Jump to content

Recommended Posts

Posted

Morning all

As I have been reading about the GDPR it got me thinking about HTTPS Inspection

 

With HTTPS Inspection smoothwall has an disclaimer when you set the warning to never, about "local law blah blah must inform users blah " however as I have experienced if you let smoothwall inform users it doesn't half cause some problems therefore I usually send out an email every now and again but concerned now that these more stringent rules may mean that I am not doing it frequent enough and I want to fill my part of the survey out with confidence that it will not raise any questions. (we all like the quiet life :))

 

How often does everyone inform their users that they inspect and decrypt secure traffic on their network? I usually do it once a year (or when I remember to do so) however with the turnover of staff increasing with part timers and supply I feel maybe more frequent message need to be sent.

 

Also anyone got a more professional message I can steal of them. because I do it so infrequently I only quickly right one up which may not sound the best. I would appreciate if anyone could share their messages

 

Thanks

Posted
Absolutely no need for that. It should be in your IT usage policy for all users.

 

oh yes forgot to mention. we do include it in our AUP however because no one ever reads it (not IT problem I know) I send it every now and again just to make sure we are covered from that perspective. at least then any infringement staff and students have no leg to stand on for not reading my email and the small print of the AUP

Posted
We put ours in our AUP, BYOD Policies and also on our MITM page for users to see plus it also helps when it comes to visitors who need to use the wifi so they can install the smooth wall certificate.
Posted
GDPR doesn't mean you are forced to hold people's hands; you have more important things to worry about than that. If it's in policy then you're covered, it's not your problem if people do not read it as long as they are directed to do so; it isn't your job to make them read those policies. For guest policies, byod/wifi etc then a crib sheet would indeed be handy but it doesn't need to be in depth. "Connect to our systems by.... please note that all traffic is filtered and monitored in line with Keeping Kids safe in Education yadda yadda"
  • Thanks 1
Posted
GDPR doesn't mean you are forced to hold people's hands; you have more important things to worry about than that. If it's in policy then you're covered, it's not your problem if people do not read it as long as they are directed to do so; it isn't your job to make them read those policies. For guest policies, byod/wifi etc then a crib sheet would indeed be handy but it doesn't need to be in depth. "Connect to our systems by.... please note that all traffic is filtered and monitored in line with Keeping Kids safe in Education yadda yadda"

 

I get your point and completely agree, it isn't my problem if they cant do as they are directed to. but these are teachers and some really do need their hand holding from the point they leave their front door to the point they return home in the evening.

 

It is mentioned in the AUP that users are not to download from youtube or any other copyrighted material and distribute it across the network but they do and they get away with it commenting that the network shouldn't facilitate them to break the law resulting in a managerial instruction to put better measures in place.

 

I tend to choose my battles and cant see what measures we can improve on other than blocking all audio media file types from being saved.

anyway I am digressing from the actually question.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...