djrscally Posted October 5, 2018 Posted October 5, 2018 I.E. working from home on their own computer or similar. How are you all handling this? We basically tried to be as accommodating as possible and came up with this: 1. 'viewing' data on personal devices, I.E. reading emails through the web app or logging into the seating planner or MIS online is fine. 2. 'storing' data on personal devices, for example any kind of download of data including email apps or clients that will sync emails is not fine, and if you want to do that kind of thing you need to RDP into the school network. We were hoping that we could rely on policy and training to get people to work in a safe way, but I'm starting to lose faith in that solution (not least because I've found at least one 'switched on' staff member using personal IT kit actually in school on the grounds that they prefer it over their issued laptop). So; how are you all doing this? The nuclear option is to close all our sites (sharepoint, rdp gateway, outlook, Progresso etc) to external access and then configure staff laptops with a VPN so their traffic behaves as though it's internal, which should prevent basically any working on personal IT kit at all. I really don't want to do that though given it's going to irritate a lot of people and it is possible to work with a good level of security without going that far. So what's everyone else doing to solve these problems?
Ditto Posted October 5, 2018 Posted October 5, 2018 (edited) We try to cover this in our Acceptable Usage Policy. I'll check the wording later, but I recall it is a requirement for a home device used for school work to be password encrypted - enforcement is an issue as there's no process that ensures this to be the case. The issue I see with trying to distinguish 'viewing' from 'storing' is I doubt many people (employees or pupils) really know whether data is stored locally even when viewing. A few examples: view a PDF and it might download first, what about cache and internet history. I guess I'd be labelled by many as an 'IT expert', but when I rarely use my phone to reset a password in GSuite for Admin, I've no idea what data trail remains on my phone. In some ways, I think it comes back to a risk assessment. Suppose a teacher uses a home PC. If it's locked up at home, that's quite secure. If he has a separate account, strong password protection, that's better. If it's additionally encrypted, better still. Laptop's are generally less secure due to being left in car etc. All that said, I think bringing your own hardware in to school is a no-no. But with our previous head doing so with his personal MacBook because he didn't like the clunky Toshiba laptops we have - well, as you well know, that environment is going to be a struggle! Edited October 5, 2018 by Ditto
djrscally Posted October 5, 2018 Author Posted October 5, 2018 We try to cover this in our Acceptable Usage Policy. I'll check the wording later, but I recall it is a requirement for a home device used for school work to be password encrypted - enforcement is an issue as there's no process that ensures this to be the case. The issue I see with trying to distinguish 'viewing' from 'storing' is I doubt many people (employees or pupils) really know whether data is stored locally even when viewing. A few examples: view a PDF and it might download first, what about cache and internet history. I guess I'd be labelled by many as an 'IT expert', but when I rarely use my phone to reset a password in GSuite for Admin, I've no idea what data trail remains on my phone. In some ways, I think it comes back to a risk assessment. Suppose a teacher uses a home PC. If it's locked up at home, that's quite secure. If he has a separate account, strong password protection, that's better. If it's additionally encrypted, better still. Laptop's are generally less secure due to being left in car etc. All that said, I think bringing your own hardware in to school is a no-no. But with our previous head doing so with his personal MacBook because he didn't like the clunky Toshiba laptops we have - well, as you well know, that environment is going to be a struggle! Yeah it's a fight, which is annoying. The distinction is hard for some yeah; the problem was basically trying to avoid having to go full MDM on people's personal devices which they would be unlikely to allow. home PCs might be secure locked up at home but at some point that staff member isn't going to work for you any more, and that makes their continued access to the data unauthorized, so it has to be either "Don't store PII on your home PC" or "allow an MDM solution to be installed". I'm beginning to think an MDM solution and blocking access to things without it may be the only real answer
Areku Posted October 5, 2018 Posted October 5, 2018 whats to stop them email / cloud storing information from a machine thats full MDM to one thats not? Personally i think we can only take technical solutions to this problem so far, and then it will fall back on compliant training / policies.
djrscally Posted October 5, 2018 Author Posted October 5, 2018 whats to stop them email / cloud storing information from a machine thats full MDM to one thats not? Personally i think we can only take technical solutions to this problem so far, and then it will fall back on compliant training / policies. Restrict access to those services to internal traffic and configure a VPN to make traffic from authorised devices count as internal. I thought policy and training might be enough, but I'm coming to the conclusion that they're not.
enjay Posted October 8, 2018 Posted October 8, 2018 I can send you our full policy if you want it, but basically it says data must be held on encrypted devices or password-protected (emphasising to password protect the document not the laptop as hard drives can be removed and read), phones/tablets must have passwords and remote wipe enabled. If the computer is shared, users must log out of services each time and passwords must not be saved in the browser. Staff with children in the school or children who know students (e.g. their child is at a different school but plays hockey with students from our school) are specifically advised about information protection in the home. Let me clarify that - everyone is given that advice, it is emphasised for those staff in that position.
djrscally Posted October 8, 2018 Author Posted October 8, 2018 I can send you our full policy if you want it, but basically it says data must be held on encrypted devices or password-protected (emphasising to password protect the document not the laptop as hard drives can be removed and read), phones/tablets must have passwords and remote wipe enabled. If the computer is shared, users must log out of services each time and passwords must not be saved in the browser. Staff with children in the school or children who know students (e.g. their child is at a different school but plays hockey with students from our school) are specifically advised about information protection in the home. Let me clarify that - everyone is given that advice, it is emphasised for those staff in that position. Thanks; I'd be interested in seeing it. I particularly like the idea of giving advice about data protection at home
enjay Posted October 8, 2018 Posted October 8, 2018 This is our current policy:Data protection and security.docx It doesn't actually contain as much as I thought it did, some of that content (e.g. browsers saving passwords) must only be verbal in the annual briefing.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now