Jump to content

Recommended Posts

Posted (edited)

I’ve just attended the JISC security conference sessions for day 1. The last session I attended today was ‘Cyber Essentials Clinic’. JISC offer Cyber Essentials drop-in clinics which I’m now planning to attend.

 

In this session, JISC notified us of changes to cyber essentials that will require us to report on just about all staff personal devices if they’re accessing organisational data in any form; whether this is O365 webmail, a web-based business system, through VPN/RDP, at home or mobile data. If they access this data, they're in scope. Student devices largely seemed out of scope as long as they're on their own network separate from staff BYOD devices.

 

In a nutshell, we need a record of the device’s model and operating system and to ensure it’s in support and it’s patched recently. We need to put in technical (or manual) measures to prevent uncompliant devices from accessing these services such as Conditional Access Filter for Devices or we fail Cyber Essentials.

 

This was quite the bombshell in the session for all of us attending.

 

Did anyone else attend or has had to implement these kind of controls on personal devices for cyber essentials? Seems like it’s going to be an absolute nightmare to implement.

Edited by georgeescott
Posted

I wonder if locking the information to never actually be on the device, or the document to be secure would be enough? I know with M365 you can set policies that stop the download of documents, users having to either use the online version or connect direct. You can use data protection tools to label data and prevent it being opened except by those with an organisational account.

 

If the device is never on your system, dumped straight out to Internet, then your system won't be compromised by personal devices. If the data and documents are secured, then they can't be compromised. Would still mean many systems would be unacceptable to be used though.

Posted
Did anyone point out that this is incredibly difficult and will make CE a massive non-starter for people?

 

It was, by many IT folk.

 

Although the supported and patched OS has always been a requirement for Cyber Essentials for personal devices accessing corporate data. But the change from IASME is that we now need a record of it, whereas before just an AUP stating these would have been enough.

 

- - - Updated - - -

 

I wonder if locking the information to never actually be on the device, or the document to be secure would be enough? I know with M365 you can set policies that stop the download of documents, users having to either use the online version or connect direct. You can use data protection tools to label data and prevent it being opened except by those with an organisational account.

 

If the device is never on your system, dumped straight out to Internet, then your system won't be compromised by personal devices. If the data and documents are secured, then they can't be compromised. Would still mean many systems would be unacceptable to be used though.

 

 

Unfortunately not, even web-based interfaces such as webmail will be covered under this as it's still accessing corporate information regardless of whether it's saved or not. See page 8 of https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-for-IT-infrastructure-2-2.pdf. There are ways to bypass protections from downloading e.g. screenshots, but it's definitely a risk-mitigation worth implementing.

 

I completely understand the need for having a supported and patched operating system, but accessing/controlling this typically requires registration in an MDM which some users will be very hesitant to do on personal devices I'm sure (plus the cost implications of any additional MDM licences).

Posted
It was, by many IT folk.

 

What was their reaction?

 

I must admit I've been putting off doing the CE stuff for a while and it is definitely a good idea in principle but this makes it unworkable and means lots of organisations will completely forget about it.

 

I get security is hard, I get there are compromises etc but they need to be realistic with their expectations.

Posted
What was their reaction?

 

I must admit I've been putting off doing the CE stuff for a while and it is definitely a good idea in principle but this makes it unworkable and means lots of organisations will completely forget about it.

 

I get security is hard, I get there are compromises etc but they need to be realistic with their expectations.

 

 

A lot of questions, confusion and unhappiness!

 

Yes, I agree, the principal is good and generally sets a good benchmark for organisations to aim for.

 

You can still carry out limited scopes (or now called 'subsets') for your cyber essentials assessment, so you could accredit just the finance department and their BYOD devices versus the entire institution if you wanted to. But many require the full scope for cyber insurance, grants or other compliance reasons so this wont be an option to them. JISC are expecting a rise in assessments for 'subsets' following this change.

 

JISC are working with the NCSC/IASME so hopefully feedback from the community will reach back about this. Perhaps it could be implemented just for CE+ and not the standard certification as a compromise.

Posted (edited)

Did anyone else attend or has had to implement these kind of controls on personal devices for cyber essentials? Seems like it’s going to be an absolute nightmare to implement.

