msi_school Posted January 5, 2022 Posted January 5, 2022 One of my first acts at my current job three years ago was to implement the blocking of writing to USB, staff can still read from them. This was very unpopular in concept but in practise the staff generally used them to read from far more that to write to. This coupled with the fact that all our teaching staff have VPN connected laptops allowed us to move fairly painlessly from writable removable devices. We still allow removable devices to be read from which is a security hole but we judge this to be far smaller than email or various web based vectors but I could probably be able to remove this now with little fuss. I would like to be able to use USB myself occasionally when a student device has decided to not talk to the network after a student has done their work without saving as happens about one a term here but other than that we don't miss them. There is some sort of strange compulsion in users to expose their data to as much risk as possible, I don't understand why they seem to insist on saving data in one location preferably one that can go through the washing machine.
Koldov Posted January 5, 2022 Posted January 5, 2022 Well, I've sent the email and had a surprisingly positive response from SLT... How it goes in practise will be another thing I'm sure! Just have to decide if Sophos can do everything I need or whether to start mucking about with GPOs and then testing everything that can be plugged in... and if I should actually allow read access (but then need a whole other set of things to deny nasties) for the Theatre Troupe that turns up with all their music on USB or the Youth Group the Family Workers have arranged with their PowerPoint presentation on a USB or....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now