Jump to content

Recommended Posts

Posted

Hi all, just wondered if anyone else was aware that although GovernorHub supports MFA, governors and trustees have to enable it themselves and it cannot be forced on or reported on. They can choose not to enable it, or enable it and then subsequently disable it and we'd have no way of knowing.

 

Our DPO is now (quite correctly in my view) pointing out that given the very sensitive data we are using GovernorHub to share, not having the ability to force or report on MFA means that we are not meeting our requirements under the Data Protection Act to take appropriate technical measures to secure data.

 

We're now looking at alternative options such as using our existing cloud platform but I wondered how many schools/trusts out there had implemented this and weren't aware of this.

Posted

I don't disagree about the importance of MFA but out of interest what personal information is stored? Everything should be anonymised and available through FOI anyway.

 

Also if you've asked governors to do this as part of your policy then that's what they should do. If it's not in the policy then it's not. You shouldn't need to have to police it.

Posted (edited)

All papers our governors and trustees receive are shared with them currently through GH which includes sensitive and confidential data as well as PII data as far as I know from my discussions with our governance staff.

 

The DPA says you have to take appropriate technical measures - a policy isn't that and not being able to enforce MFA in 2023 is madness - we use it for our emails/cloud platform, our MIS etc. This is why in platforms like M365 and Google Workspace you can both force and report/audit MFA usage - it's also the same in Arbor (can't speak for Bromcom).

 

The fact they have MFA as an option tells you it's clearly needed, the fact you can't force it or report/audit it is very strange.

 

It's also worth noting our DPO is contracted out to a company that specialise in this and the rep we deal with is always very sensible in their interpretation (IMO) so when they say something's an issue then it's highly likely to be an issue.

Edited by Primus
Posted

All fair comments but I'm gonna double down.

 

Been governor at 2 schools. We've always worked on the assumption they anything could be requested or viewed. Nothing is sensitive. Parental complaints that could involve children's names are stored differently and not everyone is Prive to them. Staff names never included next to anything HR related.

 

Having said this, like you I would still prefer MFA. I really don't think you need to police this though. If you asked them to do it and they have agreed and signed off they've done I really don't think you need to Audit it. This is the same with myconcern which holds the highest sensitivity of data. I do agree it would be good to have but I don't think it's a need to have.

Posted
I think the "appropriate technical measures" are the governors having the ability to use MFA not you being able to check up and audit if they are using MFA
Posted (edited)

Not everything that governors deal with can be requested by anyone - they see information about student exclusions, hear appeals and deal with staff misconduct etc - obviously a SAR means that information is disclosed to the person concerned but not to anyone else without subsequently being anonymised if it's within scope of a FOIA request.

 

There's potentially lots of documentation that is sensitive or contains PII.

 

I disagree, in 2023 we need to be able to force or at very least audit - that's why the big players like Microsoft and Google provide these features.

 

Would you not police or audit staff use of MFA?

 

We use CPOMS rather than My Concern - to do anything other than log new information on there you need to use MFA - this is forced and rightly so.

Edited by Primus
  • Thanks 1
Posted

Can you configure it to use Azure Authentication and then force MFA on Azure?

 

I don’t know the product specifically so this is just an idea.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...