 

Not concerned about cyber essentials but I have implemented this to meet other requirements. It's really not that onerous. If you're using Office 365, require Intune (conditional access can be set to require devices users connect from to be marked as compliant, for example), create a light-touch compliance and configuration policy for BYOD, go to lunch because you're done.

 

Intune (or any other MDM these days) will then gather the data you need, as well as helping secure access to your data..

Edited by Roberto
  • Thanks 1
Posted
Not concerned about cyber essentials but I have implemented this to meet other requirements. It's really not that onerous. If you're using Office 365, require Intune (conditional access can be set to require devices users connect from to be marked as compliant, for example), create a light-touch compliance and configuration policy for BYOD, go to lunch because you're done.

 

Intune (or any other MDM these days) will then gather the data you need, as well as helping secure access to your data..

 

That's true, Intune does make that part easy. I'm 100% for it, we need to secure the devices our users are accessing our data on.

 

My concern is the non-Microsoft services that can't be enforced via Intune, and the initial setup and backlash from hundreds of staff we'll have to enforce this on. Apple's User Enrolment method is still in preview for Intune so once that's released that should quell some privacy concerns from some staff. Android 'work profile' has been supported by Intune for some time so that makes life easier.

 

Cyber essentials requires personal devices accessing corporate data via RDP and other corporate web-based systems to be in scope. This isn't as simple as enabling a conditional access policy like it is for O365 services unfortunately. Perhaps Azure AD Application Proxy may be the saviour here for some systems. Others... idk, perhaps a combination of policy and technology.

Posted
Having gone through CE and CE+ this actually makes sense. Logically you must move to 1:1 devices for staff and limit business data apps to organisational owned devices. This can be done with conditional access polices and hybrid azure joined devices. Given the increase in Ransomware the backlash from staff can no longer be a block to a more secure environment.
Posted
Having gone through CE and CE+ this actually makes sense. Logically you must move to 1:1 devices for staff and limit business data apps to organisational owned devices. This can be done with conditional access polices and hybrid azure joined devices. Given the increase in Ransomware the backlash from staff can no longer be a block to a more secure environment.

 

I wish we could! 1:1 devices for staff would be the dream. The free DfE devices aren’t great in terms of performance but could offer us an alternative to those who don’t have personal devices at home or who refuse to have Intune.

 

Absolutely, it could cost well in to the hundreds of thousands if not millions to fully recover from a ransomware attack. Security has to be the priority. Just might be a bumpy road to get there!

Posted
Others... idk, perhaps a combination of policy and technology.

 

Policy absolutely needs to be a part of whatever solution you work towards. I sympathise with people who don’t want controls on their personal phone, I’ve opted into a corporate one where I work precisely to maintain this separation myself. However (and this is where policy comes in), you’re not requiring them to have the controls on their personal device regardless, you’re simply mandating their use when people want to access your organisation’s data. If they don’t want one, that’s fine, but they cannot then have the other,

Posted (edited)

Thinking about this further (FE and HE), MIS systems where staff and students login might got need some conditional access for each group. VLEs may be the same. This of course assumes you have all your authentication going through AzureAD.

 

1:1 isn’t strictly needed but I think it comes back to the remote working question for staff.

 

I think a RDS gateway is the other way around it but I’m guessing the client device the user uses needs to be a supported OS with some sort of check.

 

I guess the other option is to exclude personal devices from scope.

Edited by free780
Posted
I wish we could! 1:1 devices for staff would be the dream. The free DfE devices aren’t great in terms of performance but could offer us an alternative to those who don’t have personal devices at home or who refuse to have Intune.

 

I really don't think that's what the DfE devices are for. They're for families who have little or no technology at home which is preventing students from accessing their learning. The DfE laptops are not for giving to staff who want to check their email at weekends but don't want MDM on their phone.

 

Our teachers and key business staff all have laptops (there are no teacher computers in classrooms, so we're not doubling up on devices), other staff have access to desktops or laptops in school and no business need to access resources outside of school.

Posted

I watched the session from JISC. I can honestly see ISO27001 or a different compliance standard become the norm for education.

 

The steps they described from a technical point of view are not too much work if you have AAD and A3/A5 configured.

 

Yes it will annoy staff; however when your funding relies on CE compliance you have to comply.

 

Given the threat landscape government bodies will put pressure on education to achieve CE and CE+ currently.

