Jump to content

Recommended Posts

Posted (edited)

Edit: If you wear a school or trust-wide data protection hat.........

 

Do you check code locks on doors aren't set to 12345, 67890, 2024, 2025 and any founding date found carved on a stone near the front door?

 

If you find a key, do you see what it opens and follow any further found keys?

 

Do you restrict yourself to knowledge that a student or visitor familiar with the site would have?

 

Or, to put it another way - absent taking along entry tools, how close to a physical penetration test do you get?

Edited by pete
Clarity.
Posted
Do you check code locks on doors aren't set to 12345, 67890, 2024, 2025 and any founding date found carved on a stone near the front door?

 

If you find a key, do you see what it opens and follow any further found keys?

 

Do you restrict yourself to knowledge that a student or visitor familiar with the site would have?

 

Or, to put it another way - absent taking along entry tools, how close to a physical penetration test do you get?

 

SBM (DPO) does that with the DSL. They do site walks to make sure everything is in order, then friendly polite reminders to staff about what they should do.

 

SBM line managers the site engineer and they run a tight ship on door codes/keys etc. Checking the state of classrooms and wht kind of data is exposed.

 

From us in IT, we make sure autolock exists and equipment encrypted etc. Our visitor accounts have limited access and Wi-Fi is maintained by us and everything logged.

Posted

Not my circus, not my monkeys.

 

Our ops manager and the site team deal with all of that, and as they have oversite of all code locks and door keys it's not something that has ever cropped up.

 

Ops manager does a walk every couple of weeks and reminds staff of their obligations about the security of physical data about once a term.

Posted

I think it should be checked, but not necessarily by IT.

 

Probably the main thing is checking for confidential papers, notes, passwords etc left on desks. Physical security you should probably get a specialist in - its not really part of a regular walk, unless someone's done something daft, like writen the door code at the top of the door. Schools are never going to be 100% secure physically.

 

Code locks are an instant fail - too easily bypassed. I wouldn't even bother checking the code. Codes should be centrally documented rather than checking lots of options if you want to get picky. You can use a UV Pen to see which buttons get used - Or just see which are most worn. Plenty of videos online about why you wouldn't want to use these for anything important. Same for the combination key boxes. And the first code to check is 1966.

 

Electronic and/or code locks without a good mechanical lock for out of hours should also be a fail. Again, too easy to bypass. These should all be backed up by CCTV cameras.

 

Keys left lying around - another instant fail. Doesn't really matter what they are for - its probably for something important.

 

I'd probably recommend getting a locksmith in to check and service all the external locks. If you check it in house, it doesn't take too long to check the deadlatches are working and that you can't get tools into the latch to open it. But I wouldn't bother timing how long it takes you to pick the lock.

 

Anything confidential needs to be properly locked away in a filing cab or safe, or digital. Even Filing cabs can be opened with a paperclip or big screwdriver.

 

You do need to think about what's being protected. Much of the above is fine for stopping kids getting into the staff toilet, but not OK for an external or main office door. Also, get a big enough hammer and you can get through any of it - apart from maybe a safe.

 

I think my point is don't spend loads of time testing things unless you are demoing to a budget holder why a particular lock (or whatever) isn't good enough.

Posted

As others have said, the IT involvement in this stops with "are classroom doors locked preventing damage/theft/access?" and "do laptops/applications lock on inactivity?" *. That said, many of us have advisory roles in data protection too, at which point tidy desk/noticeboards becomes important but I think any direction or instruction to colleagues, and certainly any difficult conversations regarding issues identified would come from line management or Headteacher.

 

* My team are useful "spies" on that front though, along with the Site Team, as they are moving around the school a lot so see people's desks/noticeboards/ePost-It notes accidentally projected.

Posted

I should probably have made it clearer I'm the trust data protection lead (with an outsourced DPO to keep us honest).  

 

Why?  We had a looming deadline (May 2018) for compliance at one of the schools pre-MAT, none of SLT were taking sufficient notice and the business manager (at the time) and I got fed up and fixed it.

 

Since then I've been trying (with variable success) to entice non-IT colleagues into sharing the oversight load and responsibility.

  • Like 2
Posted
16 minutes ago, pete said:

Since then I've been trying (with variable success) to entice non-IT colleagues into sharing the oversight load and responsibility.

