Jump to content

Recommended Posts

Posted

Morning all,

 

We already block most social networks and messengers on our LAN's, but we still need to get the message across(see what I did there) to staff that they shouldn't be using services like WhatsApp for business use and the conveying of any protected data on those devices, even installing it on a business device, as it will need access to the address book, and hold this in the US, where it has been proven that while they encrypt all data, they don't encrypt the metadata, and this can still provide a multitude of personal data to be floating around.

 

Anyone already have a policy for this, and would like to share the wording used? I am struggling to not come across as a complete draconian dick(which I am, but I need my cloak of nice guyishness to stay intact :) )

 

Thanks

 

James

Posted

It is part of our AUP.

 

Something along the lines of

 

"You will only use approved communication services for school business"

 

It doesn't need its own policy.

  • Thanks 1
Posted

Yes, it will be put like that in the policy, but I really want a paragraph to why to stop people asking loads of questions :)

 

I have gone with, so far in my draft:

 

WhatsApp is a global messaging platform and as such is a great way to communicate with others, but it is not fit for use in business under the terms of the GDPR and general compliance.

 

When the app is installed you give permission for them to access your address book and other aspects of the device being used, and this data is then communicated to servers in the US, where we have no control and it has been proven that while the data is encrypted end to end the metadata is not, this metadata contains:

 

-Your name, mobile number, IP address, location, mobile network and your mobile handset type.

-With whom you are chatting, for how long and at what time. And your contacts as well.

 

Also as the data is encrypted end to end, we have no access to that data once out in the world so therefore no control over that data, only the sender and the recipient have access, and that causes problems if the data is about another party.

 

Just not sure how much of that is rollocks and how much is truth, I think it all still stands, but things change in the quick world of messaging!

Posted
I wouldn't bother. None of that needs to be in a policy and if WhatsApp dies or TheNextBigThing™ comes along you will be expected to describe that as well. Keep it generic. In communicating the change you can give your reasoning, but really, the policy is the policy and has been decided by management, it is too late to question and if they don't like it they need to resign.
Posted

We use WhatsApp for SLT communications as it's secure and immediate. It's especially useful for late night or early morning incidents.

 

If anyone can think of anything better that works across all platforms then we'll consider using it.

Posted
Secure doesn't mean compliant. I suppose as long as you have mitigated risks, no protected data to be shared, make sure the app doesn't have any access to any protected data on the device it is being used on, etc, etc. I'm still not trusting the platform as far as I can fling it!
Posted
We use WhatsApp for SLT communications as it's secure and immediate. It's especially useful for late night or early morning incidents.

 

If anyone can think of anything better that works across all platforms then we'll consider using it.

 

If you're using Office 365, have you looked at Microsoft Teams?

 

John

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...