 

The other area that will be difficult is monitoring personal devices that connect to a RDS gateway when not accessed via the Azure App Proxy. Limiting this for Staff to Staff Devices may be a way to mitigate this.

Posted
All sounds very interesting and very Microsoft friendly. Not so much of your A Google school...

 

I'm talking in Microsoft terms myself because I'm an O365 expert these days and its the language I speak. I'm assuming Google have their own equivilent to most or all of this functionality? I could also do all this stuff in Okta, for example, so I'd expect it from any decent featured IdP.

Posted
I'm talking in Microsoft terms myself because I'm an O365 expert these days and its the language I speak. I'm assuming Google have their own equivilent to most or all of this functionality? I could also do all this stuff in Okta, for example, so I'd expect it from any decent featured IdP.

 

As far as I can see, this would come under Google's "Context-Aware Access", which is only available in the paid versions it seems. So, if we were to go down the CE route, we'd end up having to license Google Workspace Education Plus.

  • 2 months later...
Posted
Now the dust has settled a little on this change to CE, what are peoples thoughts on how they are going to implement this. I think for this year we will go from being fully compliant to only a subset, just what's needed for funding to be fully covered. Once they review the new question set, fingers crossed ESFA and others stop using CE as a guide on establishments cyber resiliency. I'm just in the process of creating a paper for SLT on some expensive NAC solutions, a policy based approach, or an MDM, intune? where if staff which to connect to our network they need to jump through a few hoops to gain access. In terms of cloud and remote access to resources, hopefully Azure Application Proxy will work for most. BYOD is risky and in fairness this has made me look at how we allow this.
Posted (edited)

I did some work on Windows only in terms of personal devices.

 

Just AAD Registered doesn't give the make,model of the device which is the CE requirement.

 

A MAM-WE approach (Mobile Application Management Without Enrolment) can provide Windows Information Protection which can stop copy and paste of business data. However the Make and Model are not gathered.

 

A MDM join sends the Make and Model to Intune satisfying the CE requirement.

 

It may be easier to block access on Windows unless it's a organisational device. Possible if you have 1:1 devices for staff.

 

You may be able to book access via conditional access and device filter after your IT department has got a record of the device. I imagine most departments won't have the staff to make this happen.

 

There is also the issue of Remote Desktop Gateway which won't be subject to Condional Access policies if your not using the HTML5 rdp client.

 

Mobile devices are more difficult. MAM -WE may gather more info on Android and IOS. You probably need to enforce the Intune app and Organisational versions of Outlook,Onedrive etc.

 

I don't see any point reducing the scope as this will lessen security as a whole.

 

I can't see funding getting away from the requirement and some other contracts are requiring it in FE/HE.

 

Personal Devices are a risk from a data loss point of view as well. So probably disabling copy and paste and download from organisational apps is wise.

 

There is also the issue of work life balance and having work emails on your phone can disrupt this.

 

I imagine a lot of push back when schools/colleges/universities implement this.

 

I wish we had budget to issue each staff member a phone and laptop (if role requires it).

Edited by free780
  • Thanks 1
  • 5 months later...
Posted

Afternoon, Sorry for bit of a necro, But Ive just started going though the paper work and come across the BYOD / Personal device issue everyone seems to be talking about

(picked up from reading the Cyber Essentials:Requirements for IT infrastructure document)

 

Our Staff are 1:1 devices, but do we need to count students as well? Technically they do access things like email, and shared drives? (though nothing that would be considered Business specific MIS/Finance etc)

It seemed in the requirement document we should include ALL users?

but students? really?

 

Thoughts?

Posted
Afternoon, Sorry for bit of a necro, But Ive just started going though the paper work and come across the BYOD / Personal device issue everyone seems to be talking about

(picked up from reading the Cyber Essentials:Requirements for IT infrastructure document)

 

Our Staff are 1:1 devices, but do we need to count students as well? Technically they do access things like email, and shared drives? (though nothing that would be considered Business specific MIS/Finance etc)

It seemed in the requirement document we should include ALL users?

but students? really?

 

Thoughts?

 

According to IASME students are your customers so are not in scope. Ideally your customers should be on a seperate vlan etc.

 

So unless you have lots of staff you basically need to enforce MDM for Staff personal phones and tablets.

 

If you have 1:1 I'd just ban personal Windows and Mac.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...