Jump to content

Recommended Posts

Posted (edited)

As part of contributing to the continued DfE resources around Data Protection, both EduGeek and ANME have agreed to have members look at areas around IT Services, what they access, how they work and any pinch points where risk might be a significant factor.

 

IT Support (whether an individual working part time within a school, a small team, a larger group across multiple schools or even as commercial IT Services) can be veritable gods within schools, with access and control over key systems and functions. When someone needs things changing in the MIS who do they ask? Searching mailboxes for missing documents? Checking what students have been doing on the internet? Controlling access to confidential folders? Domain admins, sysadmins with root, holders of master keys and alarm codes … the list goes on.

 

And with great power comes great responsibility. What are the checks and balances that we put in place to manage this? Do we document those or do we do it in our heads and on the fly? I think we all know that answer to that.

 

This group will look at particular roles they perform in schools and see which could be considered to have risks associated to them. We will then use the ICO DPIA form (or one of their choosing) to break down how it could be formally reviewed and measures / risk management plan could be put in place. It also means that formal acceptance of risk can take place, giving a level of support / comfort to IT staff.

 

These will then be exemplar / templates that the DfE can point people towards and reference. Contributors will be mentioned as the members of this group.

 

For EduGeek members to join this group, please message @ZeroHour or @Dos_Box with your details. They will short-list and then give you access to the relevant areas.

For ANME members, you will be given advice on how to join over on the ANME site.

 

The deadline is Tuesday 18th June

Places are limited and so the best cross-section of applicants will be involved. It is open to all, but experience of making decisions on risk would be beneficial.

Edited by elsiegee40
Posted
Would happily lend a brain (what little I have!) to this worthwhile effort. I have responsibility for day-to-day data protection at my school (we have an outsourced DPO company as well), and full responsibility for information security as you'd expect.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...