Jump to content

Recommended Posts

Posted

If a document is shared to an external account outside the school domain, or more specifically if ownership is given to that account, did you realise you use lose control of that document. Who's space do you think such a file is now taking? If the external account is just a standalone google account, do you think it is their space and therefore limited? If the external user is for example another school domain (not yours) does it switch to theirs domain?

How do you protect against such eventualities?

Posted
I suggest you take a look at your Google Drive policies in the admin console. There you can prevent users from sharing outside of the domain and control who (if anyone) can move content outside of the domain. You will shortly be able to define rules which will apply even if they have permission to do this that will scan the content of the files. So set policies that meet your needs - these can be doen at the OU level. We don't allow students to share outside of the domain at all for example.
  • Thanks 1
Posted
We don't allow pupils to share externally. Staff we do, but they haven't always followed acceptable usage policy. What has been a bit surprising is where ownership was transferred to external, we completely lose control of a document that was within our control and created within our domain - it's even beyond the reach of super admin. As a defense we are looking at a whitelist for staff accounts, but that creates a bit of an admin overhead. That actual scenario we think we have stumbled in to is this. Staff member shares a document (or even a folder) to a private email address, then shares it to a new domain at their new school - we are assuming the new school is a Gsuite school too. Not only sharing, but taking ownership along the way. Because of the share permissions on the original folder, including to some of our staff, when said member of staff at his new school creates new documents in this folder, we get access where clearly we shouldn't. Whilst after a lengthy investigation we think we understand what's happened, it seems all too easy to accidental cause a data breach and nowhere along the way was a warning raised.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...