Jump to content

Recommended Posts

Posted

Hi all,

 

First time posing but long-time visitor to the site. I just have a quick question in regards to the Cybersecurity risk register that we should be keeping as a school… I do have a register template, however when I set it up I was under the impression that it needed to be filled in AFTER something had been discovered, for example Jane Doe lost her school iPad and now we have to mitigate the risk going forward, report it to Govs, etc. However, I am now wondering whether that is correct, or whether it needs to be filled in with any risks that COULD happen along with the rational on how we mitigate to prevent it happening. For example, John Doe could attach an infected USB device to the network and spread a virus across the school, so we use encrypted USBs only to minimise the risk.

 

Basically, how do you guys currently carry out this process? Obviously, I am hoping I was right in that it is a risk register for issues that are discovered or could potentially cause an issue… rather than a register of absolutely every risk there could be.

 

Advice is much appreciated :)

 

Steve

Posted (edited)

In short and in my opinion look at a risk register a bit like you would a classroom risk assessment. Include as many potential risks as possible, It should include mitigations and what you should do in The event of it happening.

 

It’s something that you should review and build over time. It will help you and senior leaders understand what has been done and what needs doing.

 

If you are starting from scratch focus on a small area at a time.

 

 

In the event of something happening on the risk register you should be able to use it as your go to place just as a reminder to yourself what you planned to do if such an event was to occur, compose yourself and implement actions.

 

We include links to other documents in ours just so it doesn’t get out of hand.

Edited by gaz350b
Posted
Hi all,

For example, John Doe could attach an infected USB device to the network and spread a virus across the school, so we use encrypted USBs only to minimise the risk.

 

Not sure that the encryption is going to reduce that risk at all. We just ban them across the board.

Posted (edited)

Your risk register is what could happen, what mitigations you have in place and (post-mitigation) what the residual risk is. In detail.

 

That then feeds into the school/trust-wide risk register (in more general terms, with reference back to the full doc in a footnote).

 

You likely already have this written down, just not in one place. A lot of mitigations will apply to more than one risk.

 

Using your example (and ignoring encryption in and of itself, because it won't do much)

 

For example, John Doe could attach an infected USB device to the network and spread a virus across the school.

 

So:

 

Risk = potential for malware to spread via USB, interrupting teaching and learning (crypto, cleanup times) and potentially exfiltration of personal data by extortionists leading to data loss, reputational damage and (if it's safeguarding data) potential serious consequences to a subset of students.

 

Mitigations = Anti-malware measures. Automated virus scans. Restricting USB use to only those who need it. Encouraging use of OneDrive/Google Drive instead. Potentially tattooing* Bitlocker usb drives to only school-owned/encrypted devices to be used. Restriction of what (file types such as macro-enabled documents and executable code) can be copied to network/cloud locations. Cybersecurity training to reinforce "don't plug in random stuff you found in the car park". Use of Canary tokens (https://docs.canarytokens.org/guide/) to spot-check that people are actually following guidance. Alerts for file servers and cloud storage locations when too many changes come from one user over a short period of time.

 

etc

 

Residual risk = Whatever

 

Is residual risk acceptable? What would it cost (time, money, additional faff for end-users) to reduce the risk? Yes? No?

 

Notes.

 

 

*look in the Bitlocker GPOs.

Edited by pete
Posted

Please ignore my bad example... it was a good example of losing train of thought through interruption, but it’s not an example of how we mitigate the risk of USBs at all

 

I really appreciate the advice and it gives me something to think about. Obviously it's a given that risks are thought of and taken into account when setting things up here, and I do make notes of what potential risks could be associated with various things, just not in 1 place and not to that level of detail so it looks like I have got a bit of work to be getting on with.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...