garethEds Posted September 12, 2017 Posted September 12, 2017 Morning All, Wondering which forum to put this into - but basically a question to those schools that operate a BYOD system for either all pupils in the school or just for Sixth formers. We are looking at it but the LEA are worried about safeguarding - this is despite pupils being able to go outside and access information via their mobile phones. What systems (if any) have you put in place to ensure your BYOD system is safe, secure and covers safeguarding. The funny thing is, people have been asked to provide a list of issues that they are worried about but are failing to do so. SO if anyone has a list, or links to research then that would be great. I'll start searching the web later but to save re-inventing the wheel, I'm sure some schools/LEAs have already thought about the issues that could arise and may have lists/policies etc. Many thanks Gareth
Roberto Posted September 12, 2017 Posted September 12, 2017 Hi Gareth, We have our users, staff students and guests, all authenticate to our local implementation of eduroam wireless which uses RADIUS auth. We then can use RADIUS accounting info to send the IP and user details of the user to our firewall which then knows who they are on whatever device they use without requiring anyone to authenticate further. It's then easy to say that staff BYOD devices get the staff filtering settings, students get normal student settings, visitors get a general 'guests' policy and all activity is logged against IP and user ID for future reference. We're worried about both accessing and posting questionable material in terms of both safeguarding, cyberbulling, prevent, and we're happy this is a decent answer to our needs.
markwilfan Posted September 12, 2017 Posted September 12, 2017 Same as @Roberto . We use radius auth using Windows nps, Aruba instant and smoothwall. Works a treat. Only for staff, 6th and guests due to lack of classroom policy atm
Norphy Posted September 12, 2017 Posted September 12, 2017 I now have a similar setup. There is a BYOD SSID which allows our users to connect to the net. Our Smoothwall is used as the RADIUS accounting source so it knows who has logged on with which IP address. Appropriate filtering and logging policies are applied there.
pcstru Posted September 13, 2017 Posted September 13, 2017 What systems (if any) have you put in place to ensure your BYOD system is safe, secure and covers safeguarding. We have two systems. First is public access via a voucher. They connect to a specific SID and are directed to a captive portal which validates the voucher. We use this for transient visitors who we do not want to create accounts for. Smoothwall applies the most restrictive filtering to this although we do not issue vouchers to students. Second, for 6th form we record the MAC address of the device in AD, which allows them to connect to the BYOD SID. They then need to authenticate as a user to pass through smoothwall. My biggest issue is bandwidth management, the ability of AP's to deal with large numbers of clients and the internet bandwidth they can consume. I'm not sure if that is better or worse than having a bunch of phones acting as hotspots and interfering with our APs. A shame smoothwalls bandwidth management is not up to the job.
AlanD Posted September 13, 2017 Posted September 13, 2017 No difference between BYOD and schools own devices. Users are identified via AD credential ... using radius...and monitoring and filtering is in place. I've always wanted the school to agree to "test" that phones or tablets with 3/4G are at least filtered by the provider...but SLT think we can't do that....possibly because they want to avoid confronting parents. Does seem a nonsense that we spend thousands filt earring and monitoring...but at the same time they can go and do what they like via 4G. I think government needs to think about empowering parents..and smart phones held by children should be totally supervisable by parents ...and during school hours the school..and apple and android need to build this into their OS. At the moment they are working really hard on things like end to end privacy...and I don't think this is appropriate for young students.
elsiegee40 Posted September 13, 2017 Posted September 13, 2017 When on the school network, using the filters you have for school devices is the way to go I would have thought, simply to maintain the Prevent and Safeguarding requirements. You have absolutely no control whatsoever over what they do over 3G/4G and never will do whether in school or out. If you tried, they'd simply get another device or not use the BYOD at all.
elsiegee40 Posted September 13, 2017 Posted September 13, 2017 (edited) I think government needs to think about empowering parents..and smart phones held by children should be totally supervisable by parents ...and during school hours the school..and apple and android need to build this into their OS. At the moment they are working really hard on things like end to end privacy...and I don't think this is appropriate for young students. Impossible and impractical. Schools don't have the same hours or days as each other locally let alone nationally. And some kids are educated at home. Won't happen. If it did, kids would just get phones registered as adult users. It's the facebook under 13s issue. Edited September 13, 2017 by elsiegee40
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now