Ditto Posted November 26, 2020 Posted November 26, 2020 Think I'm in the clear stating "...it is good a governor is showing an interest". Removing tongue from cheek, I think the important point is working with the governors. The boundary between operational and strategic in schools is a topic that would fill a thread elsewhere, but what works at my school is via the link governor. I am a link governor with the IT staff member on IT and data security. This allows for deeper technical discussions and I can offer my wider experience and expertise. We do talk on operational matter - not to do so would be wasting value I can offer (being modest here, I know). But, at the point of deliver, it will be the IT employee that takes it forward. 1
elsiegee40 Posted November 26, 2020 Posted November 26, 2020 Think I'm in the clear stating "...it is good a governor is showing an interest". Removing tongue from cheek, I think the important point is working with the governors. The boundary between operational and strategic in schools is a topic that would fill a thread elsewhere, but what works at my school is via the link governor. I am a link governor with the IT staff member on IT and data security. This allows for deeper technical discussions and I can offer my wider experience and expertise. We do talk on operational matter - not to do so would be wasting value I can offer (being modest here, I know). But, at the point of deliver, it will be the IT employee that takes it forward. I completely agree... and I have this particular T shirt too. 1
paulkerton Posted November 26, 2020 Posted November 26, 2020 (edited) The suggestion of a separate user account on the home device (PC/Laptop) is a common technical way of reducing the risk as you know that other house members are not likely to be accessing that account, so as a risk treatment your governor is right. He might also suggest device encryption, that no other account has admin rights on there and so on. I mean, at a basic level that would be sound, however you're also asking users to use a different password than their main account, or even keep the password in place, or remember to log off. You know that won't happen. You're better placed by enforcing regular password challenges. Encryption is also fruitless. Once the device is on, it doesn't matter that it's encrypted if the issue is other members of the household accessing things when they shouldn't. That's like locking the door once the burglar is inside your house. No amount of technical solutions will stop someone being negligent with their account access around other members of the family. If the worry is the device will be stolen or dropped, then yes. Encryption. But that isn't the issue here. Thought encryption as standard should be your goal, all the data that is stored in the cloud will be encrypted until use anyway. You've got a technical measure in place there. Asking for it to be enabled on indiviual user devices is almost certainly just papering over the cracks and swinging technical jargon in the hope the ICO won't see through it. I can imagine what I'd say to you as a user if you told me that you were encrypting my device that I purchased, and locking out admin rights and assuming them for yourself... The second word would be off Edited November 26, 2020 by paulkerton
TechMonkey Posted November 26, 2020 Posted November 26, 2020 Totally agree with you both. I had a long conversation with a Governor that is an electrical engineer and has a deep interest in IT, data security and Disaster Recovery and as he worked in the oil industry he had an interesting viewpoint. It was a very good discussion, though I had to keep pointing out that we were a school not an oil platform! The issue is a Governor directly telling staff what they can and cannot do. I remember in a previous life a head getting quite frustrated that they had to edit Governor observations as they were commenting on teaching and operational matters, when all they were there to do was comment on the generalities and resources, not rate the teacher or their teaching. A two page report was cut down to a paragraph one time.
AJWright Posted November 26, 2020 Posted November 26, 2020 Surely, providing the email is not downloaded to the device, there is no GDPR breach. If they download information, and then the device is stolen, that's a potential data breach. Personally, I'm slightly paranoid about data theft, so my hard disks are all encrypted as are any memory sticks and flash drives
mavhc Posted November 26, 2020 Posted November 26, 2020 Anything you see on screen is downloaded to your computer, it's in ram in some form
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 Anything you see on screen is downloaded to your computer, it's in ram in some form Doesn't really make a difference if that is on a personal device or work device, I could even take a photo of the screen if I wanted. 1
jthompson Posted November 26, 2020 Posted November 26, 2020 Anything you see on screen is downloaded to your computer, it's in ram in some form This. Whilst we're arguably getting into more obscure threat models, the principle of the thing it that school data is ending up on personal devices, devices which could be miles out of date, riddled with malware and running with dozens of garbage browser extensions. Perhaps even syncing their downloaded files off into DropBox/iCloud/Google/OneDrive to be exposed elsewhere in years to come. The point is, you can't really determine any of that without some kind of endpoint management going on. The low-hanging fruit, though, is the sort of "sensible guidance" for staff that has already been suggested in this thread. Like with a lot of things, it's probably best to start there before heading down any technological rabbit holes.
