Jump to content

Recommended Posts

Posted

We are a G Suite cloud primary school, all the teachers and main staff do have their own laptops which they can take home, but the TA's have always just checked their emails or worked on the odd document from their own devices if needed while at home, they do have access to check from a school device while they are in school.

 

Today we had a governor say that this is not data compliant and they need to access their emails / documents from a school device, or have someone (me) setup and separate account on their device which they can use for school work, which obviously is not an option.

 

While I do agree a school should supply devices for the teachers to work on, I don't think the above issue is a data protection issue, but perhaps I am wrong.

 

My first thought is there are probably thousands of pupils logging in to G suite in the UK along with staff etc from home devices right now.

 

Any thoughts

Posted
just send them the quote for a device for each staff member they will soon change

Yep that will probably do it.

 

I just wanted to check there are no data protection issues with having the TA's login while at home from their personal devices, before I write a reply to the governor.

 

I am not going to block them from going down this road but want them to have all the facts before they do.

Posted

We have the rule where if everything is in the browser and you don't download everything, then you can use your own device it just needs to have AV etc on it.

If you want to save data there's a complicated approval procedure with a big checklist for using your own device.

 

I'd imagine GMail and Google Apps counts as "in the browser"? (We're 365 so we class Outlook Web and the Web versions of Word etc as permitted without the long procedure).

  • Thanks 3
Posted
We have the rule where if everything is in the browser and you don't download everything, then you can use your own device

 

that was my take on it, which is why we give the teachers and office staff a school laptop to take home as they do sometimes need to download files.

Posted (edited)
We are a G Suite cloud primary school, all the teachers and main staff do have their own laptops which they can take home, but the TA's have always just checked their emails or worked on the odd document from their own devices if needed while at home, they do have access to check from a school device while they are in school.

 

Today we had a governor say that this is not data compliant and they need to access their emails / documents from a school device, or have someone (me) setup and separate account on their device which they can use for school work, which obviously is not an option.

 

While I do agree a school should supply devices for the teachers to work on, I don't think the above issue is a data protection issue, but perhaps I am wrong.

 

My first thought is there are probably thousands of pupils logging in to G suite in the UK along with staff etc from home devices right now.

 

Any thoughts

 

I don't see how creating a separate account on a personal device is going to make it any safer. People will get fed up between swapping local desktop accounts and just end up using the one.

 

Whilst I do like the idea of having elevated accounts for certain admin procedure's and tasks that is a bit different.

Edited by Davit2005
  • Thanks 1
Posted
Today we had a governor say that this is not data compliant

 

Your Governor is very mistaken. It is data compliant, as its secure and encrypted. You can also audit who is downloading files and where they're downloading them too.

Now, if someone breaches by downloading from the platform, that's different but the platform itself, and anywhere access is absolutely, 100% data compliant.

 

setup and separate account on their device which they can use for school work

If it isn't data compliant on the device, it doesn't matter what profile on the device they're using. Your Governor is very, very mistaken here. All sounds a little bit Dunning-Kruger!

 

The answer is to set session lengths on accounts which enforce people having to sign-in again to verify their use.

https://support.google.com/a/answer/7576830?hl=en

 

And to audit your data for downloads, also using Shared Drives and disabling the ability to download files from them.

  • Thanks 4
Posted
Gsuite MDM policy applied to personal devices here. Users have to sign an agreement to allow us to manage the school account on their device which we then approve. Not a bad solution except that staff logins to gsuite apps on ipads leads to a jamf vs. gsuite MDM fight!
  • Thanks 1
Posted
Gsuite MDM policy applied to personal devices here. Users have to sign an agreement to allow us to manage the school account on their device which we then approve. Not a bad solution except that staff logins to gsuite apps on ipads leads to a jamf vs. gsuite MDM fight!

 

But which one's better? There's only one way to find out...

 

8oEF0tZxTYjdLPzvAUTok1noUF10Ri2GbbmGf31TAm5V5JkAy42X-awE6OpLFE1C4kZCoNhWemKv-L1b-ewkkgfvnCsQrP0puD5ikvkPzGkWDC53P6T1cUewqABC3XZS18OwvsBoPJd6_C4KNfrt2V-Ei24QDCp4-3PpVA

  • Thanks 1
Posted
Well, where to start. I guess it is good a governor is showing an interest, but the decision is operational and it's not for the governor to 'tell' anyone. There's useful advice already above, but I'd suggest completing a DPIA (see ICO site) and work through that to focus thinking in the right direction.
  • Thanks 2
Posted

We live in a cloud world now. There is no reason I can think of that staff cannot check email on a personal device.

