Jump to content

Recommended Posts

Posted

We currently have the AB Tutor client on staff only PCs as well as those used by the pupils, monitored infrequently by an SMT member. This is done as check against them accessing inappropriate content, but I think this is probably unnecessarily intrusive and we ought to be achieving the purpose by monitoring the web filter logs for alerts rather than screen monitoring.

 

I was wondering what was common practice around monitoring staff. Do you have the like of Impero, NetSupport, etc on staff PCs as well as pupil? If so, do you have it setup to prevent screen viewing without the staff member's knowledge? How about keystroke monitoring type systems like Securus or NetSupport DNA?

Posted
What does your policy say? That's the key. In my opinion actively monitoring staff without good reason is over the top. Your alerts should be in place to raise concerns but proactively monitoring the staff members screen is an invasion of privacy. Same as keylogging, useful at times but should only ever be accessed with a proper reason as part of a documented procedure that includes waht they are looking for, why and who is sponsoring and accessing the logs.
  • Thanks 2
Posted

This is what web filter monitoring is for imo. Would be more consistent than someone just checking occasionally and less intrusive.

 

If the logs / monitoring flag something, it may be justified.

  • Thanks 2
Posted

Do you prevent student login to staff machines? If not, then the ability to view silently on staff PCs may be necessary. Do you do it to staff? Then, I would say no, not unless there’s good cause for investigation.

 

I would compare it to the ability to take a look at staff files stored in their own area. Can you look at them? Yes; you’re the all powerful NM. Do you look at them? Only when there is cause for concern and only under written instruction from the Head. Otherwise routine checking your filtering should flag up those concerns.

  • Thanks 2
Posted

There's an element of trust in the job, the same as all jobs. Staff don't want to be treated like children, nor do I want to treat them like Children. However if they DO behave like a child, I will treat them the same.

 

Trusting the staff - to do their job, within data protection, GDPR, safeguarding remits etc. The firewall is there as part of the filtering to block any sites that need to be blocked. Staff can request sites to be blocked or unblocked accordingly - they're the ones teaching the students. However any sites I might have to do a double-take on will get questioned and raised to the Head for a decision if access is still needed.

 

What if there's personal information on the screen about them when you connect - wouldn't that be an issue for data protection then? Trust them to do their job and 90% of the time you won't have to worry stuff like this.

  • Thanks 1
Posted

Thank you everyone for your views. They confirm my impression that screen monitoring staff routinely is not normal. It certainly is documented in our policies that we do this and we do flag it to staff, but I totally agree on there being a significant risk of seeing irrelevant personal information when screen viewing.

 

I had a preliminary discussion with SMT today and I think the policy will be changed to web logging only, possibly with routine check by designated SMT member of the report showing sites and searches made by staff that have been blocked.

Posted
Our AUP states that all activity is logged and monitored, regardless of who the user is. This allows management to ask us to generate a report for a specific individual if they have concerns and covers their backs. As for the actual screen monitoring - we do have Impero on all workstations and are able to view them all, however we are in a 'position of trust' and know what is and isn't acceptable (much like how I am a sysadmin in SIMS, which opens up all the data).
  • Thanks 1
Posted
Have abtutor but only on pupil machines. Staff internet usage is accessible on the web filter and we could get in their email if the Head authorized it.
  • Thanks 1
Posted
Teaching staff are either in loco parentis in the classroom, or they aren't. If they can't be considered so by the senior staff, then screen monitoring is not going to be a sufficient measure.
  • Thanks 1
Posted
Have abtutor but only on pupil machines. Staff internet usage is accessible on the web filter and we could get in their email if the Head authorized it.

 

^^^ Same here.

  • Thanks 1
Posted

We have Impero on all laptops/computers.

 

We dont actively monitor what anyone is doing unless asked.

 

We do how ever use Impero to remote onto machines to do quick fixes for staff and students.

  • Thanks 1
Posted
It certainly is documented in our policies that we do this and we do flag it to staff, but I totally agree on there being a significant risk of seeing irrelevant personal information when screen viewing.

 

Does it give a reason for monitoring? I'm trying to remember but I'm sure back in the day we had to give specific reasons (Training, Safeguarding, Criminal activity, etc) and if a disciplinary was brought based on something not within those parameters then it could be taken to tribunal and it would be a slam dunk loss to the employer. If the reasons were too wide, so used every reason under the sun, and felt to be over reaching that could also be taken to tribunal and the policy dismissed.

 

This may be out of date though so check up.

  • Thanks 2
Posted

We have Visigo on all our domain PCs (and before that Securus) which monitors on-screen elements and key-presses for trigger words/phrases and then emails the safeguarding lead with reports of any concerning behavior. As we can't guarantee students won't log onto a any given compute it goes out everywhere as standard.

Of-course our AUP states very clearly (and we reiterate this in staff IT inductions) that computer activity is monitored for safeguarding reasons. Staff always seem fine with this.

