Jump to content

Recommended Posts

Posted

"processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures."

 

Is anyone considering looking at USB drive access and Wireless devices?

 

I am considering turning both off until a 'complete' secure mode of operation can be achieved.

Posted
"processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures."

 

Is anyone considering looking at USB drive access and Wireless devices?

 

I am considering turning both off until a 'complete' secure mode of operation can be achieved.

 

We enforce Bitlocker on any usb devices used in School. Are you talking BYOD wireless devices or school owned? Our BYOD devices just get access to the Internet. Our School owned wireless devices get access to the network.

Posted

I'll check out BitLocker (assuming the Head will support us cost wise). Our Sophos endpoint approach only takes us so far and does often fail to clean up some Viruses and Malware.

 

Wireless is more a question about network integrity once a devices become 'network aware'. A DHCP address is given (which is a range on our internal network).

Posted
I'll check out BitLocker (assuming the Head will support us cost wise). Our Sophos endpoint approach only takes us so far and does often fail to clean up some Viruses and Malware.

 

Wireless is more a question about network integrity once a devices become 'network aware'. A DHCP address is given (which is a range on our internal network).

 

Bitlocker is included with Windows so should be nil cost.

 

Our BYOD devices are all on a separate VLAN so do not pick up IPs on the same network as our internal devices.

Posted

Do you have routing between the Vlans? We do and that is the source of my concern. The DHCP servers and Proxy servers sit on our Server Vlan and then we let the layer 3 switches manage the packets between the Vlans. This provides a BYOD device with a 'route' to our Server Vlan and therefore a risk.

 

I can fix this as you would expect but I'm wondering if the GDPR compliance is making me over zealous about such things ... LOL

Posted
Well ideally you need ACLs between your BYOD Vlans and your domain VLANS. If there are domain joined systems you need to provide to BYOD you can put in a rule in layer 3 for the port required. In an ideal world vlans would exist for your devices and user groups staff and students. Or authenticated firewall rules. I don't think many of us have the capacity to maintain that level of security.
Posted

We're looking at either Bitlocker, or banning USB drives completely, probably the former. Be aware though if you enable Bitlocker, the drive will become unreadable to Mac and other OSs, including Windows pre-7.

 

Our guest WiFi is routed to be Internet access and DNS only, so hopefully that's secure. I hadn't thought of that one though!

Posted

Decided against Bitlocker (not Mac- or Chrombook-compatible) and banning them, but have policy (i.e. "operational measures") saying to password protect anything sensitive.

 

BYOD wireless devices sit in their own VLAN with ACLs and port-blocking rules in place to prevent anything other than DHCP, DNS and HTTP(S). All mobile printing is done via Google Cloud Print. BYOD access to MyDocs (only available on Windows) goes out of the network and back in, as if from home.

Posted
We've just implemented Bitlocker and have had frustrations with staff who use Macs. We've provided 2 alternatives - 1 buy a USB drive with built in encryption that works on PC and Mac (e.g. https://www.mymemory.co.uk/integral-32gb-secure-key-encrypted-usb-flash-drive.html), or use something like Veracrypt, although this needs to be installed on all PCs where the USB drive is used, which makes it a pain. Ultimately, I want to ban the things and just use OneDrive/Office 365.
  • Thanks 1
Posted
We've just implemented Bitlocker and have had frustrations with staff who use Macs. We've provided 2 alternatives - 1 buy a USB drive with built in encryption that works on PC and Mac (e.g. https://www.mymemory.co.uk/integral-32gb-secure-key-encrypted-usb-flash-drive.html), or use something like Veracrypt, although this needs to be installed on all PCs where the USB drive is used, which makes it a pain. Ultimately, I want to ban the things and just use OneDrive/Office 365.

 

We just purchased this for our few Mac users.

