Jump to content

Recommended Posts

Posted
Earlier this week, we told staff they'd only be able to use encrypted memory sticks - cue obvious backlash about cost, especially for the massive drives from people who carry copies of their entire lives on USB. So, I'm wondering about the viability of a policy which says "encrypt this, but don't worry about the other". I've seen a definition for "special category" data, but that didn't feel complete for a school context, as it didn't include assessment data for example which I'm sure is something we should encrypt. So, does anyone have any pointers as to what data must be kept securely and what doesn't, or do you think we should just stick to our guns and enforce encrypted only?
Posted
I found that the only way I was ever going to get traction with the same policy (introduced last May) was to provide the sticks myself, or offer to encrypt their devices for them. I offered 8GB sticks for free to staff - any more capacity than that and I charged the departments the extra. Went well overall. We stuck to our guns - no unencrypted storage (by policy rather than enforcement).
Posted

Any data that can identify a living human being should have adequate technical measures to ensure it is secure. Once that data is leaving site it is expected that it should be secured - encrypting is a good way to ensure it is, at least in transit.

 

A powerpoint of the lesson probably doesn't include any info of a living individual (you shouldn't need to worry about people in the public eye) so that wouldn't necessarily need encrypting. However once you allow some info to leave site unencrypted it is easier to make a mistake with data that should be protected.

 

Technical measures only work along side robust policies and procedures that are adhered to and regularly audited.

Posted

Not sure if this is helpful, but we decided that there would always be confusion if it is left down to staff to make a judgement call about what is and what isn't worthy of encryption, so we decided that anything whatsoever that is related to school must be encrypted. This is enforced by SLT.

 

Meldrew

Posted

Could you use BitLocker so the staff don't need to worry about buying an encrypted memory stick

 

(see this link for details on how to do it ...

http://www.edugeek.net/forums/data-protection-information-handling/192353-gdpr-compliant-i-think-not.html )

 

In terms of what data to encrypt and what not to encrypt on a memory stick, I think its a bit of a recipe for disaster (unless I've misunderstood what you mean!). It would put the burden on staff to determine what is personal data and what is not, then the burden of encrypting that specific data, then you'd always get someone who didn't encrypt it or would say they didn't know it was personal data.

 

I'd say the starting point should be enforce encryption for pen drives, unless there is a valid reason not to. If there is a valid reason not to, then risk asses that and see if you can off an alternative solution.

Posted
We enabled bitlocker on all School computers. Staff can still bring in their own USB sticks but these are read-only in School. We provide 8GB sticks for staff if they need otherwise we will encrypt their drives but we recommend they use ours and we take no responsibility if their drive stops working for any reason and they blame the encryption.
Posted (edited)

We are encrypting all school staff laptops - regardless if they assure us that they won't save personal data. For USBs we will do the same or disable all portable storage usage. They have access to their secure areas and have a backup option of the cloud.

 

It's a discussion that needs to be with the Data Protection Officer and/or leadership.

 

We are using our judgment and experience with staff to simply say - we can't trust them tomorrow to not save personal data on an insecure device. This protects them, the school and personal data.

 

Be safe, not sorry.

 

We recently implemented an auto lock after 15 minutes of inactivity for all users. Some grumbles but it's time for people to wake up to data protection. GDPR is coming because not enough take it serious. Too many have got a bit too accustomed to doing things their way. You have to take the hard approach.

 

This post might seem a bit blunt but after a huge amount of discussions with the DPO/LM/HT - we decided it's the way to protect the school 'cover our backs' which is what the best approach for us is.

Edited by Lonix
Posted
In terms of what data to encrypt and what not to encrypt on a memory stick, I think it's a bit of a recipe for disaster (unless I've misunderstood what you mean!). It would put the burden on staff to determine what is personal data and what is not, then the burden of encrypting that specific data, then you'd always get someone who didn't encrypt it or would say they didn't know it was personal data.

Knowing what teachers are like I agree 100%. The only foolproof method is to encrypt every single storage device they are able to save data to.

Posted

Stick to your guns. If you decide to allow USBs, enforce encryption on them as a blanket measure.

 

Side note; those massive drives they're carrying round that belong to them - I feel like that's probably something that needs nipping in the bud also. Obviously you can encrypt it, but it's theirs so they keep it when they leave. When they stop working for you they'll still have access to all the data that's stored on there.

 

So our policy is going to be; USBs will be read only for the vast majority of staff, so they can happily use their personal drive to create lesson plans at home and bring them in. If they really need to store personal data on one, we'll supply an encrypted one so that a) it's safe and b) when they leave, we get it back.

Posted

We're on the verge of enforcing BitLocker for staff so as soon as they plug a USB in they either have to encrypt or it opens read-only.

