Jump to content

Recommended Posts

Posted

If a school was to edit one of their policies to state, "only school provided encrypted memory sticks are to be used."

Would this be sufficient in the eyes of GDPR?

 

I think I know the answer, but just wanted to hear everyone else's views on this!

Posted

I guess that depends in what scenario you're trying to use that context.

 

Just modifying a policy without getting anyone to read it, sign up, etc etc won't be a catch all to sort any data loss out.

 

If you're talking all new users/staff etc are signing this and you're re-issuing the policy to all current people then probably would be fine, as you're still dealing with the issue and have a clear policy in place.

 

It's no different to a policy that says don't email personal info externally, and then someone does. There's always limits as to what you can physically do to stop an issue without going overboard.

 

But in reality, if you're going to put that in a policy why wouldn't you just enable it via bitlocker/gpo too?

 

Steve

  • Thanks 1
Posted

I'm with @Steve21 's view. Your policies should help dictate the overall culture of your school.

 

So if you say no pen drives in your policy but then do nothing else to support this, I'd say its pretty much worthless as the policy isn't do anything to dictate how your school is being managed.

 

If you say no pen drives in your policy, then do regular data protection awareness training, provide encrypted pen drives/enable bit locker, put technical measures in place to prevent unencrypted pen drives etc then you can show your policy has supported the overall culture of how the school is managed.

  • Thanks 1
Posted

Thanks for your comments @Steve21 and @Edutech98

 

I was thinking along the same lines, we will be getting all staff to sign any amended polices and providing training etc.

The problem is, we are currently using windows 7 professional on our Domain, so no Bit locker available. (Please correct me if I am wrong as the articles I have been reading state that this is not available on Windows 7 Professional.) :rolleyes:

 

I'm currently of the thought that the only way to comply with GDPR would be to disable USB use completely, until we are in a better position to be able to use Bit Locker for example.

 

Or due to our current position, is a policy and providing encrypted pen drives enough to make us GDPR compliant for this scenario?

 

I'm deliberately leaving out my thoughts on this to see what others would do in this situation. :confused:

Posted

I have been trying my best to stop teacher (and students) using pen sticks for some time. Much better just to use cloud space....not least of all - because it can be deleted should a password be compromised - or the teacher leave....

 

Why use pen sticks?

  • Thanks 1
Posted

Agreed @AlanD

 

This is something I am also pushing for, using one drive for example is a no-brainer especially when you can set up a member of staffs laptop (encrypted of course) to synchronize with OneDrive. :juggle:

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...