Jump to content

Recommended Posts

Posted

I know that GDPR is a minefield, but can anyone simplify what my role as an IT Tech is relating to GDPR?

 

Do I just have to make sure staff are:-

 

  • Using Encrypted USB Flash Drives
  • Using Encrypted School laptops
  • Computers are automatically locked after timeout
  • Stronger password polices?

Posted
The answer is that it all depends on what your Schools policies say. For example, some schools say no USB Flash Drives at all, some say they all must be encrypted and others may say they can use them but not for any identifiable data.
Posted

You have to do what you are asked to do by the leaders of your school :)

 

Don't confuse matters by doing things unless you've been asked too. There should be a whole school policy in place and you should be consulted as to how you are to implement the policy within the larger picture.

Posted (edited)

The ICT Tech would be part of the team that is responsible for "implementing appropriate technical measures to ensure a level of security appropriate to the risk".

 

The specefic areas that are mentioned are;

 

* Encryption of personal data

* The ongoing confidentialty, integrity, availability and resilience of processing systems and services

* The ability to restore the availaiblty of personal data in a timely manner

* A process for regularly testing the effectiveness of technical measures (i.e disaster recovery testing, penetration testing)

 

I wouldn't expect an ICT Tech to be responsible for the implementation of them though, but they would probably be involved with them as part of their day to day activities. Some of the things I can think of are

 

 

Encryption of personal data - i.e responsible for encrypting laptops, pen drives, servers, desktops.

 

Condifentailty - Implementation of password policies, creation of VLANs, adding devices into VLANs, social engineering awareness training, checking levels of access for MIS system,

 

Integrity - Monitoring event logs, checking file permissions, ensuring the correct people are in AD security groups,

 

Availiabilty - hardware repairs, checking life cycle of servers (I.e making network manager aware of servers coming to oow), redundancy checks (ie RAID health, redundant PSU working etc), Windows updates, anti-virus management,

 

Ability to restore - backup checks, recovery checks and disaster recovery testing

 

You'd expect all these things to be driven from policies and procedures further up though from the Network Manager, Data Protection Officer, SLT etc

Edited by rom1984
Posted

So far I have only been asked by SLT to give each Teacher an Encrypted USB Flash Drive to save any school data on them e.g. reports, lesson plans, Assessments etc..

 

Each Teacher has signed for the USB Flash Drive and I have made it clear that I will not be able to recover the data if the Teacher forgets the password to the USB flash drive.

 

Some Teachers have a Teacher laptop provided to them by the School and these laptops don’t have any encryption on them. The laptops do have Sophos antivirus installed on them and are password protected by the Teacher.

 

For sensitive data the school has been asked to use egress switch to send data to Birmingham City Council, which is mainly used by SLT.

 

@Liam The School doesn’t have a DPO yet, so I’m trying to cover my back in case something happens and the blame finger is pointed at me.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...