 

Plus points: doesn't require purchase of new USB sticks, allows IT to recover forgotten passwords

Minus points: doesn't solve issue of data already out there, takes a long time on large capacity devices (Windows 7), have managed to break a couple of low-quality sticks that couldn't handle writing to every part of the storage

 

In an ideal world either blocking USB storage completely or standardising on a single model would work better but budget and avoiding a riot come into play (!)

 

Also planning to recall all laptops to redeploy with Windows 10 \ Bitlocker \ Azure AD join but again a lot of those may need replacing as they either need a TPM onboard or the USB "cranking handle" to hold the encryption key (far from ideal as it usually ends up stored with the laptop)

Posted
Side note; those massive drives they're carrying round that belong to them - I feel like that's probably something that needs nipping in the bud also. Obviously you can encrypt it, but it's theirs so they keep it when they leave. When they stop working for you they'll still have access to all the data that's stored on there.

 

True. Same goes for their home computers too and personal mobiles. We will have policy saying not to save things there, but can neither enforce or police this.

Posted

Thanks everyone. You've reassured me about standing our ground in the face of opposition.

 

I like the sound of Bitlocker - I had thought that was encryption in itself, not a means of saying "encrypted or read-only, you decide". How would it handle the kind of memory stick where you press buttons or use biometrics to "unlock" it before connecting? People with Mac or Chromebook, that is their only option - would Bitlocker see those as being unencrypted and force them read-only?

Posted (edited)

Bitlocker is the encryption thingy, but there's a group policy you can set that says "If it's not bitlockered, make it read-only". Not sure how that policy treats the hardware encryption things though.The actual setting as quoted in help articles as " Deny write access to removable drive not protected by Bitlocker"...which sorta hints that they're useless. Also shuts out competing encryption software like luks or veracrypt, which is kinda annoying for cross-compatibility.

 

https://blogs.technet.microsoft.com/askcore/2010/02/16/cannot-save-recovery-information-for-bitlocker-in-windows-7/

 

Boo microsoft, you suck.

 

Edited by djrscally
Posted

The problem is, from what I can see, we have to implement something for the staff to use, you can't rely on the staff members professionalism to ensure you have no data breeches. If you have one member of staff that doesn't encrypt the files they were supposed to encrypt and you get a laptop/train/car boot theft incident then when the ICO asks "how did this happen" your answer of "the teacher should have encrypted it but didn't" is not good enough, your school has still had the data breech and no suitable measures were in place to ensure encryption.

 

So it has to be, ban non encrypted drives, surely?

Posted
Thanks everyone. You've reassured me about standing our ground in the face of opposition.

 

I like the sound of Bitlocker - I had thought that was encryption in itself, not a means of saying "encrypted or read-only, you decide". How would it handle the kind of memory stick where you press buttons or use biometrics to "unlock" it before connecting? People with Mac or Chromebook, that is their only option - would Bitlocker see those as being unencrypted and force them read-only?

 

As others have said - only bitlocker is recognised. It doesnt work on Chromebooks or Mac , although you can get some 3rd party software that will unlock bitlocker drives on Macs but it does cost. we purchased 2 licences for the School for our only 2 official Mac users.

https://www.m3datarecovery.com/mac-bitlocker/

Posted
Why are so many people using USB drives? They're not reliable for a start. Anyone who's doing work outside of the building should be using a school laptop, otherwise how do you know it's not infected? random computer x uploads screenshots every 5 seconds to imgur, that's a 10 line program.
Posted
As others have said - only bitlocker is recognised. It doesnt work on Chromebooks or Mac , although you can get some 3rd party software that will unlock bitlocker drives on Macs but it does cost. we purchased 2 licences for the School for our only 2 official Mac users.

 

Probably what I'll do too. The licence will go nicely alongside the one we've had to buy them because Macbooks only run the latest Smart Notebook, not the free 11.4

  • 2 weeks later...
Posted (edited)
Why are so many people using USB drives? They're not reliable for a start. Anyone who's doing work outside of the building should be using a school laptop, otherwise how do you know it's not infected? random computer x uploads screenshots every 5 seconds to imgur, that's a 10 line program.

 

Yeah, alright then, good luck with that one.

 

A) Laptops cost more

B) Laptops can also be infected with viruses

C) Teachers like to feel self-sufficient, and the majority of them feel 'It works, why change it?'

D) It doesn't require an internet connection

 

You're not wrong. I support what you've said in principle. But it just isn't feasible. Every teacher does some degree of their work from home. Maybe that's just marking, maybe it's lesson planning, maybe it's everything they do in school. They need some degree of getting that working at home, and things like remote access aren't always viable depending on your setup and what tech they have at home.

