Jump to content

Recommended Posts

Posted
only allowing authorised email accounts which we can monitor, audit and if needed shutdown

So, when someone uses your authorised email system to send a file to their home email account, what happens??

Posted
So teachers having school-owned laptops or VPN access is the only way to comply?

 

I was at a MS conference about GDPR and this question was raised. Wolly answer time but the jist was that if you cant say what user X has done with your data or cant justify your taking steps towards implementing a solution you are not complaint. We can no longer live in ignorance :ohwell:

 

I suppose we will know more once clearer guidelines for schools are published.

  • Thanks 1
Posted

I think this is the problem - logging what happens on a removable USB device is very impractical. Logging what everyone does in the cloud is easier, but then what does this actually prove?

 

If I hack x users account, all the logging appears in their name...

 

I can't help but think there are huge holes in GDPR already.

 

How long would we need to keep logs? I think the issue with GDPR is over a short period of time, it will create thousands or even millions of entries. Just completely unmanageable, so the guidelines need to be precise and not suggestive. All down to interpretation then, which creates even more holes.

Posted
So, when someone uses your authorised email system to send a file to their home email account, what happens??

 

You should inform the person concerned that they are not allowed to do this and they need to follow the schools data guidance. They do not own this data the business or school does. I would also be asking why they felt the need to do this, why is it not easier to use the systems we have put in place.

 

You are right in that we can not control what others do but they could be in a lot of trouble if they do not follow the policies supplied. and signed

Posted (edited)

All my primary schools have only been allowed encrypted keys for about the last 4 years. If they want remote access they must use a school laptop to access the RD server. If they use Google drive they must have 2 factor authentication. If I find anyone not following the above I will pass the information on to the school data manager.

 

The thing is, if you have all these things setup in an easy to use way the staff actually want to use them as its easier than emailing a file, trying to remember which file was lasted updated etc.

 

With the exception of encrypted keys we can audit all the rest.

Edited by TwistedHelixis
Posted
If I hack x users account, all the logging appears in their name...

 

That would be covered under a very different legal framework. If something has been hacked you would need to call the police and report it, although 2 factor authentication makes this much more difficult.

Posted
I think it comes down to the fact that it's a lot harder for hundreds/thousands of paper documents to make their way into the wrong hands in bulk without anyone noticing, compared to their digital equivalent.

I'd disagree. The duty of care is the same in both cases so an organisations response should be to exercise essentially the the same care.

 

IMO the guidance will likely be similarly helpful to their guidance on encryption. They will not dictate specific techniques or technology rather they will say that whatever is used should be appropriate. IMO auditing of data access such as proposed here would only arise as a result of a risk assessment of specific, usually sensitive data and then only where strict partitioning (access control) cannot be met [*1] (so think the Police National DB where the police need access to do their job but there is a risk of abuse by (say) them looking up details of the person the want a date with).

 

[*1] Because access control is preferred, this is Data Protection, auditing access is only useful as evidence of a breach after the fact - it does absolutely nothing to actually protect the data in the first place.

Posted
I'd disagree. The duty of care is the same in both cases so an organisations response should be to exercise essentially the the same care.

 

Yeah, I don't really know why I mentioned hundred/thousands of paper documents. One paper record being stolen or handled carelessly could be just as potentially serious for an individual, so I would agree with your point about the duty of care being the same.

Posted
So, when someone uses your authorised email system to send a file to their home email account, what happens??

 

You should inform the person concerned that they are not allowed to do this and they need to follow the schools data guidance.

 

So, you are recording every email sent, including recipient and content?

  • 2 weeks later...
Posted
My concern is the level of access given by SIMS under their Predefined Roles. They always seem excessive and it's time consuming to cut them down but still allow functionality. I wonder how this will sit within the GDPR regulations.
Posted
My concern is the level of access given by SIMS under their Predefined Roles. They always seem excessive and it's time consuming to cut them down but still allow functionality. I wonder how this will sit within the GDPR regulations.

 

I've found myself wondering that too, as there is some safeguarding information held in SIMS which will need reviewing under GDPR audits.

  • 2 weeks later...
Posted
IMO the guidance will likely be similarly helpful to their guidance on encryption. They will not dictate specific techniques or technology rather they will say that whatever is used should be appropriate.

Was thinking the same thing - it'll be audit logging on sensitive data. But what is sensitive data?! Serious question, medical would be obvious, but in an emergency, I'd rather more people knew I couldn't have penicillin for example

[*1] Because access control is preferred, this is Data Protection, auditing access is only useful as evidence of a breach after the fact - it does absolutely nothing to actually protect the data in the first place.

I don't know. Doesn't auditing act as a layer of security? Wouldn't it make you think twice if you knew you would be caught, its just a matter of time. (I mean in general terms, not personally)

Posted
Was thinking the same thing - it'll be audit logging on sensitive data. But what is sensitive data?! Serious question, medical would be obvious, but in an emergency, I'd rather more people knew I couldn't have penicillin for example

According to the ICO, sensitive personal data is ..., so medical info would fall under the definition of "sensitive data"

I don't know. Doesn't auditing act as a layer of security? Wouldn't it make you think twice if you knew you would be caught, its just a matter of time. (I mean in general terms, not personally)

I would not dispute that but I'd point to instances of abuse of the Police National database as evidence that it's deterrence effect is not foolproof (i.e. despite the chance of being caught, there is still evidence that abuse occurs). My point is the cost of auditing READ access to a database. To be honest, I don't think people really appreciate what they are asking for or what the cost of that would be. It is only practical at an application level (user A accessed Screen X viewing entity 901 at 9:01am on 27/07/2017), so any direct DB access will just bypass it.

Posted
Was thinking the same thing - it'll be audit logging on sensitive data. But what is sensitive data?! Serious question, medical would be obvious, but in an emergency, I'd rather more people knew I couldn't have penicillin for example

 

I don't know. Doesn't auditing act as a layer of security? Wouldn't it make you think twice if you knew you would be caught, its just a matter of time. (I mean in general terms, not personally)

 

This is only a valid defence if you can show that staff are well trained, their training / knowledge / compliance is assessed on a regular basis (and to a given standard, if necessary) and that you have lifecycle management in place around the whole arena ...

 

Oh, doesn't this sound a lot like H&S, COSHH, etc.?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...