S:\ drive permissions. Could we have some official guidance on this please? 1
Esteban_Child_of_the_Sun Posted February 22, 2017 Posted February 22, 2017 For our SIMS training databases I created an SQL script that sets all those file paths within SIMS, it should be reasonably simple to reverse it so it gets the values and package it as a DBDiagnosis script so schools can see what folders SIMS is currently configured to use. I think that if Capita were to do this I'm sure it would be a helpful tool in this sort of discussion as guidance could tell schools to run the DBDiag script and substitute the results in to a standard document giving advice on what to secure etc.
Popular Post PhilNeal Posted February 22, 2017 Popular Post Posted February 22, 2017 I've had an update from our engineers - we will update our advice on this issue aiming to be complete by Monday. I'll post on here when the revised advice is available. 6
minimoo Posted February 22, 2017 Posted February 22, 2017 @kennysarmy @PhilNeal Sorry - as I think I missed the change of topic from ITGuru last night and thought we were still on the same topic - i.e. that Phil was saying that they couldn't support schools setting up S: drive permissions as ad groups / requirements etc are different... In any case, given that some things e.g. the attendance module - originally defaulted to saving files to S:\SIMS\ATTEND\Templates and the old DBase Data files live at S:\SIMS\ATTEND [i know this might vary for some schools], it would be good one day to see some clear guidance to allow these folders to be safely cleared down. I think in the modern sims that equates to the only things that may likely still be using a shared driver are a) attendance templates/letters, b) CTF files - both in and outwards c) documentation (from solus file server deployment) d) exams hold/in/out directories e) BACs FMS transfers f) Workforce census g) school census h) school census results reports i) NovaP data j) Options data k) Nova-T data l) a simsconnect.ini (used by solus 3) / FDS ini for fms (if multiple db's) and that anything else can probably be removed. From a personal point of view - given that S:\SIMS\*.pdf used to be where manuals + applications were stored (but I think this has moved to a sub-Documentation folder for us at least) - i'm not sure if all the documentation has moved.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now