Jump to content

Recommended Posts

Posted

Hi all,

 

We have decided to go with bit locker for USB encryption from Friday or at least I thought we had. SLT have some concerns.

 

I have set it up to require complex passwords, 8 in length and to prevent write access unless it has been protected by bit locker. The issue comes from the fact that a removable drive not protected can still have its contents read so for devices that already hold data are at risk.

 

I have suggested that unless those sticks are already lost then the assumption is they are already in the posession of the rightful owner who has the permission to view the contents anyway who will have been trained to encrypt without delay, the responsibility is with them. The school are keen to think for the end users it would seem and do not want the user to have read access either until it has been encrypted. I have explained that this isn't an option as you can't really stop someone from accessing their own files on their own memory stick. They suggested buying new memory sticks for staff but I said the issue would remain as unless you are going to only whitelist those sticks any others could still be plugged in.

 

My own view is that they should ban USB, we have plenty of remote access and that is the only way we can be sure. Just wondered how the rest of us have dealt with this?

Posted
We're about to block USB drives as a mitigating move; some areas (photography, media) will still be allowed limited access due to transferring data from cameras etc. Same reasons, plenty of other methods of securely getting at data.
Posted

Personally feel it's kind of a silly point to raise by them, if the data is on those USBs already and the concern is it not being encrypted whether you can plug it into your computers or not is irrelevant as it can still be stolen/accessed.

 

As you said you enforce any new ones, and old ones it's down to them to secure or wipe.

 

Steve

Posted
Personally feel it's kind of a silly point to raise by them, if the data is on those USBs already and the concern is it not being encrypted whether you can plug it into your computers or not is irrelevant as it can still be stolen/accessed.

 

As you said you enforce any new ones, and old ones it's down to them to secure or wipe.

 

Steve

 

Exactly, I feel the school are trying to make changes that will not put the responsibility on the teachers to take necessary steps to protect the data that they handle. Truth is we all have that responsibility and need to be put right if/when we screw up.

Posted
We use a piece of software called Deslock Pro to Hard Drive encrypt all laptops and file encrypt all USB sticks, we then also setup group within impero to allow specific users to access USB's
  • Thanks 1
Posted
I have had the same discussion. We have reach to an agreement eventually. We have bought memory sticks and encrypt them using BitLocker. These memory sticks will be used for a period of time (ending next 11th June), so staff has had the time to swap files from their own sticks to the school's sticks. After 11th June we are banning the use of any usb removal storage except the school's. I am using Device Control Policy in Sophos Enterprise Console. Our next move is banning these memory sticks and move to OnDrive / SharePoint. Some users are already using this services.
Posted
We were thinking of going down the route of making USB read only using NetsupportDNA. Users can still use their own drives to transfer data from it to the network but will be unable to transfer data from the network to a USB device. This then does not stop photography etc from getting images from their camera.
Posted

We've forced BitLocker on USB sticks using MBAM for a few years now - ahead of GDPR (totally using it as an excuse) I've denied all write access to any removable storage on end user devices now. Staff have OneDrive and their own school laptops - there's no reason for them to be using USB sticks anymore. This has killed the issue of staff doing work on non-school computers too.

 

Of course you can still read from them OK for things like cameras.

Posted
The school are keen to think for the end users it would seem and do not want the user to have read access either until it has been encrypted. I have explained that this isn't an option as you can't really stop someone from accessing their own files on their own memory stick

Sure you can. It's a school computer so you can stop them doing anything that might compromise the security of the network/data (or am I misunderstanding your point.)

 

We're planning to use Sophos to block USB storage devices. We'll then be providing (probably) hardware encrypted sticks for staff who "really, really need them". Only the school bought, encrypted memory sticks (and school card readers) will work on any school computer. If the staff need the data from their memory sticks then we've got plenty of routs for them to get to it.

Posted (edited)

We are issuing new drives that are pre encrypted with the recovery keys held securely.

 

Already issued drives will have the data migrated to a wiped and encrypted drive.

 

USB drives will be restricted in use to specific computers and users. So an authorized user cannot access a usb drive on a PC in a computer suite for example. This is to prevent the USB stick being lost because the user leaves it in a pc that is in an insecure location.

 

Also we are deciding on if to enforce a white list of authorized removable drives and or not allowing any data tto be written to unencrypted drives.

Edited by ICT_GUY
Posted
We use cloud storage (Box) for all data and on all devices we disable the USB in BIOS to prevent their use. All Laptops and PCs are bitlockered through MBAM. I do remember having the discussion in a number of primaries where I mentioned blocking USB drives and it took a few years of negotiation. One good thing about GDPR is its raised the awareness and SLT are now even more aware of the responsibilities they have!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...