mavhc Posted November 26, 2020 Posted November 26, 2020 it's mostly the loss of mass data that GDPR is about, so don't put mass data in emails. Don't have mass data in files at all, that's what your MIS is for 2
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 This. Whilst we're arguably getting into more obscure threat models, the principle of the thing it that school data is ending up on personal devices, devices which could be miles out of date, riddled with malware and running with dozens of garbage browser extensions. So are you saying pupils that are also logging into Google Classroom or Office 365 should not be working from home. Perhaps even syncing their downloaded files off into DropBox/iCloud/Google/OneDrive to be exposed elsewhere in years to come. Is this not a user policy issue? Anyone can do anything to any file even on school devices, as a school you must make sure people are aware of what they should not be doing, not making it impossible for anyone to work. 1
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 Whilst we're arguably getting into more obscure threat models, the principle of the thing it that school data is ending up on personal devices, devices which could be miles out of date, riddled with malware and running with dozens of garbage browser extensions. Cloud based system mitigate most of these issues anyway. 1
mavhc Posted November 26, 2020 Posted November 26, 2020 So are you saying pupils that are also logging into Google Classroom or Office 365 should not be working from home. pupils don't have access to mass personal data about others
paulkerton Posted November 26, 2020 Posted November 26, 2020 pupils don't have access to mass personal data about others Don't they? I'm assuming your pupils have never done a survey as part of coursework then?
mavhc Posted November 26, 2020 Posted November 26, 2020 They should have been instructed to not ask questions involving PII information if so. And to not give out their address to random people
paulkerton Posted November 26, 2020 Posted November 26, 2020 They should have been instructed to not ask questions involving PII information if so. And to not give out their address to random people Oh so we rely on instructions and guidelines for the children when handling that kind of information, but we must use technological solutions with the staff that make life harder, even though everything in place is already compliant. Got it. 👍🙄
synaesthesia Posted November 26, 2020 Posted November 26, 2020 Wow, chill. Some simple facts - we have an obligation from our job to our organisation to ensure the safety of the personal data we record and process. The governor wants to ensure this is the case and appears to have put across a request, maybe not in the best way but no doubt would want reassurance to see what steps are being taken to mitigate and minimise risk. They may not have all the facts, they are not the experts; not in the IT or the data protection side of things. We are aware of the data protection requirements, but are the experts in the IT side. It is therefore our job to educate and inform. All of this information should be recorded by the school anyway as to what data they hold, why they hold it, who has access to it and what steps are taken to reduce risk of a DPA issue. The governor I believe should be able to see this information if requested and it would then be prudent to find out what parts they would like adjusting and why. They probably have good intention but not the realisation of what it means. Keep communication up, speak to the people involved and that certainly includes your DPO and make sure all those people are correctly informed.
jthompson Posted November 26, 2020 Posted November 26, 2020 Is this not a user policy issue? Anyone can do anything to any file even on school devices, as a school you must make sure people are aware of what they should not be doing, not making it impossible for anyone to work. It's not entirely a user policy issue, though. I certainly agree that our job should not make life unduly difficult for other staff, but school machines are often going to have in place policies to restrict writing to removable media, prevent installation of unapproved software, etc. A large part of the reason for doing things like that is to enforce, by technical means, an acceptable use policy that staff may very well be adhering to regardless. That can be done without making it impossible for people to do their job, yet at the same time it protects them from dropping a USB full of class lists in the local supermarket or ending up with a tonne of documents on DropBox by accident. As technology develops, those sorts of mistakes can become easier for people to make. I'm not advocating a hard approach of prohibiting any access from personal devices (and certainly not for pupils, whose accounts are a much lower data protection risk than staff) but where and when it becomes possible to reinforce voluntary adherence on those devices with technical enforcement, that ought to be considered. That's really the point I wanted to make.
