TwistedHelixis Posted November 25, 2020 Posted November 25, 2020 We are a G Suite cloud primary school, all the teachers and main staff do have their own laptops which they can take home, but the TA's have always just checked their emails or worked on the odd document from their own devices if needed while at home, they do have access to check from a school device while they are in school. Today we had a governor say that this is not data compliant and they need to access their emails / documents from a school device, or have someone (me) setup and separate account on their device which they can use for school work, which obviously is not an option. While I do agree a school should supply devices for the teachers to work on, I don't think the above issue is a data protection issue, but perhaps I am wrong. My first thought is there are probably thousands of pupils logging in to G suite in the UK along with staff etc from home devices right now. Any thoughts
round2it Posted November 25, 2020 Posted November 25, 2020 just send them the quote for a devicefor each staff member they will soon change 2
TwistedHelixis Posted November 25, 2020 Author Posted November 25, 2020 just send them the quote for a device for each staff member they will soon change Yep that will probably do it. I just wanted to check there are no data protection issues with having the TA's login while at home from their personal devices, before I write a reply to the governor. I am not going to block them from going down this road but want them to have all the facts before they do.
Katy Posted November 25, 2020 Posted November 25, 2020 We have the rule where if everything is in the browser and you don't download everything, then you can use your own device it just needs to have AV etc on it. If you want to save data there's a complicated approval procedure with a big checklist for using your own device. I'd imagine GMail and Google Apps counts as "in the browser"? (We're 365 so we class Outlook Web and the Web versions of Word etc as permitted without the long procedure). 3
TwistedHelixis Posted November 25, 2020 Author Posted November 25, 2020 We have the rule where if everything is in the browser and you don't download everything, then you can use your own device that was my take on it, which is why we give the teachers and office staff a school laptop to take home as they do sometimes need to download files.
Davit2005 Posted November 25, 2020 Posted November 25, 2020 (edited) We are a G Suite cloud primary school, all the teachers and main staff do have their own laptops which they can take home, but the TA's have always just checked their emails or worked on the odd document from their own devices if needed while at home, they do have access to check from a school device while they are in school. Today we had a governor say that this is not data compliant and they need to access their emails / documents from a school device, or have someone (me) setup and separate account on their device which they can use for school work, which obviously is not an option. While I do agree a school should supply devices for the teachers to work on, I don't think the above issue is a data protection issue, but perhaps I am wrong. My first thought is there are probably thousands of pupils logging in to G suite in the UK along with staff etc from home devices right now. Any thoughts I don't see how creating a separate account on a personal device is going to make it any safer. People will get fed up between swapping local desktop accounts and just end up using the one. Whilst I do like the idea of having elevated accounts for certain admin procedure's and tasks that is a bit different. Edited November 25, 2020 by Davit2005 1
paulkerton Posted November 25, 2020 Posted November 25, 2020 Today we had a governor say that this is not data compliant Your Governor is very mistaken. It is data compliant, as its secure and encrypted. You can also audit who is downloading files and where they're downloading them too. Now, if someone breaches by downloading from the platform, that's different but the platform itself, and anywhere access is absolutely, 100% data compliant. setup and separate account on their device which they can use for school work If it isn't data compliant on the device, it doesn't matter what profile on the device they're using. Your Governor is very, very mistaken here. All sounds a little bit Dunning-Kruger! The answer is to set session lengths on accounts which enforce people having to sign-in again to verify their use. https://support.google.com/a/answer/7576830?hl=en And to audit your data for downloads, also using Shared Drives and disabling the ability to download files from them. 4
southhamster Posted November 25, 2020 Posted November 25, 2020 Gsuite MDM policy applied to personal devices here. Users have to sign an agreement to allow us to manage the school account on their device which we then approve. Not a bad solution except that staff logins to gsuite apps on ipads leads to a jamf vs. gsuite MDM fight! 1
paulkerton Posted November 25, 2020 Posted November 25, 2020 Gsuite MDM policy applied to personal devices here. Users have to sign an agreement to allow us to manage the school account on their device which we then approve. Not a bad solution except that staff logins to gsuite apps on ipads leads to a jamf vs. gsuite MDM fight! But which one's better? There's only one way to find out... 1
Ditto Posted November 25, 2020 Posted November 25, 2020 Well, where to start. I guess it is good a governor is showing an interest, but the decision is operational and it's not for the governor to 'tell' anyone. There's useful advice already above, but I'd suggest completing a DPIA (see ICO site) and work through that to focus thinking in the right direction. 2
localzuk Posted November 25, 2020 Posted November 25, 2020 We live in a cloud world now. There is no reason I can think of that staff cannot check email on a personal device. We have suitable controls in place if they use a phone, in that we can delete their data remotely if we need to but that's about it. The governor shouldn't be telling you how to do things anyway. They can provide advice, but you are not required to do what a governor says - they are not an employee, or a manager. They are governance. Operational decisions belong to the headteacher. 1
jthompson Posted November 25, 2020 Posted November 25, 2020 (edited) Not really used it myself, but my understanding is that you could limit account logons to approved devices only. In the case of personally owned devices, that would require that the user install an Endpoint Verification agent and that an admin then approves that device (rejecting it if it's Windows XP, etc.). It's on my list of things to look into properly, so don't judge me too harshly if I've got this all wrong. I understand where the OP's governor is coming from. It's all too easy for attachments to silently pile up in a Downloads folder, for instance. Edited November 25, 2020 by jthompson
strawberry Posted November 25, 2020 Posted November 25, 2020 emails / documents from a school device, Any thoughts And how does Mr Governor check his?