 

https://www.m3datarecovery.com/mac-bitlocker/purchase.html

Posted

This is the platform-independent memory stick we bought - https://istorage-uk.com/product/datashur-personal/ One person offered to buy it themselves since it was their choice to have a non-compatible computer at home, but I suspect you'd be on shaky (or at least unpopular) ground if you made that policy.

 

As @mjk says though, offer a decent remote access and people will naturally stop using memory sticks. Our students don't carry them any more now we have Google Apps, and the only staff who carry them are Powerpoint-lovers who haven't adopted Drive (understandably) or Google Slides (also fairly understandable), and even then it is just their PPTs on the memory sticks, the sensitive files are kept in Google.

 

Whatever you decide, make sure it is user-friendly - if your encryption system is a PITA to use, staff may well start emailing files home instead, and then you'll fail GDPR-compliance for a different reason.

Posted

I have thought about this today and thanks to everyone for their replies etc.

 

USB - I am going to use Netsupport DNA to register and allocate USBs to nominated staff (encrypted). Students and remaing staff will use their Google Drive.

HOME ACCESS - Disable USB RDP redirection to prevent data leaving the school domain

WIRELESS - ACLs for DNS, RDP and Apple Bonjour (DHCP from the Wireless Controller)

 

Thanks

Posted

..... and the only staff who carry them are Powerpoint-lovers who haven't adopted Drive ....

 

File Stream will fix that !

Posted
File Stream will fix that !

 

Not sure it will - we use shared folders (created pre-Team Drives) which are then added to each person's Drive - end result, each person's Drive is around 15GB.

Posted
Not sure it will - we use shared folders (created pre-Team Drives) which are then added to each person's Drive - end result, each person's Drive is around 15GB.

 

It doesn't download all the files like a sync - it streams them and they only download them when they need the files.

Posted
It doesn't download all the files like a sync - it streams them and they only download them when they need the files.

 

Does it then delete them at logoff? We already have problems with the size of people's Downloads folders, I don't want another semi-hidden folder getting clogged up too.

Posted
As @mjk says though, offer a decent remote access and people will naturally stop using memory sticks. Our students don't carry them any more now we have Google Apps, and the only staff who carry them are Powerpoint-lovers who haven't adopted Drive (understandably) or Google Slides (also fairly understandable), and even then it is just their PPTs on the memory sticks, the sensitive files are kept in Google.

 

Whatever you decide, make sure it is user-friendly - if your encryption system is a PITA to use, staff may well start emailing files home instead, and then you'll fail GDPR-compliance for a different reason.

 

+1 for Google Drive on this one. I'm not going to encrypt USB drives until I've got our school implementation of Google Drive in use as an alternative to USB sticks.

Posted
This is the platform-independent memory stick we bought - https://istorage-uk.com/product/datashur-personal/ One person offered to buy it themselves since it was their choice to have a non-compatible computer at home, but I suspect you'd be on shaky (or at least unpopular) ground if you made that policy.

 

As @mjk says though, offer a decent remote access and people will naturally stop using memory sticks. Our students don't carry them any more now we have Google Apps, and the only staff who carry them are Powerpoint-lovers who haven't adopted Drive (understandably) or Google Slides (also fairly understandable), and even then it is just their PPTs on the memory sticks, the sensitive files are kept in Google.

 

Whatever you decide, make sure it is user-friendly - if your encryption system is a PITA to use, staff may well start emailing files home instead, and then you'll fail GDPR-compliance for a different reason.

This is where Ems will come in and files will not be able to be emailed to external addresses.
Posted
Does it then delete them at logoff? We already have problems with the size of people's Downloads folders, I don't want another semi-hidden folder getting clogged up too.

 

The profile will grow - but only if files are non-google ones like powerpoint. If you used roaming profiles you would store them on your server and make it more simple for machine roaming (you'll probably have space if you move your home/mapped drives there) and make it easier to purge using scripts if you needed to.

Posted
Win 10 1709 has a feature to clear the downloads folder. You could always delprof2 old profiles. I'd stay clear of roaming profiles as they are depreciated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...