Jump to content

Recommended Posts

Posted
blocked them this year for staff using Windows and we're just using OneDrive instead. No grumbles and teachers just get on with it but a bit of a pain for us for teacher interviews and visitors as we have to copy whats on their USBs to the network should not email it in advance. From September we're banning them for students too, that might be a bit bothersome.

 

How you configured one drive as their network drive ? Are you using third party software?

Posted
no we just use the onedrive app, azure AD logs them in automatically + there's a few GPO options which can be configured too. Only downside is the app has to be run manually the first time, can't seem to auto launch it but once done the shortcut to their onedrive folder is accessible from file explorer. No need for any 3rd party software. I won't use it for their network drive as I've no backup mechanism so have just told staff to use it like they would a usb.
Posted
Our art department have a 3 workstations and some macs that they can still use for SD cards. Beyond that anyone that needs access to a usb brings them to us. So far as we've only banned them for staff its been no issue. Come September once the ban is in place for students too it maybe a different story
  • Thanks 1
Guest Guest
Posted
For those blocking already, can I ask how you handle the transfer of files from phones/cameras/video cameras as required by staff & students?

 

We only block writing to USB so copying photos etc can be done as normal

Posted
blocked them this year for staff using Windows and we're just using OneDrive instead. No grumbles and teachers just get on with it but a bit of a pain for us for teacher interviews and visitors as we have to copy whats on their USBs to the network should not email it in advance. From September we're banning them for students too, that might be a bit bothersome.

 

Our students stopped using USB of their own volition as soon as we got Google Drive.

  • Thanks 1
Posted

We made it so USB sticks have to be encrypted to write to them. They can be used as read only still without being encrypted.

 

One issue we came across was devices such as Microbits or MBEDS that act as a USB storage device but are actually used for programming got blocked. Does anyone have a work around for these kid of devices?

Posted
We made it so USB sticks have to be encrypted to write to them. They can be used as read only still without being encrypted.

 

One obvious hole in that is if a staff member puts sensitive data on a non-encrypted USB at home then brings it in and loses it - that would be readable to whoever found the USB.

Posted
One obvious hole in that is if a staff member puts sensitive data on a non-encrypted USB at home then brings it in and loses it - that would be readable to whoever found the USB.

 

And then the onus is with them not us.

Posted
One obvious hole in that is if a staff member puts sensitive data on a non-encrypted USB at home then brings it in and loses it

That would be such an obvious breach of policy that the staff member should be instantly dismissed.

 

The fact is, you can't legislate for every eventuality or for IT used by morons.

Posted
That would be such an obvious breach of policy that the staff member should be instantly dismissed.

 

The data loss in this article is almost certainly a breach of policy too. Worst case, the school has a policy saying "don't use unencrypted USB".

 

The thing which still niggles with me about this article is why someone was even carrying all that data in one spreadsheet in the first place, encrypted or otherwise. That's a lot of data for one person to be working with, which makes me think they should be senior enough to understand data protection better. We're not talking a teacher with a copy of their own markbook, this is the SEN register and prior attainment for every student, so that's likely an Assistant Head's USB stick (or an IT person who exported it for upload to their seating planner product). And if it is an Assistant Head, I wonder what else was on there if someone were to look in some sub-folders.

  • Thanks 1
Posted (edited)
How many of you guys and gals have actually banned USB sticks Physically (either within Windows / Group policy, or Impero or the like).

 

Or have you just advised staff not to use them?

 

I mean, if you have not physically stopped them from working on your PCs, then this kind of breech could still happen to you no matter how tight your training/policies are? All it takes is one person's mistake.

 

We blocked them here this year in preparation of GDPR as quite frankly as well as being a potential source of a data breach it’s just makes no sense to carry a USB drive these days with cloud storage.

 

We use group policy to block all usb devices and then created a whitelist of allowed devices blocking all portable usb devices other than the hardware encrypted ones we on rare occasions might supply staff.

 

We allow obvious things like keyboard, mice etc but only school owned cameras are allowed to connect and the polices also block phones and tablets.

 

The guide I used can be found here http://blogs.catapultsystems.com/gtate/archive/2010/02/07/windows-7-restricting-and-securing-usb-storage-devices/ if anyone else is interested in this approach.

 

It uses a combination of System Device Class GUIDs and Device Hardware IDs to manage to allowed devices.

 

Had no grumble from staff and it’s increased the uptake of OneDrive and any visitors are simply asked to email anything they might need to the school beforehand.

Edited by AngryITGuy
  • Thanks 3
Posted
We blocked them here this year in preparation of GDPR as quite frankly as well as being a potential source of a data breach it’s just makes no sense to carry a USB drive these days with cloud storage.

 

We use group policy to block all usb devices and then created a whitelist of allowed devices blocking all portable usb devices other than the hardware encrypted ones we on rare occasions might supply staff.

 

We allow obvious things like keyboard, mice etc but only school owned cameras are allowed to connect and the polices also block phones and tablets.

 

The guide I used can be found here Windows 7: Restricting and Securing USB Storage Devices if anyone else is interested in this approach.

 

It uses a combination of System Device Class GUIDs and Device Hardware IDs to manage to allowed devices.

 

Had no grumble from staff and it’s increase the uptake of OneDrive and any visitors are simply asked to email anything they might need to the school beforehand.

 

Excellent - will be absorbing that guide!!! Thanks!

Posted
Why is cloud safer than USB? USB have mostly one person access to. And when put everything in the cloud millions of people could have access
Posted
Why is cloud safer than USB? USB have mostly one person access to. And when put everything in the cloud millions of people could have access

 

Because you can tie down the rules so folders and files cannot be shared outside the organisation and because people don’t tend to drop “the cloud” in a car park.

 

If you have rules and policies on cloud use and devices allowed to access it then it is much less likely to be accessed by unauthorised users than an unencrypted memory stick.

Posted
Why is cloud safer than USB? USB have mostly one person access to. And when put everything in the cloud millions of people could have access

 

My USB can be accessed by whoever finds my USB when I drop it, leave it in a classroom PC by mistake, have my bag stolen, etc. Data I store in the cloud can only be accessed by someone who has either obtained my password or hacked the cloud storage provider.

Posted
Why is cloud safer than USB? USB have mostly one person access to. And when put everything in the cloud millions of people could have access

 

You cant drop your 'cloud' in the street or leave it in your laptop bag that you accidentally left on the train. You can with an unencrypted UBS memory stick and anyone finding it can access it.

 

With regards to the cloud having millions of people potentially hacking in to your account, cloud service providers have dedicated security teams to prevent that, unless you have hired a security guard to stay with your memory stick at all times, you don't have that kind of security with a USB memory stick.

Posted
...unless your USB stick has all your encryption keys to all your cloud service accounts. I don't think we have a policy for that yet.
Posted
...unless your USB stick has all your encryption keys to all your cloud service accounts. I don't think we have a policy for that yet.

 

Better start making one! mind you so should I!

Posted
...unless your USB stick has all your encryption keys to all your cloud service accounts. I don't think we have a policy for that yet.

 

We don't have a specific policy on that either, but I think it comes under the AUP which says not to write passwords down. There's only so much you can write policy for common sense!

Posted
We don't have a specific policy on that either, but I think it comes under the AUP which says not to write passwords down. There's only so much you can write policy for common sense!

 

That's an interesting perspective: that it's accepted in the industry that an encryption key is far more secure than a password, but the school policy explicitly bans their use on the grounds of 'security'.

Posted
Well, you obviously can't have encryption keys committed to memory so they're "written down" somewhere; but presumably that somewhere has some hefty access controls.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...