Jump to content

Recommended Posts

Posted

We are slowly getting device creep of staff using their own devices around our trust for work purposes, mainly those that don't want to use a Windows device and would much prefer to use a MacBook so are using the BYOD networks for work purposes and then complain that they are unable to print anything or access any of the onsite services.

 

Question is, how do others mitigate the use of staff using their own devices when the trust has tried to issue a work device to them but yet they continue to use their own device?

 

Do you have a staff BYOD policy? If so, would you mind sharing it?

 

I've tried to get staff to agree to the following points but they will not accept them so I feel a formal policy coming.

 

You will need to download and install the security certificate from the BYOD website before you continue to login to the wireless network.

 

Can you confirm that no personal information will be left or stored on the MACBook for longer than required?

Can you confirm that when you decide to move on from SHS, you will remove any files / information / data relating to SHS?

 

And then in general, the school is not responsible for misuse of a device or damages to a device that occur during normal operation.

- It is the employee’s responsibility to take additional precautions, such as email, contacts, etc.

- The employee assumes full liability for risks including, but not limited to, the partial or complete loss of company and personal data due to an operating system crash, errors, bugs, viruses, malware, and/or other software or hardware failures, or programming errors that render the device unusable.

- The school reserves the right to disconnect devices or disable services without notification.

- Lost or stolen devices must be reported to the school within 24 hours.

- The employee is expected to use their devices in an ethical manner at all times and adhere to the school’s acceptable use policy and other applicable policies.

- The employee is personally liable for all costs associated with their device.

 

I know this is going to raise the question of, "well the trust allow me to use my own phone for emails, 2FA authentication and to access online services when there's no wifi around the trust such as outside. How do we protect these devices? What about using personal devices at home?" Which is a valid point but i feel a code of conduct for staff using personal devices might be required here.

Posted

Crikey. You can’t conform to a FOIA request very easily! If staff are doing any school work which contains pupil data, and storing it on their own devices, you will need to use the law to come down hard on this.

 

Accessing emails in a browser on a phone is one thing. Using a personal device as a school laptop is not going to end well. If you have to allow them further and further into your network, the risk increases greatly.

Posted
Just a straight no here - you're issued a device, use it. If they want to use their own device in school they're welcome to use BYOD (if it works, we're not obliged to make it work) but not for storing any data. As has been mentioned, increase of risk of data going walkabouts. Cybersecurity & GDPR and you're giving them the tools to use otherwise.
Posted

Do you have a staff BYOD policy? If so, would you mind sharing it?

 

I can't share our policy and I don't think it would be helpful to you anyway, but where we work you can use your personal mobile device to access our data only with full MDM profile install, and via mandatory software (e.g. Outlook for email, not whatever app they might personally prefer).

 

For "desktop" type access, printing, etc, you can install the Citrix client if you want to and use a citrix desktop, or Windows 365 if you're lucky enough to have that, or you can forget about it.

 

 

I've tried to get staff to agree to the following points but they will not accept them so I feel a formal policy coming.

.

 

This absolutely needs to come from management. I'd be warming them up about the obvious security risk, also going to great pains to stress the data protection risks also of data being transferred to devices out of your control, and saying (not asking) to senior leadership that they are responsible for any issues that arise from their failure to act decisively on this.

Posted
I think you need senior management in your corner to be most effective, and you should also look at technical restrictions to put downward pressure on it, too. For instance, are you able to restrict access to work MS/Google accounts from unmanaged browsers?
  • Thanks 1
Posted

As an alternative viewpoint.

If we're using 365 and cloud based MIS, then I don't see there's any compliance issue. Obviously nothing should be downloaded to the local device, but if they're working wholly in the cloud and that access is password/MFA protected, then it shouldn't matter what device they're on. And is technically no different from working at home on their own PCs, which we know some staff do.

I just say no to printing and local services on BYOD devices. If they want full network access then it's on a domain joined/school managed device. If they're happy just accessing the could resources (which is most of our stuff these days), then it's fine*.

 

* Our BYOD/home use policy states that devices accessing school resources should have up-to-date endpoint protection and the latest vendor security patches.

Posted

If there are devices being supplied by the organisation, then those ought to be being used as a matter of principle, really.

 

There may be policies such as screen lock timeouts, full disk encryption, application allowlisting that are set by the org on those devices, to mitigate against unattended devices in classrooms, etc. With BYOD devices being used, those sorts of organisational stances are weakened.

It's also a matter of how far the IT support is expected to go. With org-managed devices, you can support people doing their work on them, but BYOD, not so much. You won't necesarily have spare chargers to help keep a lesson on track, for instance.

  • Thanks 1
Posted
Thanks all, I thought all this would be the case. I thought by giving the statements that I gave would be a "meet half way / disclaimer" but it does seem like I need support from high above which I'm struggling to get.
Posted

You can't really go any further without the buy in from head/slt. It is such an important issue that here, it would be my head sending that out to staff as an instruction rather than from me as a polite request from IT.

