Jump to content

Recommended Posts

Posted

Been trying to define "Organisational data"

 

Obviously things like our MIS, Finance systems, Drives, Emails etc are included.

 

However what about platforms like Sam Learning? or Accelerated Reader?

Platforms that are cloud based, and have things like student names in.

My first instinct would be "Yes".

 

However I'm now looking at needing to be able to control access (secure passwords etc) on these platforms and finding the ability to do so is woefully inadequate?

 

 

Anyone got any thoughts on this?

 

(I did try searching the forms but could see any results)

Posted

Cloud systems are now in scope. Many don't allow the controls that are required. SAML and/or MFA being the biggest issue. IP restrictions wouldn't be that hard to develop as a short term fix.

 

I wonder if NCSC will have to re consider the requirements due to the lack of controls avaliable?

Posted

They tested our e-mail (365) for resistance to malware and asked about MFA. However, they asked no questions about other cloud systems. This was in March.

 

I guess things must have changed since.

Posted

I'm not sure when the change came in but it's now:

 

All Cloud services are now in scope, added definitions and a shared responsibility table toassist with this.• Extended the Multi-factor authentication requirement in relation to Cloud services.

Posted
The question set has changed in January with further changes in Jan 2023 mainly MFA for all users not just admins.

Ok... so are they accounting for the Government's desire to see all schools ban mobile phones. I know they're not going to do it legislatively, but they do want that ban in place done from the position of Headteacher...

Are they accounting for 5 year olds accessing solutions? When they say all users, do they mean staff or students also?

Posted
Ok... so are they accounting for the Government's desire to see all schools ban mobile phones. I know they're not going to do it legislatively, but they do want that ban in place done from the position of Headteacher...

Are they accounting for 5 year olds accessing solutions? When they say all users, do they mean staff or students also?

 

They mean your staff not your customers. I do not understand the phone ban thing. Theres this thing called self control which I'm sure would be helpful.

Posted

I wonder if NCSC will have to re consider the requirements due to the lack of controls avaliable?

 

I doubt it, part of the objective is for the vendors to up their game too.

Posted
They mean your staff not your customers. I do not understand the phone ban thing.

 

I didn't say I agree with the phone ban thing, but many schools do it. Even with staff... when you point out that phons being banned means a few thousand pound on 2FA keys, teeth get sucked like a plumber looking over a dodgy boiler. :D

Theres this thing called self control which I'm sure would be helpful.

 

In 14 year olds who can't stop themselves doing really stupid stuff even when they know they're in plain site of a CCTV camera? :laugh:

Posted

We all need to accept that phones get banned within school. When we look at what we are doing here, it is based on risk assessment for a very specific scope.

Other areas of school life also need risk assessments and there are times when risk treatment for one area (MFA via staff phones) increases risks in other areas (staff use of phones for photos, etc… so holding unsecured personal data on a personal device).

 

After it is balanced out you cannot reduce the risk in one area by increasing it in another. It is not that safeguarding trumps things, it is about risk in particular scenarios.

 

Whilst I agree that NCSC should *not* have a lower grade of scope to let schools fit in, schools need to recognise that this is not done in a silo.

  • Thanks 1
Posted

We came to the same conclusion @GrumbleDook.

 

Because I hold the budget for IT across a large Trust I could easily justify and implement licensing that includes conditional access. There are likely colleagues on this forum without that authority, and as long as the case has been presented it's the Head/CEOs ultimate responsibility.

 

All colleagues should be pushing for MFA and have an audit trail for when something happens.

 

As far as I know, only conditional access allows MFA to be skipped when on the internal school network, a simple fix that balances the risks of phones and needs of security.

 

We also skip MFA when using a work device in all locations - the laptops itself is the second factor and I'm comfortable with that.

Posted (edited)
As far as I know, only conditional access allows MFA to be skipped when on the internal school network, a simple fix that balances the risks of phones and needs of security.

 

But we also have to be aware that IP addresses can be spoofed and we all have resourceful children who will be able to that, or that your ISP behaviour when it comes to your IP addresses is less than sub-optimal. Ours can switch and change between addresses mid-session and cause Google to suspect bot usage!

 

I would say that whitelisting IP is somewhere you are, rather than something you have or something you know. It also makes it easier for children to access staff accounts on-site because they don't need that second factor.

 

There are likely colleagues on this forum without that authority, and as long as the case has been presented it's the Head/CEOs ultimate responsibility.

 

Is it though? Safeguarding is ultimately their responsbility too, but if the safeguarding lead in a school makes a decision that is to the detriment of the school and someone who should be being safeguaded, its' like not the Head/CEO who gets the chop.

Edited by paulkerton
Posted

We're Cyber Essentials approved. Went through the extended trial. Cloud was not in the original scope but now is so wasn't much of a consideration however I tried to implement as much as I could for next year already.

 

We're a Google school and using 2-step successfully for all staff. We purchased Yubikeys @ £26 per key, they can be reset and reused. No need to carry a mobile around the school. However you'll see some Apps start requiring authentication codes anyway (CPOMs for one).

 

Google don't have the option of IP geo locations unfortunately but I've heard some people purchase Azure and connect that to Google in order to get conditional access applied.

 

I think the idea of only conditional access isn't a good option by itself, if an account is compromised and remote access is available in some way then game over. MFA is required to secure data online and against insider threats.

