Jump to content

Recommended Posts

Posted

Does anyone ask their technical teams to sign an IT Team specific AUP or do they all sign the standard staff policy?

 

Our general staff AUP doesn't cover some things that IT staff have access too e.g. server rooms. I need to write one but didn't want to reinvent the wheel if anyone had one or a template I could use.

 

Thanks

  • Thanks 1
Posted

To be honest, alter the general staff one as a range of staff will need access to protected and sensitive systems.

Then make sure you have a process in place for permission to be requested and a record of authorisation and subsequent granted access.

 

This will apply to SLT, SENDCO, IT staff, site staff, caterers, MIS manager, exams officer, timetables, Governors, etc.

Posted
To be honest, alter the general staff one as a range of staff will need access to protected and sensitive systems.

 

ALL staff have access to protected and sensitive data, so something in the AUP about only accessing data for school purposes would cover this and a lot of potential mis-use by IT Support staff. Our AUP says that, and we have various technical procedures in place about upgrade processes which must be followed, so we're probably covered. This has prompted me to review them though!

  • Thanks 1
Posted

I suggest you check your school's Data Protection Policy and staff code of conduct before writing any new IT policy - you may find it is already covered. I've just re-read ours, and I'm satisfied the existing policies cover mis-use of access granted via elevated and/or admin permissions. The policies may not spell it out in as many words by saying "staff must not access data in SIMS which they're not supposed to, and IT staff mustn't browse round staff members' areas and emails", but there are references to following data protection guidelines and only accessing data for work purposes, which I think cover it.

 

Of course, IT staff can and should look at what is in people's areas, as it is part of managing disk space, but of course there's a difference between noting a staff member has 200 holiday photos on the network and actually looking at those photos.

 

Another thing to look for while reviewing your policies is whether you prevent staff who are also parents from looking up information which regular parents can't see. I've seen problems arise from that before now.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...