Jump to content

Recommended Posts

Posted
People who deal with sensitive matters are in a different group, not readable. You have home drives because they're read only to everyone else. Most things end up on a shared drive anyway.

 

"People who deal with sensitive matters" is potentially everyone. Any manager could deal with sensitive matters about their team, or in some cases other staff in the school. Any staff member at all could deal with sensitive matters about students, e.g. if they witness something or a disclosure is made.

Posted
There is a massive difference between your employer may look at your files and everyone can look at your files willy nilly.

 

Where do standard users store their Appraisals, reviews or sensitive documents that are meant to be for them and their line managers eyes only now that everyone can now look? Disciplinary matters, bereavement issues, medical or mental health documents.

 

What if something is downloaded that someone else looks at that is either misinterpreted or causes issues? What about medical or sickness documents that may need to be saved to a home area to be passed on to management?

 

The better question is why does everyone need access to all documents, even read only? Just to prove your point that you want to stick to? It ignores best practice of the principle of least privilege. One mistake, one accidental save, and you have the potential to cause massive HR/employment issues. As I said great shortcut to a tribunal and a complete disregard or ignorance of potential issues.

 

Usually in email. Worked fine for 5 or 10 years, no one ever complained, or spent their days looking at other people's files when they didn't need to access them. The point is everyone knew, so weren't surprised to find out. Thus they didn't store their secrets there. And if they wanted to store secrets, I'd show them how to use permissions

Posted
Usually in email. Worked fine for 5 or 10 years, no one ever complained, or spent their days looking at other people's files when they didn't need to access them. The point is everyone knew, so weren't surprised to find out. Thus they didn't store their secrets there. And if they wanted to store secrets, I'd show them how to use permissions

 

Email for storage? But that is non personal as well so shouldn't that be shared?

 

"No one went looking" that you know of as you had no way to check?

 

No one should be surprised as it should be in your AUP and part of your induction.

 

Those arent secrets, they are sensitive information that is company related. What you probably created is staff storing information on USB sticks (if allowed) or on other storage, creating Shadow IT, and we all know how well both of those go.

 

I'm glad you or your previous school lived a charmed existence. But as I said one mistake and that would be a tribunal or a court case.

Posted
Why?

 

...

 

Because it's madness, that's why. Staff should be able to keep files from being viewed by each other & likely expect that their home directories aren't open to everyone - Because you know, that's the flipping standard virtually everywhere.

 

If you don't allow them. then they certainly are running some kind of shadow IT operation somewhere. If you can't see why they need "private" access then you've become too detached from the people you are supporting.

  • Thanks 1
Posted

As @rom1984 has said, no reason not to comply with this request but you also need to consider this within wider legislation and practices.

Why are the files being accessed? To assess for reasons for stress? To allow someone else to carry on the work? To allow for the SBM to identify who to hand things over to (effectively being the gatekeeper ... which is actually a good thing as it shows that someone is taking ownership of this and not just giving carte Blanche to others to dig in there).

There is nothing wrong in asking for the Head to sign off the request (it should be done by someone other than SBM to protect the SBM and the school) and ensuring that they have considered all applicable legislation, sought guidance from HR and checked school policies.

  • Thanks 2
Posted

OK back to the original question.

 

couple of things, is there a caveat in your AUP for monitoring? Ours does have this, but is pulled into place only when needed, we do not actively monitor staff all the time, that would be a nightmare.

 

For my school, no staff member has out right access to anyone's areas, except Domain Admins, People can submit requests that have to be signed off by my line manager or the Headteacher in order to get a copy, and email is just the same, in fact, email they have to ask for a from and to address and I run a powershell command to copy those emails to their inbox, so I cannot see anything.

 

Now as for this particular scenario, I would o to the head to sign it off no mater what the main policy is, this is because this person is signed off, and theory should not be working but as from previous experience, being off and not doing anything can actually heighten the stress levels, as you feel like you are falling behind and not being useful

  • Thanks 1
Posted

In the time I've been here, I've had a few requests for this to be done for people on long term sick. Most of the time, I get a request for a specific file or folder to be sent over to someone - I get told what file/folder, and I make a copy for them. On the few "really long term" sickness requests, our COO authorises it, and I make the data available via a shortcut for the person who needs access.

 

I think there's only ever been one request for access for someone's files regarding a disciplinary, all other times have been due to long term sickness for job continuity.

  • Thanks 1
Posted

> Email for storage? But that is non personal as well so shouldn't that be shared?