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 but school machines are often going to have in place policies to restrict writing to removable media, prevent installation of unapproved software, etc. A large part of the reason for doing things like that is to enforce, by technical means, an acceptable use policy that staff may very well be adhering to regardless. That can be done without making it impossible for people to do their job, yet at the same time it protects them from dropping a USB full of class lists in the local supermarket or ending up with a tonne of documents on DropBox by accident. As technology develops, those sorts of mistakes can become easier for people to make. I'm not advocating a hard approach of prohibiting any access from personal devices (and certainly not for pupils, whose accounts are a much lower data protection risk than staff) but where and when it becomes possible to reinforce voluntary adherence on those devices with technical enforcement, that ought to be considered. That's really the point I wanted to make. OK but aren't a lot of these issues actually overcome because a user is using a cloud based system, for example I have cloud based drives for the TA's that are read-only and actually block downloading of the files, printing is also blocked, those files will always be under our control and will never end up in dropbox by mistake. 1
mavhc Posted November 26, 2020 Posted November 26, 2020 Never is a long time A computer lets you make more mistakes faster than any invention in human history
TwistedHelixis Posted November 26, 2020 Author Posted November 26, 2020 Never is a long time A computer lets you make more mistakes faster than any invention in human historyI'll just insert the word 'probably', lol.
enjay Posted November 30, 2020 Posted November 30, 2020 OK but aren't a lot of these issues actually overcome because a user is using a cloud based system, for example I have cloud based drives for the TA's that are read-only and actually block downloading of the files, printing is also blocked, those files will always be under our control and will never end up in dropbox by mistake. Until someone screen-grabs what they need because you prevented them downloading or printing it. Introduce inconvenient security and people will work to circumvent it so they can do their jobs. Technical measures are good, but they must come with education and guidance - much the same as how we teach students about online safety. In my opinion, students being able to access from phones is essential. I know students don't have access to the same information as staff so in that sense it is different, but unless G Suite/Office365 can allow students to use mobile apps but not staff, you'd be severely impacting T&L if you block access from personal devices. Going back to the OP, has anyone asked why the TAs are accessing their email at home? Are they paid/expected to do so? Why aren't/can't they access in school?
TwistedHelixis Posted November 30, 2020 Author Posted November 30, 2020 Going back to the OP, has anyone asked why the TAs are accessing their email at home? Are they paid/expected to do so? Why aren't/can't they access in school? I have a feeling this is more a lockdown issue and not something the TA's are normally doing. Introduce inconvenient security and people will work to circumvent it so they can do their jobs. Yep, the list is endless, I could take a photo of a document, print a document out to take home etc.
enjay Posted November 30, 2020 Posted November 30, 2020 Yep, the list is endless, I could take a photo of a document, print a document out to take home etc. Photograph the screen on your phone then email it to your spouse (not an employee of the school) so you can view it larger on their iPad alongside your laptop. I think that is my personal favourite. Plus lots of data printed in school and taken home hard copy "in case it is needed", sometimes by teachers who are also parents of children in the school.
GrumbleDook Posted November 30, 2020 Posted November 30, 2020 it's mostly the loss of mass data that GDPR is about, so don't put mass data in emails. Don't have mass data in files at all, that's what your MIS is for It is so much more than that. It is about data protection, privacy, Rights and requirements ... but above all, it is about Rights. 1
chazzy2501 Posted November 30, 2020 Posted November 30, 2020 I'd of thought an MDM policy would be enough, ensure remote wipe is available and the device is password protected. This should be enough.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now