Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Our IT service providers have told me that compliance with KCSIE requires that all BYOD and visitor devices must have an iBoss certificate installed on them to access our network to ensure that internet usage is correctly filtered. This is problematic as many visitors don't have admin access to their devices and colleagues who use their own devices report that their access to the internet at home is also blocked by iBoss and are unhappy about the restrictions iBoss imposes on the personal use of their devices whilst at home e.g. extract from an email to one of our staff: Social media sites tend to get blocked, but it could include things like looking for holidays etc that you would normally do when searching for stuff at home. Also restricted to the same safe wording searching as well. So whilst it's nice to have a bit of protection, you may find it also restrictive for searching stuff that you would normally search for at home with no restrictions.

 

Is this correct and is there a way around this that enables us to ensure that we remain compliant with KCSIE requirements on school sites?

 

I'm not an IT specialist, so apologies if this is a real novice question!

Posted

Id be on the side of,nyou cannot force someone to install the certificate on to their own device.

 

We are looking to take the stance of any device that is managed by the the school is to have the certificate on it.

 

If the devices doesn' fall into that category (BYOD / Visitors), it's made a note of in the risk register.

Posted

As above, you have no right to force anything onto a personal device. Everything must be at the user's discretion and you should provide the option of doing it.

 

For example, we use a Smoothwall. After connecting to the BYOD network, it redirects the user to the certificate page to download and install the Smoothwall certificate. They can choose not to, in which case their ability to do anything is almost entirely inhibited. Because of this, most students choose to use their phone's data rather than school WiFi but that's not our problem as they're not using our services.

 

Anything owned by the school should be managed and therefore it should be enforced.

Posted
Our IT service providers have told me that compliance with KCSIE requires that all BYOD and visitor devices must have an iBoss certificate installed on them to access our network to ensure that internet usage is correctly filtered. This is problematic as many visitors don't have admin access to their devices and colleagues who use their own devices report that their access to the internet at home is also blocked by iBoss and are unhappy about the restrictions iBoss imposes on the personal use of their devices whilst at home e.g. extract from an email to one of our staff: Social media sites tend to get blocked, but it could include things like looking for holidays etc that you would normally do when searching for stuff at home. Also restricted to the same safe wording searching as well. So whilst it's nice to have a bit of protection, you may find it also restrictive for searching stuff that you would normally search for at home with no restrictions.

 

Is this correct and is there a way around this that enables us to ensure that we remain compliant with KCSIE requirements on school sites?

 

I'm not an IT specialist, so apologies if this is a real novice question!

 

I'm not sure where (adult visitor) guest access falls in KCSIE, but it would make sense to have the guest SSID filtered quite stringently anyway. The Filtering guidance says that filtering should take place at network level, so even if using an agent based filtering solution, you should have some protections in place for non-managed devices, servers, whiteboards, guests, etc in my view.

Posted

The general thrust has been answered, so I'll address this bit:

 

e.g. extract from an email to one of our staff: Social media sites tend to get blocked, but it could include things like looking for holidays etc that you would normally do when searching for stuff at home. Also restricted to the same safe wording searching as well. So whilst it's nice to have a bit of protection, you may find it also restrictive for searching stuff that you would normally search for at home with no restrictions.

 

...and say you likely need to have the "Tough, it's a work device subject to work filtering - it's not a substitute for buying a home computer/tablet" conversation with them.

 

One person's "stuff you would normally search for at home" is another person's Rule 34 / HR complaint / safeguarding concern if done on work devices.

 

Want to do perfectly legal adult stuff on the Internet? Do it on your personally-owned device in your own time on a Internet connection of your own.

Posted

Id say have the guest and Staff BYOD networks filtered at DNS / network level with unauthenticated requests rather than per user level / HTTPS devryptio.

 

Assign the 2 networks with Staff policies so the URLs are still blocked, after all you may get some visitors trying their luck and i guess you'd expect malicious / adult themed sites to be blocked.

 

What happens if 20 guests turn up, are you really going to assign each one a unique logon to use the internet? It will take you ages to register each one and hand them out.

Depending on how you issue out your guest access codes, make sure they expire or someone changes the password so the access isn't accessible for more than the allowed time.

 

As long as we are to be seen to be protecting users (that includes anyone who uses the system) i'd say we are meetibg the standards.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...