Jump to content

Recommended Posts

Posted

One of the jobs on my summer list is to get Bitlocker working. I've found (but not yet implemented) the GPOs and GPPs necessary to prompt for encryption and enforce read-only if not encrypted so assuming that all works as expected, I'll be 90% there. That leaves the other 10% though, which is that staff could create non-encrypted memory sticks at home, save sensitive data on them and bring them in to school as reference resources. I can see staff using this loophole to get round the fiddliness of encrypting a stick, so I'd like to block non-encrypted sticks for staff. Is this possible?

 

I know staff could still do this and leave the non-encrypted stick lying around where a student could find it, but I'm willing to accept that risk. I think if the staff can't read the non-encrypted sticks at all, they'll very quickly stop bringing them in.

 

So, can I achieve what I'm after, or do I need to accept there is a still a risk staff could still access sensitive data from non-encrypted memory sticks?

 

Am I overly worrying here? Will setting the sticks as read-only be sufficiently restrictive for staff they won't want to bring them in anyway??

Posted
Am I overly worrying here?

 

Yes :p

 

If they can access that sensitive data at home to be able to add it to an unencrypted USB in the first place they're either breaking AUP/policies etc, or you have something setup wrong :p

 

What's the difference to accessing the files at home and emailing them in? You won't block attachments etc would you.

 

There's always going to be a level of "what ifs", like taking a picture of the screen with a phone and printing out an image etc, but as long as you're putting the policies and practices in place you're doing more than enough.

 

Steve

Posted
If they can access that sensitive data at home to be able to add it to an unencrypted USB in the first place they're either breaking AUP/policies etc, or you have something setup wrong :p

 

I wouldn't say we have things set up wrong. Staff have access to Google Apps and SIMS from home, so could easily access sensitive information and transfer it to a non-encrypted memory stick.

 

What's the difference to accessing the files at home and emailing them in? You won't block attachments etc would you.

 

The difference is emails would be protected behind a password. A non-encrypted memory stick left on someone's desk would not be (although leaving said non-encrypted memory stick lying around would be against policy).

Posted
The wrong part was in relation to if they aren't breaking any AUP/Policies by doing that :p As in if you didn't have that in them.

 

Ah, I see. We have written policies saying not to do it - and have had for years. GDPR brings with it the desire the technically enforce / prevent breach of these policies, rather than just telling people what (not) to do.

Posted

But you're taking one scenario rather than the whole overview. If they can access the data at home and get the data onto a USB drive, that drive can be lost anywhere even on route to school for argument sake, or when their home computer is stolen.

 

Blocking of the USBs at school isn't going to stop this happening, therefore you're either saying you need to stop all possible downloads at home or have policies that are used for this. It's not a technology based answer in that regards but an overall process that's put in place.

 

Steve

Posted
If they can access the data at home and get the data onto a USB drive, that drive can be lost anywhere even on route to school for argument sake, or when their home computer is stolen.

 

Yes, I acknowledge that. My thinking is that if the non-encrypted memory stick were just a paperweight in school, the staff would be unlikely to bother saving data to it and it therefore wouldn't matter if it got lost.

 

I also acknowledge I'm probably being overly-panicky here!

Posted
It's not a technology based answer in that regards but an overall process that's put in place.

 

The devil's advocate response to that is to say, if I'm ultimately reliant on human enforcement not technical, why am I bothering with any technical enforcement? Why not just carry on as we have been for years with a written policy saying "don't do it"?

Posted
The devil's advocate response to that is to say, if I'm ultimately reliant on human enforcement not technical, why am I bothering with any technical enforcement? Why not just carry on as we have been for years with a written policy saying "don't do it"?

 

Because saying "don't do it" rarely works and you should have at least investigated technical and organisational measures ... and taken them where you can. Rdcuing risk vectors can be a fine art, but for something as general as this ... I think you are going about it the right way. USB sticks are a bad thing to put data onto ... so if you can eliminate a vector for data loss, then go for it. You have established the scenarios and know that organisational measures are unlikely to reduce risk.