  • Thanks 2
Posted (edited)

Google don't have the option of IP geo locations unfortunately but I've heard some people purchase Azure and connect that to Google in order to get conditional access applied.

 

I think the idea of only conditional access isn't a good option by itself, if an account is compromised and remote access is available in some way then game over. MFA is required to secure data online and against insider threats.

 

You can do this in Google Workspace, it's in the documentation.

Essentially you set a 'context aware access" and define the geolocation in CEL, then apply that to the applications that you want to restrict.

 

https://cloud.google.com/access-context-manager/docs/custom-access-level-spec

https://support.google.com/a/answer/9262032?hl=en-GB&fl=1

Edited by dmj
  • Thanks 3
Posted (edited)
You can do this in Google Workspace, it's in the documentation.

Essentially you set a 'context aware access" and define the geolocation in CEL, then apply that to the applications that you want to restrict.

 

https://cloud.google.com/access-context-manager/docs/custom-access-level-spec

https://support.google.com/a/answer/9262032?hl=en-GB&fl=1

 

Yes, but it's only available in the licensed Google Workspace, requires them to be "company owned devices" which means staff and students won't be able to use personal devices (which will generate complaints) and as I've previously said : Location based on IP is not, for me anyway, a very secure way of enforcing (or not in this case) 2SV anyway.

It's a moot point anyway, in that you can buy Yubikeys for staff and apparently students are not considered under Cyber Essentials.

Edited by paulkerton
  • Thanks 1
Posted
Yes, but it's only available in the licensed Google Workspace, requires them to be "company owned devices" which means staff and students won't be able to use personal devices .

 

That's not true. It's available on Education standard and works on home devices. you CAN restrict access to 'company owned devices' but that isn't required.

Posted (edited)
That's not true. It's available on Education standard and works on home devices. you CAN restrict access to 'company owned devices' but that isn't required.

Education Standard is a licensed product. Education Fundamentals is the free tool. Therefore you can restrict access to company owned devices, because you are licensed.

 

https://edu.google.com/intl/ALL_uk/workspace-for-education/editions/compare-editions/

 

Even if that was the case that it's available for free, it still doesn't negate the fact that IP based restrictions are a very bad way to manage 2SV

Edited by paulkerton
Posted

My bad, I forgot they messed with the free education version, we're on enterprise.

 

It's not a great way of dealing with 2-step- but it dramatically reduces the number of attempted logins from areas where the company doesn't operate - it's more Mutlifactor auth than 2step auth.

  • 3 weeks later...
Posted
Education Standard is a licensed product. Education Fundamentals is the free tool. Therefore you can restrict access to company owned devices, because you are licensed.

 

https://edu.google.com/intl/ALL_uk/workspace-for-education/editions/compare-editions/

 

Even if that was the case that it's available for free, it still doesn't negate the fact that IP based restrictions are a very bad way to manage 2SV

We have our GSuite SSO'ing with Azure to provide 2fA

 

IP based restrictions are a terrible idea, but better than nothing and solves issues with 2FA in the classroom

Posted
IP based restrictions are a terrible idea, but better than nothing and solves issues with 2FA in the classroom

 

Does it though? That's my point... Spoofing an IP address isn't exactly difficult.

Posted

It solves user issues, not security issues. Spoofing an IP is easy but you would have to know our ranges, who our suppliers are and various other bits of information to be successful.

 

It's totally impractical to ask primary age students to use 2FA, so we accept that risk.

 

We can (and do) use another method to detect Intune managed Windows devices and iPads, but we also have 1000's of Chromebooks and iPads managed by other systems.

Posted (edited)
Spoofing an IP is easy but you would have to know our ranges, who our suppliers are and various other bits of information to be successful.

So the first thing I'd do is go and see if your school has a Wikipedia entry, and check the anonymous edits to see what IP addresses have been exposed via that. :ranger:

But anyway, you're absolutely disregarding students (and they are capable, I've had one take me on a run around all Summer with similar schemes)

 

They wouldn't have to know who your suppliers are, but they are completely able to be exposed by a Freedom of Information request too.

IP addresses for protection are as useful as a chocolate fireguard.

Edited by paulkerton
Posted
So the first thing I'd do is go and see if your school has a Wikipedia entry, and check the anonymous edits to see what IP addresses have been exposed via that. :ranger:

But anyway, you're absolutely disregarding students (and they are capable, I've had one take me on a run around all Summer with similar schemes)

 

They wouldn't have to know who your suppliers are, but they are completely able to be exposed by a Freedom of Information request too.

IP addresses for protection are as useful as a chocolate fireguard.

 

It is a risk management exercise. As long as you complete the exercise, log it, justify the decision and have a regular review/intervention process there is not much else that can be said or done. The same threats/vulnerabilities can easily produce different risk levels depending on the school. You are right to raise it, but it is a given way of having some risk mitigation for this area. Context, as always, is key.

Posted
It is a risk management exercise. As long as you complete the exercise, log it, justify the decision and have a regular review/intervention process there is not much else that can be said or done. The same threats/vulnerabilities can easily produce different risk levels depending on the school. You are right to raise it, but it is a given way of having some risk mitigation for this area. Context, as always, is key.

Were we not all saying a few months ago that security by obscurity is not security at all?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...