pbad Posted March 19, 2018 Posted March 19, 2018 I know that GDPR is a minefield, but can anyone simplify what my role as an IT Tech is relating to GDPR? Do I just have to make sure staff are:- Using Encrypted USB Flash Drives Using Encrypted School laptops Computers are automatically locked after timeout Stronger password polices?
Fazza Posted March 19, 2018 Posted March 19, 2018 The answer is that it all depends on what your Schools policies say. For example, some schools say no USB Flash Drives at all, some say they all must be encrypted and others may say they can use them but not for any identifiable data.
strawberry Posted March 19, 2018 Posted March 19, 2018 You have to do what you are asked to do by the leaders of your school Don't confuse matters by doing things unless you've been asked too. There should be a whole school policy in place and you should be consulted as to how you are to implement the policy within the larger picture.
rom1984 Posted March 19, 2018 Posted March 19, 2018 (edited) The ICT Tech would be part of the team that is responsible for "implementing appropriate technical measures to ensure a level of security appropriate to the risk". The specefic areas that are mentioned are; * Encryption of personal data * The ongoing confidentialty, integrity, availability and resilience of processing systems and services * The ability to restore the availaiblty of personal data in a timely manner * A process for regularly testing the effectiveness of technical measures (i.e disaster recovery testing, penetration testing) I wouldn't expect an ICT Tech to be responsible for the implementation of them though, but they would probably be involved with them as part of their day to day activities. Some of the things I can think of are Encryption of personal data - i.e responsible for encrypting laptops, pen drives, servers, desktops. Condifentailty - Implementation of password policies, creation of VLANs, adding devices into VLANs, social engineering awareness training, checking levels of access for MIS system, Integrity - Monitoring event logs, checking file permissions, ensuring the correct people are in AD security groups, Availiabilty - hardware repairs, checking life cycle of servers (I.e making network manager aware of servers coming to oow), redundancy checks (ie RAID health, redundant PSU working etc), Windows updates, anti-virus management, Ability to restore - backup checks, recovery checks and disaster recovery testing You'd expect all these things to be driven from policies and procedures further up though from the Network Manager, Data Protection Officer, SLT etc Edited March 19, 2018 by rom1984
pbad Posted March 19, 2018 Author Posted March 19, 2018 So far I have only been asked by SLT to give each Teacher an Encrypted USB Flash Drive to save any school data on them e.g. reports, lesson plans, Assessments etc.. Each Teacher has signed for the USB Flash Drive and I have made it clear that I will not be able to recover the data if the Teacher forgets the password to the USB flash drive. Some Teachers have a Teacher laptop provided to them by the School and these laptops don’t have any encryption on them. The laptops do have Sophos antivirus installed on them and are password protected by the Teacher. For sensitive data the school has been asked to use egress switch to send data to Birmingham City Council, which is mainly used by SLT. @Liam The School doesn’t have a DPO yet, so I’m trying to cover my back in case something happens and the blame finger is pointed at me.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now