Jump to content

Recommended Posts

Posted

We are still going through the process of updating our acceptable use / byod / etc. policies and want to be 100% clear to both students and staff that as soon as they connect their personal devices to our networks everything is logged by our Smoothwall. Although we are not yet using HTTPS decrypt and inspect we will be doing so at some point. One line in particular has been singled out:

 

You can have no expectation of privacy when using our IT networks – everything you type, every website you visit and every social media post you make is recorded*

 

The suggestion is that we should seek legal advice as the line may be considered excessive and whilst I can understand the concern is it something we should tone down? I don't want people to be in any doubt whatsoever that the Smoothwall logs everything and we can see everything that goes through it - we would of course put exceptions in for banks and any other sites that are recommended as exempted from HTTPS decrypt and inspect but Facebook posts, YouTube comments and so on will be readable even if not actually read unless they trigger an alert.

 

*Thanks to @elsiegee40 for the idea for the text (albeit not necessarily deliberately) here :)

Posted
The suggestion is that we should seek legal advice as the line may be considered excessive and whilst I can understand the concern is it something we should tone down?

It might be OK for students but IMO it is not OK as standalone for Staff.

 

First, I doubt if it is true - do you really record ALL network traffic, ALL keystrokes? If so, that is surprising but if you do, what are your policies for access to it, for retention of it and for deletion? The main problem area is likely to be access to it. Do you have a policy which governs access to this data by staff - which may or may not include you? If you do not have a policy that controls who can access it, under what circumstances and who's permission needs to be sought and given etc, then you may well be in violation of peoples rights under various pieces of legislation (EU Human Rights, DPA, Business Communications, RIPA etc). It is not good enough to simply put in an AUP that staff are being monitored. The situation is different for students and you pretty well can do this AFAIAA.

 

To operate safely within the law, you need the monitoring policy in place and clearly communicated to staff. IMO that means they sign for it.

Posted

I'd say that it's too strong, and actually misleads users into thinking that IT are all over their devices like Hollywood hackers (able to see keystrokes on a private iPhone, etc.). That's something I would avoid, since it can create an unhelpful impression of IT techs sitting at their desks with nothing better to do than spy on people. Students can surely have ~some~ expectation of privacy: the web filter logs, etc. are confidential and any concerns arising from them ought to be being handled accordingly.

 

I would second elsiegee40's suggestion of sticking a 'may be' into whatever line you decide on.

Posted

My thoughts

 

 

You can have no expectation of privacy when using our IT networks – everything you type, every website you visit and every social media post you make is recorded*

 

Rephrase as;

 

Please be aware all activity is monitored and recorded for the purposes of security and safety. Logs are retained for a period of xx months.

Posted

The bit of our AUP that deals with this says

 

User areas on the school network are closely monitored and regular checks on your files and communications take place.

 

All internet access and most ICT activity in general is logged and can be examined at a later date if needed.

 

All files held on the network will be treated as school property, including e-mail.

 

Access to all web based e-mail with the exception of the school approved system is forbidden.

 

Failure to follow the code will result in loss of access and further disciplinary action as appropriate. When applicable, police or local authorities may be involved.

 

Payment will be requested for malicious damage caused to any part of the school network.

 

The security of ICT systems must not be compromised, whether owned by the school or by other organisations or individuals.

Posted

Good points and accurate - the 'everything you type' was in reference to social media posts and YouTube comments (which I believe are captured by Smoothwall) rather than sending texts from an iPhone but the difference is not at all clear. It was then further confused by adding the bit about social media posts as separate wording.

Staff and students will be asked to sign the policy which is why it's important we get the wording correct - I guess the existing wording would be easy to interpret as is active monitoring when in reality it is more likely to be a check through the logs by the DSL because a violation has been recorded. Tee problem is that the Smoothwall DOES log everything regardless of whether or not it is actually reviewed although we would (when we eventually get decrypt and inspect implemented) naturally exclude banking etc.

I'm trying to strike a balance between the rights of the user to privacy and our safeguarding duties - if I student is looking at porn sites from their personal device on our network we will know about it and they will be spoken to - I can't have them turn around and say we never told them it was logged and therefore they have no privacy. If a student is looking at porn sites using their own 4g it will be invisible to us via the Smoothwall and therefore they have privacy.

 

Guess I need to work on the wording :)

Posted
...and in the 30 minutes it took me to type that out (I get a lot of interruptions) some more posts have appeared with more good advice in them :)
Posted

The offending paragraph has been changed, I looked at changing the wording but in the end decided to just omit it:

 

Original - In order to protect you and safeguard our data we monitor and log the usage of our IT networks – that means all computer usage and all Internet usage. It is important that you understand that if you connect your personal device to our Wireless BYOD (Bring Your Own Device) network then all data sent or received when using our network is monitored and logged. You can have no expectation of privacy when using our IT networks – everything you type, every website you visit and every social media post you make is recorded. This helps us to comply with our safeguarding responsibilities and the governments’ PREVENT anti-terrorism strategy.

 

New - In order to protect you and safeguard our data we monitor and log the usage of our IT networks – that means all computer usage and all Internet usage. It is important that you understand that if you connect your personal device to our Wireless BYOD (Bring Your Own Device) network then all data sent or received when using our network is monitored and logged. This helps us to comply with our safeguarding responsibilities and the governments’ PREVENT anti-terrorism strategy.

 

I think it works just as well without the wording - just hope that the board agrees :)

Posted

We use this:

 

Monitoring

In line with government advice and conforming to the requirements of the Data Protection Act 1998 (Employment Practice Code Article 3), SCHOOLNAME monitors all ICT systems connected to the school network to ensure a stable network environment and fix problems before they become major issues.

 

SCHOOLNAME may monitor and audit users and their use of ICT to promote good practice and ensure users are complying with policy. Deliberate misuse will be reported to the Headteacher and illegal activity will be reported to the police.

 

All SCHOOLNAME computers report the contents of any files and Internet traffic likely to be a cause for concern to the Designated Safeguarding Lead (DSL) and their deputies. This happends regardless of where (at school, at home, elsewhere) the device is.

 

For the avoidance of doubt, activities carried out on SCHOOLNAME devices will be judged according to the AUP regardless of where that device is or when it is being used.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...