Jump to content

Recommended Posts

Posted
I once took a screenshot of the users desktop with all of its icons and then set it as their desktop background and removed the icons. It took them quite a while to realise what had been done. They always lock their computers now.....
Posted
One person at my last place used to love jumping on to unlocked machines and emailing messages declaring undying love, resignation, and announcing a coming out party, to name a few.
Posted
We use single sign on. I just open mail and send email to our data protection officer and relevant head of department of the breach with a screenshot using their own account.Problem sorted and or back covered. Not my problem from thereon.
Posted
Most people don't bother to lock their machines because it is too much effort if they are only going to be out of the room for a couple of minutes.

 

With that mindset in mind, is there such a product, or appetite for such a product that when a laptop is unlocked and the cause of the lock was due to the time-out, the machine doesn't let the user do anything for 10 seconds (or a configurable length of time). If the cause of the laptop locking was Windows+L, then once it is unlocked they can start working again straight away as normal. The idea being to make leaving the laptop unlocked more of an annoyance than locking it is. There are obvious edge cases where the machine will lock while you are in front of it speaking on the phone or similar but you could counter that by not applying the 10 second delay if the machine is unlocked less than 10 seconds after the time out locked it. The 10 seconds delay could be used to display GDPR facts (largest fine etc.)

If it's recorded in registry or wmi it might be possible to powershell. Again it's doing lots of things to get around people not doing what they are told.
Posted

Hi

 

We maintain an Data Breaches Incident Log

 

 

Date: Student or staff Incident Action Taken re this incident Actions to prevent reoccurrence Legal implications date Closed

 

 

All incidents such as leaving a pc unattended and logged on are recorded and the entire log is reviewed by the LT every term and the Governors annually

 

As they say "what gets assessed gets done"

Posted

One of my users said sometimes in an emergency situation (first aid call for example) they didn't have enough time to lock their computer. I asked if that emergency came in whilst you were on the phone would you not replace the handset as it takes about the same time?

 

Had a cartoon image in my mind of a puff of smoke, a pair of legs running away and a handset falling to the floor.

Posted
the only solution is to make an example of someone, they arent going to take it seriously until shown the management are serious about enforcing it
Posted

I am amused by the "acts of shame" approach, but I would advise caution about approaching this purely from a technical viewpoint. Appropriate times on screen savers are good, of course, but remember teachers have lots of data on paper too so it is important to work on the data security mindset to make sure they handle everything appropriately.

 

My team and SLT don't actively look for unlocked computers or visible data on desks, but we do a quick check if we happen to be at someone's desk for another reason, e.g. support call or SLT learning walk. Reminders are put in the staff bulletin - from HT not me - saying to protect sensitive information and use Win+L.

 

A useful tip I heard somewhere was to stop talking about "data protection" but instead "information protection" or "information privacy", because people link the word "data" with computers.

 

If you still want a technical solution beyond timed screen savers, you could look at Bluetooth key fobs which lock the PC when they leave range, could be annoying for the teacher who walks to the back of the classroom though.

  • Thanks 1
Posted
I've found they will only start to take it seriously when something actually happens to those doing it (e.g. disciplinary action) rather than just being written in a policy that doesn't in reality get enforced.

 

We had a request for a website to be allowed thru filtering at a previous place, I don't normally check these out as they only come from staff members and this was requested by a staff member.

 

Something about the name of the website drove me to check it and found out it was a proxy avoidance site. Questions were asked and it turned out that the staff member had let students use his computer/account. So there he was paying no attention to what the students were up to, obviously.

Posted
We had a request for a website to be allowed thru filtering at a previous place, I don't normally check these out as they only come from staff members and this was requested by a staff member.

 

Something about the name of the website drove me to check it and found out it was a proxy avoidance site. Questions were asked and it turned out that the staff member had let students use his computer/account. So there he was paying no attention to what the students were up to, obviously.

 

Our filtering system has a free-text box for requester's name, it doesn't pick it up from the client, so one of our students entered a teacher's name in that box when they sent in a request for a blocked site! I first twigged there might be something up because it was a request for a site which is already available to staff but blocked to students.