 

If you can't get that - just get an email from head/slt instructing you "no" or "it's fine" etc and that instruction will cover you in case of a GDPR issue/etc

  • Thanks 1
Posted

Good point about the use of personal devices for 2FA for work accounts and then saying they can't use personal devices...to access work stuff.

 

Schools can't have it both ways. Buy staff a device and have done with it. We see enough waste in education through damage and the latest trend. Spending money on a device for staff for work is a no-brainer for me in comparison

Posted
We are slowly getting device creep of staff using their own devices around our trust for work purposes, mainly those that don't want to use a Windows device and would much prefer to use a MacBook

 

We issue 2FA USB dongles / fobs to staff, we don't require they use their own phones for 2FA (official school policy is "no phones in classrooms"). We use the same devices for building access (Paxton) and printing (Papercut), so staff have one school-issued device to access everything. For those that want to use their own device (typically a Macbook), we have a web-based remote desktop server behind a Cloudflare zero-trust gateway that staff can access via their (2FA protected) Google account.

 

I'm not quite sure why some staff like Macs so much. We have few older iMacs we have re-formatted with ChromeOS Flex in our Art department. When one of their power supplies conked out, we replaced it with an all-in-one Chromebase - same OS, same sized screen, I think even the same keyboard, but the teachers still complaied because they wanted a Mac!

  • Thanks 1
Posted (edited)

Pretty much the same here as what others have said above.

 

Our school issues 1:1 iPads to all, headteachers choice, they don't like using them and want to use their own laptops, tough.

 

Due to the sheer amount of WiFi devices we have in school now 1200 roughly on an active day we don't permit a BYOD network or offer WiFi to staff, mainly they want it for their phones and emails, get a better contract is my usual answer, £8 for 50GB a month is the norm nowadays.

 

Anyways, we do allow a very small number of staff due to desperation circumstances and it's internet only, no internal network.

 

Majority of our files are now on SharePoint along with email, Teams and the rest of Office365 gumpf.

Sims is still sh#t so go use a school device or NextGen on the web which we are a trial of in the god awful state that's in.

 

Use to offer remote desktop until I finally pulled the plug and told SLT tough as I got fed up of monitoring people logging on to remote desktop to use Outlook and web browsing only even after explaining just use office.com and your own home web browser.

 

The staff hate iPads because they are not computers but I tell them it was the wish of the headteacher and digital strategy leader so go take it up with them, eventually they give up and admit defeat.

For the few that really do try to dig their heels in I start speeling off the DofE guidelines about security, data protection, safeguarding and web filtering even if you are a teacher etc etc etc and then throw them a link to the DofE IT guidelines page with a "enjoy the read" sign off.

Edited by Tefters
  • Thanks 1
  • 2 weeks later...
Posted
The staff hate iPads because they are not computers but I tell them it was the wish of the headteacher and digital strategy leader so go take it up with them, eventually they give up and admit defeat.

Slightly OT here but I very recently found out that you can plug a usb keyboard and trackpad into an ipad via lightning/usb adapter and type on the thing with a lil cursor on the go also. Prop it up or use a stand and it's much more use-able.

 

This might be the most obvious thing in the world to everybody btw but myself and my line manager found it handy! Might win some hearts and minds if you had chance to offer that.

Posted
Slightly OT here but I very recently found out that you can plug a usb keyboard and trackpad into an ipad via lightning/usb adapter and type on the thing with a lil cursor on the go also. Prop it up or use a stand and it's much more use-able.

 

This might be the most obvious thing in the world to everybody btw but myself and my line manager found it handy! Might win some hearts and minds if you had chance to offer that.

 

Yup aware of this one, same as a Bluetooth keyboard and mouse however the SLT wont approve for the school to buy the adaptors and teachers wont out of their own pocket!

Posted

Our view would be we supply you a device use it. The problem is using personal devices although things might be internet facing its controlling how that data is on that machine, if its lost it will be unencrypted and if teacher X has class details list on their machine thats a data breach. It's like if email is added to a phone and you don't have a password set you are prompted to before you can go any furhter. Also you don't know what viruses etc they have on their machine which would spread on your BYOD network or even be uploaded if files are saved up.

 

You are just opening yourself up and a can of worms, for your own protection, the orginisation and individuals if you already provide a work device enfore they use that. How would you feel if your bank allowed its staff to use thier own machines, had a copy of data (which they shouldn't in theory but we know does happen) on their machine which wasnt encryped and it was stolen or taken as part of ransomware attack on that machine. The orginisation would be fined but the individual, and would staff want to pay up to the ICO?

 

If there is a problem with the devices they are using speak to them find out whats wrong? I'm sure there wont be but for everyones protection put measures in place if they are using their own devices to protect everyone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...