NorthernNoel Posted January 7 Posted January 7 Just having a read through the standards again and this one jumped out at me in the cyber security section: Quote Make sure SLT have access to a dedicated administrative account – this will only be needed in an emergency where IT support is unavailable Maybe it's just me but giving keys to someone without the correct knowledge seems a dangerous thing? Surely you mitigate this by ensuring you have IT support staff that are available?
NegativeKillDeath Posted January 7 Posted January 7 I've done this before by having a separate admin account with very hard, non-rememberable password. That account details were written down, sealed in an envelope and then laminated shut. It was then stored in a fire proof safe and audited on a regular basis to make sure it wasn't unsealed. 1
paulkerton Posted January 7 Posted January 7 Personally, that's an "emergency break glass account that's stored in a safe, in a sealed envelope with a tamper seal on it and only to be used when IT support isn't available due to dire circumstances" kind of thing. 1
RobFuller Posted January 7 Posted January 7 1 minute ago, paulkerton said: Personally, that's an "emergency break glass account that's stored in a safe, in a sealed envelope with a tamper seal on it and only to be used when IT support isn't available due to dire circumstances" kind of thing. Exactly this!
NorthernNoel Posted January 7 Author Posted January 7 I get that but don't really get what they'd do with it 😂 Unless the entire IT team was wiped out under a bus in the car park perhaps? I guess the worry is that an enterprising member of SLT thinks they know best and have a way of gaining access. I've certainly worked with some SLTs where a little knowledge is a dangerous thing. Many years ago I had an member of SLT assert their authority by saying they 'needed' admin access. It was duly given and two days later they managed to play with things and lock out an IT room. Putting a failsafe in of keeping it in a sealed envelope makes sense. I just wish these standards weren't so vague sometimes for others (i.e. SLT) to misinterpret.
NegativeKillDeath Posted January 7 Posted January 7 The IT team in question may be an MSP that suddenly goes into administration or some such issue where by the replacement offering needs an account to get up and running. I get what you mean about tinkering SLT though.
TheHyperTechie Posted January 7 Posted January 7 I find this funny, as my current MAT (and their MSP) won't even let me have an admin account to their O365 tenant! I will pass this info onto them. 1
Koldov Posted January 7 Posted January 7 4 minutes ago, NorthernNoel said: entire IT team That would be just me then... 5 minutes ago, NorthernNoel said: wiped out under a bus in the car park ...and with the members of staff that are allowed to drive the minibus, it's not as unlikely as you'd think! Thing is as far these 'standards' go, yes they are a little grey and open to interpretation, but they have to be slightly vague to cover a lot of different scenarios, given not all schools are run/staffed the same way. 1
TechMonkey Posted January 7 Posted January 7 Pass it on to your replacement or the company that steps in if the entire team is wiped out under a bus. It really is an end game failsafe and why it is a very, very long password sealed in an envelope, signed by members of the IT team, laminated, kept in the Finance safe after being eaten by a Doberman, as well as being checked regularily by the IT team that it is there and not been tampered with. It should be made clear that using this without proper cause needs to be a gross misconduct offense. Mine generally have a password with a length of multiple page lines, partly to put off anyone wanting to quickly use it but also to really make sure it is secure.
6Foot3 Posted January 7 Posted January 7 11 minutes ago, HyperTech said: I find this funny, as my current MAT (and their MSP) won't even let me have an admin account to their O365 tenant! I will pass this info onto them. What is your job role then?
TheHyperTechie Posted January 7 Posted January 7 11 minutes ago, alordcharlie said: What is your job role then? To be honest, not sure at the moment. I was the NM of our previous Trust, but we got absorbed by the new one, and they use an MSP so didn't really want my involvement! I am still the NM of the original school I started at, and retain access to and manage pretty much everything here... 1
NorthernNoel Posted January 7 Author Posted January 7 24 minutes ago, Koldov said: That would be just me then... ...and with the members of staff that are allowed to drive the minibus, it's not as unlikely as you'd think! Thing is as far these 'standards' go, yes they are a little grey and open to interpretation, but they have to be slightly vague to cover a lot of different scenarios, given not all schools are run/staffed the same way. I get that and I've covered lots of these roles from being a single tech to director of IT at MAT level as well as offering a traded service. I guess my issue is that they actually need to be more specific as the standards are mainly targeting people who are from a non technical background. I can easily see a member of SLT that fancies themselves as an 'IT expert' interpreting this as they should have an admin account for their emergencies. Emergencies that should be dealt with through the proper process.
pete Posted January 7 Posted January 7 ^ You can configure big honking alerts that email the whole of IT and SLT if an account is used. You can supplement those with a Canary Token or two: https://docs.canarytokens.org/guide/ (But as suggested above, definitely get it written into policy that misuse is gross misconduct up to and including dismissal).
DrCheese Posted January 7 Posted January 7 Ours is in a safe in our backup room, in a sealed envelope. Part of my checks every so often are to check that it's still correct/accurate. We have an extra account on 1password that's set aside for "Recovery" also - So the details on how to access that are in it as well. Where 2fa is needed, we've got a physical yubi key in the envelope as well. SMT don't generally go near the backup room (It's on seperate keys) & there's CCTV in there that alerts on entry so I'm not massively worried about meddling that wouldn't be detected.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now