mavhc Posted November 25, 2020 Posted November 25, 2020 If you have spyware on your home computer then someone in the world could be reading every email easily. And you'd never know.
free780 Posted November 25, 2020 Posted November 25, 2020 Force them to use RDS to access email with MFA. Or give the magic money tree a shake for devices.
TwistedHelixis Posted November 25, 2020 Author Posted November 25, 2020 Not really used it myself, but my understanding is that you could limit account logons to approved devices only. In the case of personally owned devices, that would require that the user install an Endpoint Verification agent and that an admin then approves that device (rejecting it if it's Windows XP, etc.). It's on my list of things to look into properly, so don't judge me too harshly if I've got this all wrong. I already have a list of users and the OS the access from, but have never installed endpoint software. And how does Mr Governor check his? This is the correct question, although I don't think it will ever get asked. Force them to use RDS to access email with MFA. Or give the magic money tree a shake for devices. All staff already have MFA for cloud access, and I'm not setting up a new server just so a TA can access her email over RDS :0).
Katy Posted November 25, 2020 Posted November 25, 2020 Force them to use RDS to access email with MFA. Or give the magic money tree a shake for devices. I don't see why RDS would be needed... they can just do it in the browser, MFA for added security - the only issue here is in the head of the governor who should not be giving operational instructions anyway as that's out of their remit.
GrumbleDook Posted November 26, 2020 Posted November 26, 2020 Risk assessment it, then put in technical and organisational measures to reduce any risks. It is not a yes/no thing. It is about changing culture including home use. The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on. Operationally, you might get the same risk reduction by implementing a home-use policy with guidance for when working from home (a useful guide in present circumstances) including guidance on patching anti-virus/anti-malware products and so on. It is worth saying that NCSC has good guidance to review to help with all this. Instead of slapping the governor down, be glad that they are switched on to this. They are someone to work *with*, not against. As always, if there is something specific you can PM. 3
TechMonkey Posted November 26, 2020 Posted November 26, 2020 the only issue here is in the head of the governor who should not be giving operational instructions anyway as that's out of their remit. This is the biggest FUBAR here. The Governor can make the suggestion but can't not implement or enforce it. But as others have said, just ensure your MDM can check certain criteria, like the device has a password and/or is encrypted. If using InTune you can even be mean and not let copy and paste work!
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on. I am sure I would get a never ending stream of' I followed your instructions and now my home computers doesn't work, fix it now' calls doing this. Operationally, you might get the same risk reduction by implementing a home-use policy with guidance for when working from home (a useful guide in present circumstances) including guidance on patching anti-virus/anti-malware products and so on. This is something I was thinking of suggesting :0) It is worth saying that NCSC has good guidance to review to help with all this. Thanks, I will take a look Instead of slapping the governor down, be glad that they are switched on to this. They are someone to work *with*, not against. Not sure where you got this from, in my second post I pointed out I wanted the governor to have all the facts before they made their decision. 1
Boredguy Posted November 26, 2020 Posted November 26, 2020 TwistedHelixis I think that last bit might have been aimed at some of the other replies more so than yours
steveg Posted November 26, 2020 Posted November 26, 2020 We operate a similar policy, no staff are allowed to access work email on a personal device, we decided the risks were too high. Whilst there are technical ways to ensure doing this is secure and data compliant, since we already issue every member of staff with an ipad it was a simple decision for us.
synaesthesia Posted November 26, 2020 Posted November 26, 2020 MFA would be a good step towards risk reduction here particularly when off-site. It won't definitively stop anyone who really wants access but from a general point of view, a teacher's kid/other half/nosey parent isn't going to lop off a finger to circumvent this. We have MFA for all services accessed outside of school including email and there are very few if any issues even from the lesser savvy.
smurfomatic Posted November 26, 2020 Posted November 26, 2020 There's no way this idea would work here. Most teaching staff have emails set up on their (personal) phones, and we also have Educare accounts for all cleaning, maintenance & admin staff (who all have school email accounts but no school devices) so they'd be unable to do required KCSIE training. Would be great for me if implemented though, as I would be forced to remove emails from my dual SIM phone - which I paid for - and also my home laptop, and not get any messages when away from my desk!
GrumbleDook Posted November 26, 2020 Posted November 26, 2020 Not sure where you got this from, in my second post I pointed out I wanted the governor to have all the facts before they made their decision. Definitely aimed at other responses and not you.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now