bald_pig Posted October 29, 2020 Posted October 29, 2020 The legislation is Keeping children safe in education. It references the UK Safer Internet Centre's guidance. It also references the "Prevent Duty" - aka Protecting children from radicalisation: the prevent duty. It does leave some questions down to individual schools and their risk assessments and it does discuss "over blocking". But the requirement is clear, you are expected to filter and monitor your school Internet connection. And every single point there says "for children"
Primus Posted October 29, 2020 Posted October 29, 2020 The first paragraph says: Governing bodies and proprietors should be doing all that they reasonably can to limit children’s exposure to the above risks from the school’s or college’s IT system. As part of this process, governing bodies and proprietors should ensure their school or college has appropriate filters and monitoring systems in place. Allowing staff or visitors to view content that is unsuitable risks children also seeing it, hence the need to filter and report on staff, visitors and children. It also calls into question their suitability to be members of staff or visitors under the broader safeguarding duty on schools - if someone on site is viewing inappropriate content using your Internet connection then you ought to know about it in order to be able to take action. There is also the obvious issue with shoulder surfing and students obtaining access to accounts they shouldn't - eg. a rogue visitor sharing their log on details or students seeing it written down on a visitor's information pack or similar. 1
FN-GM Posted October 30, 2020 Posted October 30, 2020 The first paragraph says: Governing bodies and proprietors should be doing all that they reasonably can to limit children’s exposure to the above risks from the school’s or college’s IT system. As part of this process, governing bodies and proprietors should ensure their school or college has appropriate filters and monitoring systems in place. Allowing staff or visitors to view content that is unsuitable risks children also seeing it, hence the need to filter and report on staff, visitors and children. It also calls into question their suitability to be members of staff or visitors under the broader safeguarding duty on schools - if someone on site is viewing inappropriate content using your Internet connection then you ought to know about it in order to be able to take action. There is also the obvious issue with shoulder surfing and students obtaining access to accounts they shouldn't - eg. a rogue visitor sharing their log on details or students seeing it written down on a visitor's information pack or similar. Doesn’t mention monitoring. You can filter this out without the need for SSL inspection.
Primus Posted October 30, 2020 Posted October 30, 2020 Doesn’t mention monitoring. You can filter this out without the need for SSL inspection. It does mention monitoring. Read it again! 1
FN-GM Posted October 30, 2020 Posted October 30, 2020 It does mention monitoring. Read it again! Sorry. I meant to the it doesn’t mention the level of monitoring.
elsiegee40 Posted October 30, 2020 Posted October 30, 2020 As ever, the DfE stops short of giving MUSTs for filtering and monitoring. This is partly because the technology changes so rapidly. Rebecca Avery the Kent Online Safety Officer, aka @esafety_officer, went through KCSIE with a fine tooth comb and extracted the implications for online safety that settings must consider. See this pinned thread Online Safety within ‘Keeping Children Safe in Education’ (KCSIE) 2019 https://www.edugeek.net/showthread.php?t=208603 2
Ditto Posted October 30, 2020 Posted October 30, 2020 KCSIE repeatedly says 'Governing bodies and proprietors should ensure appropriate....'. How it is implemented is an operational matter. Perhaps the school should ask for strategic guidance on appropriate monitoring and filtering for guest accounts. Ultimately it is not a decision the IT team should make, they should just implement what the governing bodies and proprietors deem appropriate. IT can help by providing the consequences of each option. i.e. that impact of monitoring encrypted traffic for guests, the risks with not doing so. Once it has been decided, policies need to be updated to reflect this and I'd suggest pulling together a brief document to provide guest users that explains the terms of use and filtering/monitoring in place.
Dos_Box Posted November 2, 2020 Posted November 2, 2020 :mod:Mod Alert:mod: We have unapproved some posts to tidy up the thread.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now