 

If you don't have a Business Manager or they're not interested, the HR Manager is a good one to share it with, as they're often relatively senior and have a good grasp of privacy and protocol.

Posted

Frankly if the business manager is "not interested" in room security or data protection/gdpr then they need sacking as that is their ACTUAL JOB ROLE whilst they are "managaing the business"???

  • Like 1
Posted
6 minutes ago, enjay said:

 

If you don't have a Business Manager or they're not interested, the HR Manager is a good one to share it with, as they're often relatively senior and have a good grasp of privacy and protocol.

Unless they're the same person... 😬

 

I had to go over the head of the BM and HT to the govs about 10 years ago to get a concern about upgrade plans/priorities taken seriously because the old BM didn't/didin't want to understand the need to change. 

 

Govs are a last resort and not every board of govs takes kindly to being approached directly.

Posted

The problem is that all the people with the aptitude (I've rejected a few people) and the seniority to do it are (because education) already stretched thinly.

 

The current approach is to go more mid-level (capable, confident, some management experience) with backup from me if someone tries to pull rank on them.  It's early days, so we'll see how it goes.

  • Like 2
Posted (edited)

 

We work in a building that we designed to be securable in zones, and also open to the public out of hours. Unless teachers forget to lock offices or classrooms (both in violation of CP/Safeguarding practice) the building is intrinsically pretty secure. We have serialised keys (so all staff have access to certain rooms, and others rooms are more restrictive, but some keys open most doors, and a handful of people have keys that open all doors) except certain doors are on completely different locks to provide an additional security boundary.

 

Since the IT office has delegated DPO responsibilities, and the IT Team walk the building for other reasons on a regular basis, unsecured doors, or paperwork left out is spotted and followed up as part of routine operations.

 

If the appropriate remedy is not applied, with a follow-up email or two it becomes the SBM or Head Teacher's problem.  It never does.

Edited by psydii
  • Thanks 1
Posted
51 minutes ago, Oaktech said:

Govs are a last resort and not every board of govs takes kindly to being approached directly.

 

I suspect a lot of HTs wouldn't take kindly to that either!

  • Like 1
Posted
9 minutes ago, enjay said:

 

I suspect a lot of HTs wouldn't take kindly to that either!

Correct... However this was the right time to do it, the govs agreed with my decision and reasoning and both the BM and the HT were ousted and replaced within the year. There was far more going on than I knew about.

Posted
1 minute ago, Oaktech said:

Correct... However this was the right time to do it, the govs agreed with my decision and reasoning and both the BM and the HT were ousted and replaced within the year. There was far more going on than I knew about.

Agreed, sometimes it is the right and only course of action, but I would want to be very sure of myself before taking it.

Posted

As I walk down the hallways after school and see through the door windows that the teacher's projectors are on and their email is displayed on the board, I make sure the door is locked...

 

😁

Posted

I love doing security wandering but rarely get the chance now. Our Internal Systems team are wonderful for spotting things (which, happily, is quite rare) and having a quick word. I do still do random checks when in the office but short of forced, physical entry there is little to check nowadays.

 

School visits are another matter though. A small credit card-sized pocket tool usually gives me enough to point out external hinges which can be dismantled to get into a server room, an old loyalty card to beat spring-latched locks which have not been deadbolted (meant to be done each night to lock up but folk forget) ... and with the help of a year 9 student, showing how staggered A/C units could be used as steps to get to an external open window (I didn't ask him to do it, he had left stuff behind and needed to get it ... I spotted him and thought it best to let site staff know).

 

Checking on clear desks .... no name and shame but work out there are, for example, 10 desks in a department across different offices and classroom ... and 2 have stuff on their desk which should not be there. 80% pass ... another department had 32 desks ... and 16 had stuff there ... so a 50% rate ... a clear fail. This way you are not targeting individuals and it helps to spot departments/groups who have little interest in following the clear desk policy ... so what else are they ignoring?

Posted

The credit card (or better yet iFixit prizing card) trick doesn't work on our doors without a flathead or chisel to knock out the door surround (fire / draught baffle) and at that point it's faster to kick the door in if you're going to leave signs of entry.  Underdoor tools don't work for similar reasons (very stiff draught excluders and intumescent stripping) and most doors are keyed each side.

 

But too far down that path and I'm knocking out hinge pins, shimming padlocks and a site walk that already takes 3hrs per secondary school would be a whole day.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...