dcwhitworth Posted January 21, 2019 Posted January 21, 2019 OK and going forward what are people's policies on two factor authentication? I have it enabled on all of my accounts but do people insist this is set up for other school users? Not done yet but I definitely want to introduce it. I have concerns about user pushback over the 'inconvenience'. I think it's an essential in the cloud age.
TechMonkey Posted January 21, 2019 Posted January 21, 2019 OK and going forward what are people's policies on two factor authentication? I have it enabled on all of my accounts but do people insist this is set up for other school users? Here all O365 admins have it on. I am looking to move to it for general staff but if we do it will be set to not ask on site to minimise disruption. Currently planning the best way to cause minimum disruption.
jthompson Posted January 21, 2019 Posted January 21, 2019 I'd love to do what Google have done and mandate the use of U2F keys for all staff. We've got a bit of a journey to navigate to get there (both technical and human), but I think there's an inevitability about that as a destination.
rpain Posted January 21, 2019 Author Posted January 21, 2019 OK - and for further security how do people deal with monitoring the monitor? We're looking at my colleague checking what I access once a week (through the office 365 audit logs) and us mutually signing a sheet saying everything is in order. Also, how do people manage screen sharing and control - free access to pupil machines but explicit 'click here to allow screen sharing' on all staff machines? The big deal there being what about if a member of staff is looking at something inappropriate? It's been a shamefully long time sorting this out but better late than never...
Garacesh Posted January 21, 2019 Posted January 21, 2019 Personally, we don't do any sort of active monitoring at all. Staff have NetSupport that connects to all the machines in their room. We don't monitor the kids or the staff. Classroom management is their job, not ours. If a member of staff spots a kid of games etc, they can email me and say "Joe Bloggs, year 10, was on games at around 10:30, can you pull his web history and block it?" If a member of staff is accused of being on something inappropriate, we can pull their Smoothwall logs too. Every week I pull of a few reports from Smoothwall, what sites have been accessed the most, what search terms, etc, and follow up anything that looks a bit suspish. Smoothwall also emails reports to the CPO for her to check up on, and every once in a blue moon she'll come and ask us to investigate something. As for how do we log checking people's cloud files etc? Again, we don't. We just have an understanding that we won't go snooping for no reason and that they shouldn't store anything inappropriate in the first place, and a policy in place that says so.
dcwhitworth Posted January 21, 2019 Posted January 21, 2019 OK - and for further security how do people deal with monitoring the monitor? We're looking at my colleague checking what I access once a week (through the office 365 audit logs) and us mutually signing a sheet saying everything is in order. Also, how do people manage screen sharing and control - free access to pupil machines but explicit 'click here to allow screen sharing' on all staff machines? The big deal there being what about if a member of staff is looking at something inappropriate? It's been a shamefully long time sorting this out but better late than never... The keystone of our dealing with these issues is we have a specific system admin AUP on top of the standard user AUP which covers our broad behaviour and deals with some specific issues like what if you see something confidential. Personally I think monitoring the monitors is rather overkill and time that could be better spent on something else unless you have specific security concerns. We allow connection to all machines without permission. You can argue it both ways but there are times it is useful to be able to connect without permission being able to be granted.
Katy Posted January 21, 2019 Posted January 21, 2019 We allow connection to all machines without permission. You can argue it both ways but there are times it is useful to be able to connect without permission being able to be granted. We also have this set up, but it's using SCCM so the person being viewed gets the green bar at the top telling them so, and they can terminate it if they wish. Probably a good compromise between both sides that really.
dcwhitworth Posted January 21, 2019 Posted January 21, 2019 I think with a lot of these things it doesn't so much matter what your policy is, more that you have a policy that is written down and has been formally approved.
rpain Posted June 28, 2019 Author Posted June 28, 2019 Thanks - since then, staff now have their own passwords (12 characters long) and two factor authentication is on the way, usb sticks blocked unless approved. All of our files are in onedrive and sharepoint so that should mitigate ransomware problems. Hopefully we should be covered for the moment - can never be complacent of course. Richard
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now