Jump to content

Recommended Posts

Posted

I have been looking to update the staff AUP here for a while now and it just so happens I have been speaking to the Chair of Governors and the Head about it today.

 

At the moment the policy has guidance on saving sensitive information to portable drives how it should be encrypted etc. The policy also informs staff that the school will issue them with an encrypted memory stick if they need carry sensitive data on a portable device.

 

However the Head and the Chair of Governors are concerned that because staff still use personal USB drives they could still be saving sensitive data to that rather than an encrypted device.

 

Stoping the use of non encrypted devices isn't an option as the encrypted devices we provide are only 4GB.

 

They have asked me to find out if there is a way for the school to ensure the guidance in the policy about encrypting sensitive data on portable devices is actually being followed. It's all fine and well having it written in a policy but is it being followed was the question!

 

Reading between the lines I think they might want to be able to do random spot checks on staff USB drives that are being used on the school network that are not encrypted to ensure compliance.

 

I could be way off here but that's the vibe I was getting.

 

We have impero here so I suppose we could run reports looking for window captions for portable devices. We use USBDLM here so I already know the drive letters that will be assigned the devices.

 

I suppose thinking about it maybe the AV logs would also help out.

 

I want to know if any one else is doing anything similar, has any suggestions as to what to do, or if in fact the school is even able to spot check a personal device.

Posted (edited)

We use Microsoft MBAM, part of the MDOP suite.

 

Using MBAM we can centralise key escrow (it all goes back to an MS SQL database with a fancy web front-end) and set fine grained policies (GPOs) relating to operating system disk, external disk, and removable media encryption. We use it to enforce BitLocker on the operating system drive using a start up PIN across all staff laptops, and then use it to enforce password based encryption on USB sticks.

 

This is pretty much perfect for us because if staff don't want to encrypt their home USB sticks, it will mount them in Windows as read-only, then if they try to copy any data to it in school it'll ask them to set up encryption first or deny it if they hit cancel. When this happens it will then send all recovery keys off to our MBAM server should they forget them.

 

It also has a web-based reporting tool and can totally integrate with SCCM if you use it. I'd highly recommend it.

 

Oh... and it also works on any standard USB stick, so no need to waste money on those fancier encrypted ones. Our policies state work is NOT to be done on home computers where a school laptop is provided. Obviously we can't police that but we've done all we can in the eyes of the law to protect our data, so at that point I believe it falls onto staff for breaking our policies.

Edited by Blue_Cookeh
Posted
Do you have the capacity to Use RDP from home to the school, it will save a lot of hassle with encryption on laptops and which the data will be offsite.
Posted

If you are concerned on encryption etc then make staff to save there work to staff laptops when taking there laptop home and enable bitlocker. On bootup it will ask for a code and it will encrypt the full drive.

 

Even if someone had your school staff laptop and try to get the data off, it will still require a password for bitlocker.

Posted
Do you have the capacity to Use RDP from home to the school, it will save a lot of hassle with encryption on laptops and which the data will be offsite.

 

Thanks for that.

 

We have a 2012 RDS farm as well as Office 365 but staff still insist on using USB devices.

Posted
If you are concerned on encryption etc then make staff to save there work to staff laptops when taking there laptop home and enable bitlocker. On bootup it will ask for a code and it will encrypt the full drive.

 

Even if someone had your school staff laptop and try to get the data off, it will still require a password for bitlocker.

 

The focus here is primarily on USB devices and trying to ensure compliance with the school policy on encryption and the use of sensitive data.

 

We have laptops for the SLT that are taken offsite and they are all encrypted with bitlocker and a startup pin.

Posted
The focus here is primarily on USB devices and trying to ensure compliance with the school policy on encryption and the use of sensitive data.

 

We have laptops for the SLT that are taken offsite and they are all encrypted with bitlocker and a startup pin.

 

If you're on an EES agreement I believe MBAM is now included with the OS licensing, which will cover your needs for USB and make management of your OS BitLocker encryption easier.

Posted (edited)
Stoping the use of non encrypted devices isn't an option as the encrypted devices we provide are only 4GB.

 

If they are insisting on USB then why not get larger encrypted USB keys, they are sooooo cheap. Staff at my schools are not allowed normal USB keys.

 

16gb or 32gb cost nothing

Edited by TwistedHelixis
Posted
If they are insisting on USB then why not get larger encrypted USB keys, they are sooooo cheap. Staff at my schools are not allowed normal USB keys.

 

16gb or 32gb cost nothing

 

That's a good point but I shudder think about the size of the USB drives staff are currently using around the school and having to accommodate that capacity with an encrypted device.

 

So how are you enforcing the no normal USB devices at your school?

Posted
I just banned them.. and all portable devices are encrypted with bit locker as part of intune. I sold it to staff that USB provides too many limitations in terms of access anywhere on any device.. welcome to office 365. Staff know not to safe sensitive data as I regularly remind them. We also provide staff with remote access via rdp. Looking at some dual auth now too

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...