 

Something purpose made like visigo/securus strikes a good balance IMO, as it's always watching (better for safeguarding than a remote spot-check) but only ever logs if trigger words/phrases are found (better for data protection than remoting in at random)

  • Thanks 1
Posted
We have Visigo on all our domain PCs (and before that Securus) which monitors on-screen elements and key-presses for trigger words/phrases and then emails the safeguarding lead with reports of any concerning behavior. As we can't guarantee students won't log onto a any given compute it goes out everywhere as standard.

Of-course our AUP states very clearly (and we reiterate this in staff IT inductions) that computer activity is monitored for safeguarding reasons. Staff always seem fine with this.

 

Something purpose made like visigo/securus strikes a good balance IMO, as it's always watching (better for safeguarding than a remote spot-check) but only ever logs if trigger words/phrases are found (better for data protection than remoting in at random)

 

It's the same as with us IT folk though, if we get a report of a site being unblocked or getting through the filtering - we have to test as all the accounts. So I'd imagine IT having a high false positive rate due to that. Same as IT folk having access to social media etc, we have to update websites etc or investigate when kids put stuff on about the school they shouldn't do.

Posted (edited)

Monitoring staff devices is often a hot topic , often the driving force is what the SLT has approved with governors in terms of staff IT / acceptable use policies. I’d suggest the three main approaches I see in schools are :

 

Staff devices all have comparable monitoring to student devices ( and many staff are this as protecting them as well), or,

 

Profiles set for different staff groups, so perhaps SLT for example have thumbnails monitoring disabled and keyword filtering off, or,

 

Monitoring/ filtering disabled on staff devices. I don’t think this is good practice though and does mean the school loses its ability to enforce some of its key policies.

 

The most common option taken is to have filtering on all school devices but staff devices are profiled separately so internet restrictions etc are not enforced and when accessing systems like CPOMS / My Concern they do not trigger keyword alerts when then DSL or others are logging student concerns.

 

I’d argue the policies ratified by governors tend to be the driver for the level of monitoring applied and GDPR added an extra need to tighten policies on staff as well as student devices in a broader sense.

 

Al

Edited by Al_NetSupport
  • Thanks 2
Posted

I'll add my two cents here as well, regarding best practices;

 

We operate a fairly linear hierarchy; Server/Reports at the top (sees all PC's) > Techs (sees all staff/students) > Safeguarding (sees all students) > Teachers (sees their class of students) > Students (see no-one).

 

At each level we can choose what level of access is granted to the one above it; for example, Techs can remotely control staff machines, but they can't see their screen (thumbnails) for privacy. The Teacher gets a brief moment to deny the remote control request coming in (i.e. if they're working on something private/sensitive), and the school can decide what the 'default position' is (whether a request on an idle machine will go through or not). All of these can be tweaked and changed by the school.

 

In some rare cases, the school can also choose to allow the Students to opt out of being monitored as well, such as in a Steiner/Montessori school environment where the children have much more personal freedom than your typical state school.

 

The same applies for BYOD; the school can choose to give the student the option to drop their visibility temporarily (i.e. between classes).

 

For the staff machines, there is no individual/personal choice - as per Al's message above, we will consult with the school and then create and enforce different filtering/monitoring profiles that will determine exactly what data is a) monitored b) captured/logged c) reported on.

 

For most schools, they will want the hardware reports to complete as usual (i.e. uptime, program utilisation, login histories etc) but user-centric data such as those mentioned in the OP (i.e. website histories) are not tracked. Keyword logging & keyword-alert automatic screenshots are disabled for staff by default and 99% of schools don't ask us to change it for fear of an uprising :cool:

 

In my experience, the school will still be monitoring staff web traffic by the web filter, just not local machine activity (i.e keystrokes) via the local client, to respect their privacy and keep the peace, while still meeting the Ofsted reqiurements for safeguarding.

  • Thanks 1
Posted
We currently have the AB Tutor client on staff only PCs as well as those used by the pupils, monitored infrequently by an SMT member. This is done as check against them accessing inappropriate content, but I think this is probably unnecessarily intrusive and we ought to be achieving the purpose by monitoring the web filter logs for alerts rather than screen monitoring.

 

I was wondering what was common practice around monitoring staff. Do you have the like of Impero, NetSupport, etc on staff PCs as well as pupil? If so, do you have it setup to prevent screen viewing without the staff member's knowledge? How about keystroke monitoring type systems like Securus or NetSupport DNA?

 

We use NetSupport which does not require STAFF permission to connect although I have set a security key to stop staff from viewing other staff. We also use NetSupport DNA which will grab screenshots of anything that we have configured in the Safeguarding section. I also have VNC as a backup for connecting remotely.

 

Our school policy is basically "You have no expectations of privacy whilst using the school network and we reserve the right to monitor staff and resources as we see fit to ensure compliance with relevant school policies."

 

We also have software that I can install which will basically turn the target PC into a huge recorder, capturing screen, audio, keystrokes, keywords the lot. We only ever install this one when we have the Head's authorisation due to how intrusive it is.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...