 

Email is a good place to store information, has lots of metadata and good search.

 

> "No one went looking" that you know of as you had no way to check?

 

No one spent all day looking. Obviously they did use the drive because otherwise it wouldn't have been set up that way. The reason it was set up that way was because teachers moved around a lot and other people had to cover/access files to teach the same lesson to a kid who wasn't in the classroom etc.

 

> No one should be surprised as it should be in your AUP and part of your induction.

 

Everyone is surprised by things in long boring documents they skimmed 10 years ago

 

> Those aren't secrets, they are sensitive information that is company related. What you probably created is staff storing information on USB sticks (if allowed) or on other storage, creating Shadow IT, and we all know how well both of those go.

 

Or just asking me how to have private files, and as I said, I showed them how to change permissions

 

> I'm glad you or your previous school lived a charmed existence. But as I said one mistake and that would be a tribunal or a court case.

 

That's what the head decided, seemed to work.

Posted
The reason it was set up that way was because teachers moved around a lot and other people had to cover/access files to teach the same lesson to a kid who wasn't in the classroom etc.

Just seems super odd to me. Why isn't that kind of thing just saved to a shared drive? Do you even have a shared drive (I don't see the need to have both this kind of setup and a shared drive).

 

Or just asking me how to have private files, and as I said, I showed them how to change permissions.

Out of interest how many staff have used permissions to set up 'private' folders?

Because wouldn't it make the whole thing pretty redundant if they just created 'private folders' and put everything in there.

Also how do you guard against the teachers removing the admin permissions, which would make the folder a right pain to delete/archive.

Posted
> Email for storage? But that is non personal as well so shouldn't that be shared?

 

Email is a good place to store information, has lots of metadata and good search.

 

> "No one went looking" that you know of as you had no way to check?

 

No one spent all day looking. Obviously they did use the drive because otherwise it wouldn't have been set up that way. The reason it was set up that way was because teachers moved around a lot and other people had to cover/access files to teach the same lesson to a kid who wasn't in the classroom etc.

 

> No one should be surprised as it should be in your AUP and part of your induction.

 

Everyone is surprised by things in long boring documents they skimmed 10 years ago

 

> Those aren't secrets, they are sensitive information that is company related. What you probably created is staff storing information on USB sticks (if allowed) or on other storage, creating Shadow IT, and we all know how well both of those go.

 

Or just asking me how to have private files, and as I said, I showed them how to change permissions

 

> I'm glad you or your previous school lived a charmed existence. But as I said one mistake and that would be a tribunal or a court case.

 

That's what the head decided, seemed to work.

 

Ok, I'm going to bow out of this as you do not seem able to grasp the issue at all, which is troubling in it self to me, and we are going to end up going around and around in circles when it is off topic from the OP. You admitted that private files are needed in your own argument so negate your whole point, which leads me to wonder if you are just arguing for argument's sake or really haven't thought it through. Once we get on to discussing things like using email as a storage medium then I am definitely out.

 

But hey, we are all different, that's what makes life interesting. Good luck with it.

Posted
Just seems super odd to me. Why isn't that kind of thing just saved to a shared drive? Do you even have a shared drive (I don't see the need to have both this kind of setup and a shared drive).

Offline files iirc.

 

Out of interest how many staff have used permissions to set up 'private' folders?

Because wouldn't it make the whole thing pretty redundant if they just created 'private folders' and put everything in there.

Also how do you guard against the teachers removing the admin permissions, which would make the folder a right pain to delete/archive.

 

Can't remember, wasn't very many people. Backup user has all permissions anyway iirc. Wasn't much of an issue.

Posted
How do you mark an email as personal? Folder yes, but not individual emails. Also, if you search for a document/email, you might not know the folder it is in.

 

 

 

And who decides whether the reason is good enough? Is that decision-making process documented?

.

 

Just checked out the AUP and it says "Where personal use is allowed you should ensure the following: Mark personal emails private or "non-work" in the subject header to differentiate these from business email... We are committed to respecting staff expectations of privacy concerning the use of our ICT Systems and equipment. However, we reserve the right to log and monitor such use." This specific policy is linked it with ISO/IE 27001:2013 - no idea if that helps!

 

We have a "steering group" made of off DPO, Head of Complaints, Head of Governance and Head of IT which makes any decision ref this.

 

Is there anything in the ICOs Employment Practise code that would help? - https://ico.org.uk/media/for-organisations/documents/1064/the_employment_practices_code.pdf

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...