  • Thanks 1
Posted
Hi folks,

 

Having trained staff on this for several years, I'm at my wits end in trying to get them to take it seriously, having discovered the umpteenth unlocked laptop in a classroom, hardcopy sensitive data not locked away only days after repeated guidance etc.

 

What do other DPOs do to try and get staff to follow guidance and take it seriously?

 

Our approach so far:

 

- staff training, including refresher training (annually going forward)

- clear guidance including reference to it being a legal requirement, school policies, and inclusion in the staff code of conduct

- repeated guidance between training sessions

- penalties, including mandatory retraining for staff that are caught with unlocked laptops etc.

 

Interested to hear your thoughts and suggestions...

 

Scare them.

 

-Take the laptop so they have to effectively report it as stolen

-Any insecure area with sensitive data is a risk and should be assessed reported - do your duty and pass it on the HT/Governors. Inform staff that this is the process and that it could also go to the ICO which may end up including those responsible for the risks. We informed staff that the individual and company can be named/fined.

 

If they have received the training and still refuse to listen. As the DPO you should know the procedure especially under GDPR, follow it.

 

Our HT did a presentation to scare them. And it worked.

 

We are not expecting perfection because it's a mentality change but we do want progress. If the same member of staff constantly leaves sensitive data laying around, unlocked area..... scare tactics work. I think at the end of the day you need leadership all on the same page.

Posted
We had a request for a website to be allowed thru filtering at a previous place, I don't normally check these out as they only come from staff members and this was requested by a staff member.

 

Something about the name of the website drove me to check it and found out it was a proxy avoidance site. Questions were asked and it turned out that the staff member had let students use his computer/account. So there he was paying no attention to what the students were up to, obviously.

 

https://inthenews.co.uk/allegations-mount-for-disgraced-it-teacher-geneva-fox/

 

This is pinned everywhere I go.

  • Thanks 1
  • 2 weeks later...
Posted

Get SLT on side for a start, keep a log, 3 strikes and they have to re-do the training (obviously you would probably have to do the training). I'm sure once people have had to sit and do a refresher training course for 30 minutes a couple of times, they will just start doing things properly. Pass the log on to SLT once a term, or every other week if the log is large.

 

If SLT aren't on side, then you probably can't force people to do the training and telling SLT won't do anything either. Make them aware of the potential consequences (however unlikely). Had to sit in a few courses about GDPR in the last year (one of which was 8 hours long) and still heard a lot of head teachers basically say something along the lines of "Well we can just say we did a risk assessment and decided the risk was very low".

Posted
Or wait until a school/college gets fined heavily. Then maybe it'll be taken seriously. A bit like keeping up to date with patching before and after wannacry.
Posted
My preference is to copy and adapt the school's pupil sanctions with an escalating scale or severity for data breaches. A structure many will be familiar with... link it to performance management. Do the same for taking registrations and any other legal/important policy. Of course, I'm not expecting it to be a popular approach :tinfoil3:
Posted

One of the things we're thinking of is linking data protection, which is taken lightly, to health and safety and child protection, which are both taken with appropriate seriousness, by combining the three into a single poster

 

I'm still struggling to write the blurbs for each section (if anyone has any suggestions for how to present the text in the three sections I'm all ears), but this is the general layout to give you an idea of what I mean:

 

poster.jpg

  • Thanks 1
Posted
One of the things we're thinking of is linking data protection, which is taken lightly, to health and safety and child protection, which are both taken with appropriate seriousness, by combining the three into a single poster

 

We're taking a similar approach, reminding people they're already familiar with data confidentiality and the (in)appropriateness of sharing, so start applying the same principles to more information than previously.

 

As for your poster, maybe start with all the Ws - what am I sharing? who am I sharing it with? why am I sharing it? Think before you share. Then the obvious (to us!) holes in data protection, e.g. unencrypted memory sticks, unlocked PCs, paperwork on desks/walls.

 

I've also heard it suggested to stop saying "data protection" because people have got used to that phrase so don't realise this is something new, and also because "data" is often synonymous with computers. The trainer instead suggested talking about "information privacy".

Posted
Yep that's why I switched it to "Identity" in the poster - everyone has heard of identity theft but I'm not too sure how many link proper data protection at work to preventing identity theft as basically the same issue and the same principles to apply.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...