 

Boolean statement: Are you blocking any and all external storage media? If no, your teachers are using USB sticks already. Far better to adapt the current method to suit data protection laws than to try and push such a huge change.

Edited by Garacesh
  • Thanks 1
Posted
Yeah, alright then, good luck with that one.

 

A) Laptops cost more

B) Laptops can also be infected with viruses

C) Teachers like to feel self-sufficient, and the majority of them feel 'It works, why change it?'

D) It doesn't require an internet connection

 

You're not wrong. I support what you've said in principle. But it just isn't feasible. Every teacher does some degree of their work from home. Maybe that's just marking, maybe it's lesson planning, maybe it's everything they do in school. They need some degree of getting that working at home, and things like remote access aren't always viable depending on your setup and what tech they have at home.

 

Boolean statement: Are you blocking any and all external storage media? If no, your teachers are using USB sticks already. Far better to adapt the current method to suit data protection laws than to try and push such a huge change.

 

a) but not that much in the context of an entire school budget, if they need to find the money they will. £50k for a teacher per year, 0.5k for a laptop for 5 years is nothing.

b) but less likely than because you are the only person with admin rights, and you blocked all exes etc from running that you didn't install.

c) yeah, people hate change

d) neither does a laptop

 

I'm forcing all external media to be encrypted. So far Person 1 who used it to switch between desktop and laptop has just switched to laptop. Person 2's external hdd died anyway. Person 3 I encrypted the usb for them. Person 4 never knew such a thing as a network home drive existed, so is using that now. Either all the rest are competent, or there's no one else who's tried so far.

Posted
a) but not that much in the context of an entire school budget, if they need to find the money they will. £50k for a teacher per year, 0.5k for a laptop for 5 years is nothing.

You're assuming laptops are purchased as teachers are recruited. This is often not the case. A lot of places people won't do either mass-staff-laptops or forced-encryption and are now looking at their options. Suddenly buying ≈75-150 laptops looks pretty damn expensive.

 

b) but less likely than because you are the only person with admin rights, and you blocked all exes etc from running that you didn't install.

Well, yeah, but reasonably speaking, there's things like drive-by-exploits that can still infect machines. To be clear, I'm not insinuating a memory stick is any better, an encrypted memory stick can still get infected if it's attached to an infected machine, I'm just trying to point out it's neither here-nor-there, really.

 

d) neither does a laptop

It does if you need to access work held elsewhere.

Giving a laptop to a member of staff is 100% useless if it has no way to get the work they've done in school, no? The member of staff takes the laptop home, switches it on and... nothing. They still need either internet (to access cloud storage or to use remote access) or a memory stick/external hard drive to move files between the machines.

 

Don't get me wrong, your approach works, but going with the encrypted USB stick method is likely more familiar to a user, has better redundancy (a laptop can be lost/stolen/misplaced whilst it's switched on and thus unecrypted), and costs considerably less to replace in the event of any issues.

Posted

Hmm, they just sync their home drives with offline files here, seems to work.

 

A laptop I control is only 99.9% less likely to have a virus than a random laptop, true.

 

You can't steal it when it's on, because everyone locks the computer before leaving it, right? right? anyone there? Also you'd have to keep it open, which would be pretty funny

 

63582990-female-worker-running-on-track-while-holding-a-laptop-computer-shot-outdoors.jpg?ver=6

  • Thanks 1
Posted
Hmm, they just sync their home drives with offline files here, seems to work.

It works for the two instances we have it here for, too. We just tell them to log in when they get on-site to sync up and do the same before they leave to pull down any files made that day. But I reckon if we did that en-masse here there'd be way too much confusion around file conflicts because staff would only bring in their laptop once every six weeks. And as @enjay pointed out shared folders are an issue. We have a large shared staff repository that holds lots of things like progress reports, lesson plans, etc, there's no way we could sync that lot, and if we did there'd be file conflicts daily.

 

A laptop I control is only 99.9% less likely to have a virus than a random laptop, true.

Yeah I'm with you on that one. A laptop we provide is considerably less likely to be infected than a standard 'home laptop' where the user has admin and whatnot.

 

You can't steal it when it's on, because everyone locks the computer before leaving it, right? right? anyone there? Also you'd have to keep it open, which would be pretty funny

Lmao, if only :rolleyes: Our staff leave their workstations unlocked when they leave the room, with SIMS and emails open.. They can be.. irresponsible1.. regarding data security.

Admittedly I reckon if a thief was going to hoof off with a laptop they'd probably shut it to make it easier to keep hold of as they ran off, so it's a valid point.

 

1: If I'm being diplomatic.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...