Jump to content

Recommended Posts

Posted

Just so you know GDPR etc are not my areas within the school, that's another persons job, so I am very possibly wrong to be bringing this up.

 

I have one school that give out encrypted USB keys for staff to work on at home.

 

The way I see it is the staff are being asked to,

 

Work on potentially sensitive documents on a none school device that....

Might be shared by other family members

Can't be checked for viruses

Can't be patched or protected from being hacked.

Cant be audited

We can't remove any documents when the staff member leaves that they may have copied.

 

Am I completely wrong to be worrying about this?

 

I just wanted to get other peoples thoughts on this.

Posted
I think you're question really is "Are my members of staff GDPR compliant" and the answer is probably "no" from the sounds of what they're doing.
Posted

This is why we blocked USB sticks entirely via group policy before GDPR came in.

 

It's a grey area and what @Jawloms said is true - part of it is a staff training issue if you're going to let them do it. If you are then you should look at the DLP and identity tools that Microsoft offer through Office365 and MS Intune.

Posted

To be honest, it's inevitable that staff are going to take files home to work on. If you stop them using USB sticks, then they're only going to use another method, like emailing things to themselves.

 

We chose to enforce Bitlocker on USB drives, and push staff towards using the school-approved Google Drive. This also came with a briefing about data security in general.

 

The letter of the law on GDPR is to take appropriate measures to secure personal data, it doesn't specify yes / no on any one technology. I'd say encrypted USB drives would be an "appropriate" measure for now, although that may change.

  • Thanks 2
Posted

The school actually already use Google Drive for the staff files, but at this school I have been told the staff need to use encrypted keys when working at home. I am trying to change the culture but it's not really my place at this school.

 

The letter of the law on GDPR is to take appropriate measures to secure personal data, it doesn't specify yes / no on any one technology. I'd say encrypted USB drives would be an "appropriate" measure for now, although that may change.

Is it not a requirement to be able to delete any data help on someone if requested, or restrict access to data if someone leaves, both of which are simply not possible using USB keys.

Posted
Is it not a requirement to be able to delete any data help on someone if requested, or restrict access to data if someone leaves, both of which are simply not possible using USB keys.

 

A fair point. Again though, that probably falls under the category of where reasonably possible. When people request their data deleted, you don't have to delete every record, you have the right to retain certain records, and they may still reside on backups and other mediums where it is not practical to delete individual files.

 

You're right of course that USB sticks are a terrible idea in terms of keeping control and managing records, but any situation where files leave school, they leave your control, regardless of the transfer medium. Sounds like this school are dead set on keeping them, you can only advise them and their DPO that this is not a great idea. It's their risk, and I don't think anything in the GDPR outlaws it.

Posted

Of course, if school staff are expected (and indeed it is almost required, it's the nature of the job despite what people may say) to work at home writing reports, planning lessons etc then they should be provided with a mobile device (tablet or laptop) that is suitable for doing school work from home, as you would expect in any other professional industry.

 

Do what you can technically, anything else it becomes a management issue and your policies should mention this along with the word "disciplinary" if they decide to ignore said policies.

  • Thanks 1
Posted
GDPR doesn't say that you can't use USB sticks, encrypted or not. It's about demonstrating that you've taken reasonable steps to ensure that personal information is kept secure. You can put all the tech measures in place, such as banning memory sticks, encryption etc etc but at the end of the day, a lot of it comes down to human behaviour and what is and isn't acceptable. This is where policies come in, to back up the technical measures that have been established. If you ban USB sticks, cloud services can be used, or email to email it to a personal device. It's all about staff responsibility and behaviour, so policies, training, awareness etc are key to demonstrating that you've taken reasonable steps.
Posted

Realistically the only way to comply with staff working from home is to use a 2 factor secured remote desktop of some kind. That way the data never actually leaves your server room, staff are just temporarily and securely viewing it.

 

There's only a couple of risks to it as far as I can see, 1. using key loggers and 2. using screen recording software. Either way, you get those two risks with all of the other options available too so you could argue RDP is the least risky of them all?

 

This is what I am pushing for but it is an uphill struggle.

  • Thanks 1
Posted

My other schools all use Google Drive with 2 factor authentication and each staff member gets a laptop which they also use at home, I really like that setup.

 

The school in question probably cant afford laptops for everyone but I just wish there was a way to get them using Google Drive from home, seeing as they use it while in school and not USB keys. This is the same school that turned down remote access gateway a few years ago and that is when they all used normal USB keys.

Posted
Realistically the only way to comply with staff working from home is to use a 2 factor secured remote desktop of some kind. That way the data never actually leaves your server room, staff are just temporarily and securely viewing it.

 

There's only a couple of risks to it as far as I can see, 1. using key loggers and 2. using screen recording software. Either way, you get those two risks with all of the other options available too so you could argue RDP is the least risky of them all?

 

This is what I am pushing for but it is an uphill struggle.

 

 

I installed quite a few of these in a previous job, but in all honesty, the majority of schools never used them. Logging onto a VPN was too much of a PITA when they could just use USB sticks or email files home. If you do go this route, you need to close down the easier insecure options, and have a training push as to why they need to use the VPN.

  • Thanks 1
Posted

Progress not perfection and making an effort to cut the risks with staff training and awareness.

 

Quite important factors with GDPR :)

 

We force all our staff to have encrypted USBs or they can't save to them. If staff work at home on their own devices they should be passworded to prevent family members from accessing any documents. They can save through our remote access system. We can also offer advice on how to setup additional accounts on their equipment with a password. We strongly advise them not to save any documents on their home unless temporarily (plus a long list of other reminders).

 

Encrypted USB is more secure compared to one that's not which means better GDPR compliance. And you have to remember that a typical teacher document will only include names of students and shouldn't have any sensitive information. If you keep making staff aware of such things it should cut down the risks involved. Touch wood.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...