 

We have suitable controls in place if they use a phone, in that we can delete their data remotely if we need to but that's about it.

 

The governor shouldn't be telling you how to do things anyway. They can provide advice, but you are not required to do what a governor says - they are not an employee, or a manager. They are governance. Operational decisions belong to the headteacher.

  • Thanks 1
Posted (edited)

Not really used it myself, but my understanding is that you could limit account logons to approved devices only. In the case of personally owned devices, that would require that the user install an Endpoint Verification agent and that an admin then approves that device (rejecting it if it's Windows XP, etc.). It's on my list of things to look into properly, so don't judge me too harshly if I've got this all wrong.

 

I understand where the OP's governor is coming from. It's all too easy for attachments to silently pile up in a Downloads folder, for instance.

Edited by jthompson
Posted
Not really used it myself, but my understanding is that you could limit account logons to approved devices only. In the case of personally owned devices, that would require that the user install an Endpoint Verification agent and that an admin then approves that device (rejecting it if it's Windows XP, etc.). It's on my list of things to look into properly, so don't judge me too harshly if I've got this all wrong.

I already have a list of users and the OS the access from, but have never installed endpoint software.

 

And how does Mr Governor check his?

This is the correct question, although I don't think it will ever get asked.

 

Force them to use RDS to access email with MFA. Or give the magic money tree a shake for devices.

All staff already have MFA for cloud access, and I'm not setting up a new server just so a TA can access her email over RDS :0).

Posted
Force them to use RDS to access email with MFA. Or give the magic money tree a shake for devices.

I don't see why RDS would be needed... they can just do it in the browser, MFA for added security - the only issue here is in the head of the governor who should not be giving operational instructions anyway as that's out of their remit.

Posted

Risk assessment it, then put in technical and organisational measures to reduce any risks.

It is not a yes/no thing.

 

It is about changing culture including home use.

 

The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on.

 

Operationally, you might get the same risk reduction by implementing a home-use policy with guidance for when working from home (a useful guide in present circumstances) including guidance on patching anti-virus/anti-malware products and so on.

 

It is worth saying that NCSC has good guidance to review to help with all this.

 

Instead of slapping the governor down, be glad that they are switched on to this. They are someone to work *with*, not against.

 

As always, if there is something specific you can PM.

  • Thanks 3
Posted
the only issue here is in the head of the governor who should not be giving operational instructions anyway as that's out of their remit.

 

This is the biggest FUBAR here. The Governor can make the suggestion but can't not implement or enforce it.

 

But as others have said, just ensure your MDM can check certain criteria, like the device has a password and/or is encrypted. If using InTune you can even be mean and not let copy and paste work!

Posted
The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on.

I am sure I would get a never ending stream of' I followed your instructions and now my home computers doesn't work, fix it now' calls doing this.

 

Operationally, you might get the same risk reduction by implementing a home-use policy with guidance for when working from home (a useful guide in present circumstances) including guidance on patching anti-virus/anti-malware products and so on.

This is something I was thinking of suggesting :0)

 

It is worth saying that NCSC has good guidance to review to help with all this.

Thanks, I will take a look

 

Instead of slapping the governor down, be glad that they are switched on to this. They are someone to work *with*, not against.

Not sure where you got this from, in my second post I pointed out I wanted the governor to have all the facts before they made their decision.

  • Thanks 1
Posted
We operate a similar policy, no staff are allowed to access work email on a personal device, we decided the risks were too high. Whilst there are technical ways to ensure doing this is secure and data compliant, since we already issue every member of staff with an ipad it was a simple decision for us.
Posted
MFA would be a good step towards risk reduction here particularly when off-site. It won't definitively stop anyone who really wants access but from a general point of view, a teacher's kid/other half/nosey parent isn't going to lop off a finger to circumvent this. We have MFA for all services accessed outside of school including email and there are very few if any issues even from the lesser savvy.
Posted

There's no way this idea would work here. Most teaching staff have emails set up on their (personal) phones, and we also have Educare accounts for all cleaning, maintenance & admin staff (who all have school email accounts but no school devices) so they'd be unable to do required KCSIE training.

 

Would be great for me if implemented though, as I would be forced to remove emails from my dual SIM phone - which I paid for - and also my home laptop, and not get any messages when away from my desk!

Posted

Not sure where you got this from, in my second post I pointed out I wanted the governor to have all the facts before they made their decision.

 

Definitely aimed at other responses and not you.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...