Jump to content

Recommended Posts

Posted

One of my first acts at my current job three years ago was to implement the blocking of writing to USB, staff can still read from them. This was very unpopular in concept but in practise the staff generally used them to read from far more that to write to. This coupled with the fact that all our teaching staff have VPN connected laptops allowed us to move fairly painlessly from writable removable devices.

 

We still allow removable devices to be read from which is a security hole but we judge this to be far smaller than email or various web based vectors but I could probably be able to remove this now with little fuss. I would like to be able to use USB myself occasionally when a student device has decided to not talk to the network after a student has done their work without saving as happens about one a term here but other than that we don't miss them.

 

There is some sort of strange compulsion in users to expose their data to as much risk as possible, I don't understand why they seem to insist on saving data in one location preferably one that can go through the washing machine.

Posted

Well, I've sent the email and had a surprisingly positive response from SLT...

 

How it goes in practise will be another thing I'm sure!

 

Just have to decide if Sophos can do everything I need or whether to start mucking about with GPOs and then testing everything that can be plugged in... and if I should actually allow read access (but then need a whole other set of things to deny nasties) for the Theatre Troupe that turns up with all their music on USB or the Youth Group the Family Workers have arranged with their PowerPoint presentation on a USB or....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...