Jump to content

Recommended Posts

Posted

We are running for Cyber Essentials at school and everything is looking compliant except for our staff BYOD / Mobile Devices.

 

Our CE consultancy as said we have 2 options....

 

1) have a school policy that says no BYOD devices on the network with includes accessing Microsoft 365 / any school cloud services, even while on trips or at home.

2) introduce a MDM and have a management profile on the staff personal devices to dictate security requirements for example 6 digit pin.

 

According to our CE consultancy these are our only options, to us this seems a tad ridiculous!

 

 

How do you do this?.... We need some help from other schools with CE!

 

THANK YOU.

Posted
Either option 2 or provide a mobile device for each staff member who requires it to fulfil their role. The most difficult part is to keep track of the manufacturer, model and OS of personal devices. A MDM provides this.The enrolment method that apple and google want you to use means that work apps are segregated. In some ways the requirements are a bit out of date. You can use MAM and put controls on apps and the underlying OS and hardware are not as relevant. In theory vulnerabilities could be present.
Posted

Do you have guest wifi?

 

If you have guest wifi and it is provided through a seperate VLAN and seperate broadband link with seperate filtering like we do (WIFI Spark) - any device on that becomnes out of scope from Cyber Essentials as it is not on your admin/curric network(s) anymore. Sharing physical cable and switch infrastructure is fine apparently.

Posted
Not under Evandine, BYOD devices are in scope if it is member of staff and it accesses company data.

 

You can limit scope to just your admin team. Then only their personal devices come into scope.

 

I would just get Intune/MEM setup. You have to go through the pain and moaning. Evandine has got a fair bit wrong but ensuring up to date devices access your organisational data can’t be a bad thing.

  • Thanks 1
Posted
You can limit scope to just your admin team. Then only their personal devices come into scope.

 

I would just get Intune/MEM setup. You have to go through the pain and moaning. Evandine has got a fair bit wrong but ensuring up to date devices access your organisational data can’t be a bad thing.

 

That becomes a fairly narrow scope though and won't cover a lot of the data that you store/resources accessed plus a lot of segregation of the network.

 

I agree though that MAM-WE is the best way forward for this.

  • Thanks 1
Posted
For 2 have you looked at Intune MAM without enrollment (MAM-WE) as less aggressive than full enrolment

 

The issue is not being able to gather the Make,Model and OS of personal devices with a technical control. Full MDM is necessary. Android has the advantage of the Work Profile model which means only business data can be deleted/managed. iOS is a bit more messy.

 

In terms of scope you should aim for whole org. CE is hard work and will bring out other issues. Over the last few years education has needed to catch up with a more mature cyber security posture.

 

You have to think. If we don’t do this control when will we ?

  • Thanks 1
Posted
Do you have guest wifi?

 

While guest and filtered WiFi is great, to my mind its not stopping the greatest risk factor for kids which is taking unauthorised photos. The only real way I can see getting around this is by providing school devices with a limited range of apps.

 

You need not necessarily prevent taking photos but you need to limit how they can be exfiltrated.

 

I would personally disable any iCloud / Google Photos uploading and only allow photos to be uploaded to OneDrive / Sharepoint / Google Drive by whitelisting those apps. Also disable any USB functionality to prevent just downloading them on to a PC / Laptop. While you can still get around these measures you at least have a trail of evidence should you need to fall back on and you will be seen to be taking due diligence at preventing any e-safety issues.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...