Posted
On a technical level the built in Group Policy for removable media are most useful when targeting at the computer. The larger question is why USB sticks ? The only reason is staff who may deal with large files and want to work at home when RDP etc isn't practical. It may be safer for them to use a laptop with Google Drive sync'd that is encrypted.
Posted
Blocking USB with GPO seems fairly straightforward and reliable. The issue for us is cameras/SD cards. It seems quite difficult to block one and not the other - plus of course, there's no reason a member of staff couldn't just store all those confidential files on an SD card.... If anyone knows of a policy that could restrict to read only of file type jpg, that would be great!
Posted
The larger question is why USB sticks ?

 

Because some people like to work that way.

Because some people haven't adopted Google Apps and Drive yet.

Because SIMS exports to local drives, so some staff export at home to USB so they can carry on working in school (or because it is a shared computer at home, and they don't want others to access the files - especially relevant with teacher/parents.

Because Google Slides is horrible so staff are carrying PowerPoints on USB.

Because my predecessors were brutal with disk space allowance and had a habit of losing backups, so staff took to working on memory sticks and some haven't adapted yet or learned to trust again yet.

Posted

> Because some people like to work that way.

 

Too bad, new rules

 

> Because some people haven't adopted Google Apps and Drive yet.

 

Give them more training

 

> Because SIMS exports to local drives, so some staff export at home to USB so they can carry on working in school

 

Save to cloud drive by default

 

> (or because it is a shared computer at home, and they don't want others to access the files - especially relevant with teacher/parents.

 

Give everyone a laptop, using other computers is way too high a risk, they're probably already infected

 

> Because Google Slides is horrible so staff are carrying PowerPoints on USB.

 

Hmm, seems fine to me, what don't they like about it?

 

> Because my predecessors were brutal with disk space allowance and had a habit of losing backups, so staff took to working on memory sticks and some haven't adapted yet or learned to trust again yet.

 

Information campaign, "we've hired the top 1% of the computer industry to backup your files, they've never lost a file in 10 years", also infinite storage space, and the GDPR flying drone won't attack you

Posted

SIMS can't save to cloud drives and we can't force staff home computers to work in that way.

 

Can't afford a laptop for every staff member, unless we take their classroom computers away and have them just use the laptop (which is a new and different headache!)

 

Issue with Slides is more limited screen transitions, much slower to load than PPT (especially with large slideshows) and probably most important, it murders any PPT you try to convert to it.

Posted

It can save to a location that's synced to a cloud drive, or probably a mapped webdav drive.

 

I find it surprising that using a classroom teacher computer is found to be easier, I set up all my teaching stuff on my laptop in tabs and windows so I can start the lesson rapidly, without having to log on, load stuff, log in to websites etc.

 

Transitions are pointless wastes of time anyway. If you're using an existing pp just use https://office.live.com/start/PowerPoint.aspx

Posted
I find it surprising that using a classroom teacher computer is found to be easier, I set up all my teaching stuff on my laptop in tabs and windows so I can start the lesson rapidly, without having to log on, load stuff, log in to websites etc.

 

It is the time needed to connect the laptop to the projector (including getting the cables upside-down and in the wrong port), turn the laptop on, log in, etc. rather than just log in to a PC which is ready to go.

 

Getting everyone to use OneDrive is an odd workaround to the problems with Powerpoints in Google Drive/Slides. Also, I can imagine people getting very confused about what they've saved where.

Posted
It is the time needed to connect the laptop to the projector (including getting the cables upside-down and in the wrong port), turn the laptop on, log in, etc. rather than just log in to a PC which is ready to go.

 

Getting everyone to use OneDrive is an odd workaround to the problems with Powerpoints in Google Drive/Slides. Also, I can imagine people getting very confused about what they've saved where.

 

Laptop is already logged in and in standby, so just open it. USB-C should solve the problem, only 1 cable then, which you can't get wrong. For me plugging 2 cables in takes max of 30 seconds if I'm also blind, whereas loading all my work for the lesson takes much longer, plus logging in

Posted
Laptop is already logged in and in standby, so just open it. USB-C should solve the problem, only 1 cable then, which you can't get wrong.

 

So you have docking stations on all the classroom desks which connect to projector, speakers and interactive board, so just one cable to connect to the laptop? That's tempting...

Posted

It's one option. HDMI does speakers and video, so that brings it to 2, just need to do usb over the same cable. So your options are displayport 1.2, which isn't that common, or USB-C with Displayport alt mode, probably need a breakout box/cable for both though. The future, it's almost within reach!

 

Our teachers don't really find it a problem to plug in 2 or 3 cables though, they get used to it once they do it 4 times a day

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...