Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted
Just now, FN-GM said:

Only yesterday I was thinking about putting together a list of cyber improvements schools can make at no cost, aside from the time needed to implement them. A lot of these don’t seem to get much attention here. Would people find this useful?

I think a lot of people would find that very helpful

  • Like 1
Posted

Hoping their IT folks are OK as are the rest of the staff.

I do see a couple of concerning points in their IT AUP though - they state they do not monitor anyone's use of IT on school devices unless they suspect wrongdoing - that contravenes KCSIE - and if I read it right, they set passwords for the students and they can't change it without good reason????

  • Like 1
Posted

^ The whole AUP is a cause for concern really (and not just the terrible spelling, grammar, word misuse, conflicting instructions, repeating the same information, not writing for a student audience). 

 

Section 15 (may be given the right to change passwords from the one originally issued) clashes with Section 1 Page 3 (Initial default passwords issued to any student should be changed immediately following notification of account set up.)

 

A generous read is that a PE teacher who last used a computer in the 90s writes this ("on-line") and the IT dept tolerate it because it keeps them quiet for an afternoon.

 

A non-generous read could be summed up as "WTF bangs on about IRC/AOL messenger/MSN Messenger in a student-facing policy anywhere in 2025?" and who on earth let them write this?

 

 

 

  • Like 1
Posted

Sending good vibes out to those impacted, especially to any fellow techies.

Look after yourselves, and remember that those responsible are most likely dead inside.

Posted
3 hours ago, pete said:

^ The whole AUP is a cause for concern really (and not just the terrible spelling, grammar, word misuse, conflicting instructions, repeating the same information, not writing for a student audience). 

 

Section 15 (may be given the right to change passwords from the one originally issued) clashes with Section 1 Page 3 (Initial default passwords issued to any student should be changed immediately following notification of account set up.)

 

A generous read is that a PE teacher who last used a computer in the 90s writes this ("on-line") and the IT dept tolerate it because it keeps them quiet for an afternoon.

 

A non-generous read could be summed up as "WTF bangs on about IRC/AOL messenger/MSN Messenger in a student-facing policy anywhere in 2025?" and who on earth let them write this?

 

 

 

Ugh, I wasn't going to dig any deeper but after your comment making me realise I missed that, I looked at the trust-wide policies. I think it says it all - unprofessionally written, what from the outside appears to be a questionable structure, outdated and unsecure password polices (don't forget to put an asterisk after "Liverpool" to make your 8 character password fully secure and un-hackable!). Absolutely no RPA compliance there, and if there is, it'll be void shortly if not already. Shouldn't point fingers, but I don't think it takes a genius to work this one out :(

Posted (edited)

I wouldn't too much weight into a piece of paper/policy document.

 

Some places have lengthy policy documents, but no real actual auditing/proof they follow them.

Others have small ones, but do a metric ton of work/other things that aren't listed.

 

Edited by DrCheese
Posted

True, but I sincerely doubt any insurance provider would see it that way - what they do is one thing but if ratified policy states you do it another, it's that they'll be going on.

Not that there's any change in hell they have insurance coverage for that - if they do, richard hammond would like their number for his next car policy ;)

Posted
19 hours ago, FN-GM said:

Only yesterday I was thinking about putting together a list of cyber improvements schools can make at no cost, aside from the time needed to implement them. A lot of these don’t seem to get much attention here. Would people find this useful?


I started off with one that is a little more well known, but the impact is high. I have a long list of improvements though so stay tuned.
 

 

  • Like 4

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...