Jump to content

Recommended Posts

Posted

Hi,

 

Been reading quite a few threads about GDPR and seen a post about schools in breach with password for both website and MIS system which raised alarm bells with how we use sims.

 

We use MS RemoteApp to access sims.net and other very sensitive information. Staff have encrypted laptops, but use their domain account to sign into remote app, then sims is set to use their network account to logon. If that one password were to be compromised then there is access to sims, email, sharepoint and remoteapp.

 

How many schools allow access to sims from home? From what I've heard about staff attending courses in Suffolk is that we are 1 of very few around here?

 

Matt.

Posted
We have SIMS available via RDS and it's used a lot by teaching staff. We're now looking into only allowing RDS for staff once they've signed some sort of suitable "I understand..." paperwork.
Posted (edited)

Our MIS is a web application (Progresso); so access is available at home...or anywhere else for that matter. Access from home on encrypted laptops owned by the school is fine provided they're doing it over a secure channel.

 

Regarding no use of single sign on - we actually do use it, taking the view that it's a lower risk than password overload causing people to sticky-note them to their screens. It's one of the solutions recommended by the NCSC.

 

https://www.ncsc.gov.uk/guidance/password-guidance-simplifying-your-approach

Edited by djrscally
Posted
Regarding no use of single sign on - we actually do use it, taking the view that it's a lower risk than password overload causing people to sticky-note them to their screens.

 

Same here. We have complexity requirements and age limits on domain passwords. I don't know if those are possible within SIMS, but I do know what some users can be like with their passwords without them (i.e. hopeless).

Posted
We currently use Sims at home through RDS and they logon with their network credentials. We secure this connection using 2 factor authentication via Swivel Secure https://swivelsecure.com/ so even if the password is compromised they can't log in through the remote connection.
Posted
Our MIS is a web application (Progresso); so access is available at home...or anywhere else for that matter. Access from home on encrypted laptops owned by the school is fine provided they're doing it over a secure channel.

 

Regarding no use of single sign on - we actually do use it, taking the view that it's a lower risk than password overload causing people to sticky-note them to their screens. It's one of the solutions recommended by the NCSC.

 

https://www.ncsc.gov.uk/guidance/password-guidance-simplifying-your-approach

 

We do have complexity and could change time limits? ok thanks for the link - i'll show that to SLT

Posted

We make SIMS available via MS RemoteApp, which works well. SSO using Trusted Authentication, too.

Passwords require complexity and we enforce change every 180 days (shorter becomes self-defeating as they keep forgetting or use sticky notes).

 

We publish minimum requirements for home PCs and also set RD limits, so XP or other old OS is not allowed to connect.

Posted

We publish SIMS via RemoteApps - Access to RDS is requested by staff so no one gets it automatically.

 

No SSO. SIMS and AD passwords are separate and forced complexity. Staff laptops are encrypted too.

Posted
Access from home on encrypted laptops owned by the school is fine provided they're doing it over a secure channel.

 

Forgive me if I'm being naive on this one, but as long as it's over a HTTPS and the HTTP headers are set correctly in regards to caching the content, then this really shouldn't matter should it?

Posted
We publish SIMS via RemoteApps - Access to RDS is requested by staff so no one gets it automatically.

 

No SSO. SIMS and AD passwords are separate and forced complexity. Staff laptops are encrypted too.

 

Forgive me if i'm wrong but how do you enforce complexity on SIMS passwords? From what I can tell SIMS passwords are not even case sensitive (YET)!

Posted
If it's set to something longish like 200 or 300 days, then I'd still consider that a more secure arrangement overall. Allowing staff to stick with one password indefinitely is just leaving the door open for them to use that one password elsewhere for years on end (e.g. over at Yahoo! or LinkedIn).
Posted
We currently use Sims at home through RDS and they logon with their network credentials. We secure this connection using 2 factor authentication via Swivel Secure https://swivelsecure.com/ so even if the password is compromised they can't log in through the remote connection.

 

Well our headteacher has banned sims.net via remoteapp from home - I've removed the external DNS record so as of today it can no longer be used and already there are talks about unions getting involved, as they don't have the time to complete marksheets in school hours......

 

Now looking at multi factor authentication - what do you do when the session is active, do you have any policy in place on the connection broker for inactive timeouts?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...