Jump to content

Recommended Posts

Posted

My bursar has passed me a list of things I need to do to comply,

 

one of them:

 

"Please note, that in order to comply with the law, there should be no one person in your organisation with full access to all files and even your network administrator should have restricted access. In fact, it is recommended that the network administrator’s normal user account and his/her account with administrator privileges should be separated and only used when appropriate. This makes auditing and control of administrator actions"

 

I can understand that you have two accounts, a normal day account and an admin account to do admin tasks this has been around for years. My main concern (or maybe misinterpretation) Is that no one person can have full access, does this mean that domain admin accounts can no longer be used, backup accounts?? I mean even if I removed access to a set of files for myself, I still have to manage the backups.... therefore in theory I still have access to these files?

Posted

That "requirement" can't really be complied with to be honest. If you have a domain admin account, you have full access, no ifs no buts. Sure, you can set permissions to not give administrator permissions to a folder, but its a click to get them back.

 

I would say the best solution we could come up with is to use 2 accounts - one unprivileged, which only has permissions to files they need, and an admin account which is used when extra permissions are needed. The simple fact will always remain - IT staff have an elevated level of trust placed in them. We can't do our jobs without it.

 

You could implement some form of logging when you use those administrator accounts to access data though - either through file audit logging in Windows, or manually (or both).

  • Thanks 1
Posted
The domain admin account will always have that access, even if you Deny permissions - it's straightforward to get them back! Just operate on a lowest privilege basis and you'll be fine - a regular account for day to day, and the domain admin account when necessary. You could even have an intermediate level account, but essentially you as 'Network Administrator' will always have full access because you have the logon details of that account. Not possible to comply.
  • Thanks 1
Posted

I agree. Just don’t use domain admin permissions by default. Use elevated permissions when necessary.

 

To turn this to the paper records... and this applies to those as well as electronic ones... no one person should have access to all of those either if you apply that rule literally. I am willing to bet that, particularly in smaller schools, this isn’t the case.

  • Thanks 1
Posted
Thanks for the replies so far! So for example we delegate changing password to our "normal" account is that ok? or is that an administrative job that should only be done with admin account?
Posted

I don't have access to all our files.

I can give myself access, but I don't have access by default. If I give access there is an audit log that cannot be overwritten by me, or any other administrator.

 

It seems entirely reasonable to do this and I think that those who say it cannot be complied with could have a look at some systems that do allow this.

  • Thanks 1
Posted
I don't have access to all our files.

I can give myself access, but I don't have access by default. If I give access there is an audit log that cannot be overwritten by me, or any other administrator.

 

It seems entirely reasonable to do this and I think that those who say it cannot be complied with could have a look at some systems that do allow this.

I think that's essentially the approach most people saying it can't be done are taking.

 

The only discrepancy is the definition of whether this means they do or don't have access.

Posted
My bursar has passed me a list of things I need to do to comply,

 

one of them:

 

"Please note, that in order to comply with the law, there should be no one person in your organisation with full access to all files and even your network administrator should have restricted access. In fact, it is recommended that the network administrator’s normal user account and his/her account with administrator privileges should be separated and only used when appropriate. This makes auditing and control of administrator actions"

 

I can understand that you have two accounts, a normal day account and an admin account to do admin tasks this has been around for years. My main concern (or maybe misinterpretation) Is that no one person can have full access, does this mean that domain admin accounts can no longer be used, backup accounts?? I mean even if I removed access to a set of files for myself, I still have to manage the backups.... therefore in theory I still have access to these files?

 

...to comply with WHICH law?

 

What if your organisation only employed one person!

Posted
I don't have access to all our files.

I can give myself access, but I don't have access by default. If I give access there is an audit log that cannot be overwritten by me, or any other administrator.

 

So are you saying you cant even disable the audit log if you really wanted to?

  • Thanks 1
Posted
So are you saying you cant even disable the audit log if you really wanted to?

 

No, i've not found a way to do it. I think only Google can delete things from the audit or disable it.

Posted
Your using Google, so do you have a non admin account for everyday work? then an admin account for admin functions and swap when needed?
Posted (edited)
Your using Google, so do you have a non admin account for everyday work? then an admin account for admin functions and swap when needed?

 

All our files are in Google (team) Drive, so SLT control the permissions of who has access. Like I say, I can override with some command line trickery it but can't stop the audit.

I just use the regular (super) admin account.

Edited by mjk
  • Thanks 1
Posted
All our files are in Google (team) Drive, so SLT control the permissions of who has access. Like I say, I can override with some command line trickery it but can't stop the audit.

I just use the regular (super) admin account.

 

Depending on your Google Drive Vault retention settings, you can also retrieve Mail, Groups and Drive from there. That is also audited.

Posted
It is down to the wording... with all the auditing in the world you still have access to them files, ok you are traceable but you still have access to the files. Same with team drive, in the admin panel you can give yourself full access to any drive as an admin. ("Please note, that in order to comply with the law, there should be no one person in your organisation with full access to all files and even your network administrator should have restricted access") So assuming audting is fine, the rest of the wording seems to me to say, for day to day work I should have a non google admin account. Only then logging into my admin account if I require to do an administrative task.
Posted

Oh my ... that is a very InfoSec comment that has been sent over to you ... I can almost bet you have been told that you have to encrypt everytrhing too?

 

In reality, the law says you need to do a DPIA. Based on that you may do a range of things to manage the risk. One of them would be to improve your User Access Control so that you only have access what you need, and should you have another account (a Domain Admin account) it is auditable so people can see when it was used, what was done with it, etc.

 

This is actually part of Cyber Essentials and more can be found here.

https://www.cyberessentials.ncsc.gov.uk/requirements-for-it-infrastructure.html

  • Thanks 3
Posted

My network login is a standard one for local rights but with administrative access to the shared folders. This means I can access the files I need, support people with their files but can't accidentally install anything or execute most viruses. If I had to log out every time I needed to access a student's MyDocs folder, I'd spend my whole day logging in and out.

 

My Google login does have admin privileges, but that's deliberate - admin accounts bypass SSO, so it means I can still access Google even if there is a local problem with our servers and/or SSO.

 

We don't currently use Team Drives (may never, to be honest) which does mean I don't have access to everything in Drive - that is as annoying as it is helpful, because staff assume I can access everything therefore keep asking me for help with documents I can't see!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...