Jump to content

Recommended Posts

Posted

Hi Everyone,

 

Our schools SCR is kept in a network share that is only available to the appropriate staff. The NTFS permissions are deny all unless you are a specific user. The file is password protected and backed up via a standard 321 methodology.

 

I have been asked if this is sufficient security, and as a result I am keen to know what others are doing?

Posted

Ours is stored in Google Drive, and shared with appropriate level permissions for individuals that need access. Ofsted were happy with this when one of our schools was last inspected.

 

The security you have in place seems fine to me. It is limited in access, has an extra layer of password security (and I'm guessing that as it is password protected, its an Excel file, so has its own built in encryption too). What sort of extra security is whoever is asking thinking on top?

  • Thanks 2
Posted

That is plentiful, security wise.

Like everything the security should be there, but it shouldn't get in the way of the functionality and usage.

I honestly can't see what more you should be expected to do.

  • Thanks 1
Posted
That seems fine to me. Migrating it to a Google or O365 native document might simplify things though, and lessen the risk of somebody storing a copy of somewhere less secure.
  • Thanks 1
Posted
I have been asked if this is sufficient security

 

I'm curious what more security they would like on the document than what you've already done! You might want to question the security of the password itself - where is the password for the document? How many people know it? Is it frequently changed? How are changes communicated? Is it written on Post-It notes on people's desks?

  • Thanks 1
Posted

If the document was breached and it was reported as a personal data breach then I'd be looking at the security of the document itself, but also the wider security considerations. For example, some of the areas I'd touch on would include:

 

Governance/ISMS: I would be looking at the types of information security policies in place - were senior management directing and taking ownership for the minimum levels of security required, for example, via authorised policies. How often were the policies reviewed, how were they communicated to staff. What roles decides what 'appropriate security' looks like within the school - how was this defined, who decides this, who has ultimate sign-off. Were IT staff given risk tolerance levels to work with - what was the risk tolerance level on the SCR, where was this documented.

 

Classification Policy - I'd be looking at how you classified the data you processed, for example, via a classification policy. Was the classification based on the sensitivity of the data, did the school recognise different personal data requires different levels of security, did the classification level recognise special category data as a higher classification level. What did this mean for security, for example, did data classified as a higher level require additional levels of protection. If so, what were these additional layers (encryption, stronger detection controls etc). What level of classification was the SCR at? Where was this defined.

 

Asset Management - how did the school manage it assets that processed the SCR, was the underlying host OS in support, was it patched and up to date, how did the school manage the lifecycle of assets processing the SCR, who authorised where the SCR could be stored - was the asset appropriate for the SCR

 

Technical Control Selection - what technical controls were applied on the host such as AV/Endpoint protection, allow/deny lists, DLP etc. I'd be splitting this up into preventive and detective controls. For example - could you detect if an unauthorised actor tried to access the document? Could you detect malicious software on the host, did the server have out-going internet access - if so, did it require it? Could you detect the SCR being exfiltrated/copied

 

Access Controls - how did you manage access controls, did you follow the principles of least privilege, was there a policy in place that directed this? How were privileged accounts protected?

 

Risk Management - how did you identify threats to the asset/SCR - was a risk assessment on the asset done, who had final authorisation the asset/SCR was appropriately protected

 

Testing, Reviews and Assurance - what kind of assurance did senior management require that the SCR was appropriately secured - eg Word of mouth, written report, internal audit, external audit, accreditation against Cyber Essentials etc. Who was responsible for ensuring the document was kept up to date, retention policies, were roles and responsibilities defined. How often were access controls reviewed for privileged creep etc, how did you identify vulnerabilities on the hosts

 

Disaster Recovery - what was the backup architecture in place, how often was this tested, when was the last time a test restore was carried out, could a malicious actor access the backup if it was to compromise a privileged account, what would the risks of this be,

 

Staff Education - did staff who assessed the document require any additional training on the sensitivity of the file? If so, what training, how often,

 

It would not necessarily be the case that a negative answer therefore means non-compliance. For example, you might determine the annual 'data protection training' was an appropriate level of training and the staff that accessed the SCR did not need additional training above this. But these are some of the areas that I would potentially explore, depending on how bad the breach was.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...