Jump to content

Recommended Posts

Posted

Hi all,

 

We have a bit of a situation kicking off at our school. It was agreed 6 months ago that a former ICT Support Room/Office would be turned into a 2nd server room as part of our disaster recovery plan. Basically the main server room is easily accessible via the roof - and I once witnessed an ASBO peering in after hours not so long ago. So server room 2 has been setup at the other side of the school - with all data replicated to the BDC as well as an NAS box and admin server etc...

 

To cut a long story short I recently got an e-mail from the head of ICT (Teaching) telling me to use some work experience kids (the idiot ones who'd been sent home from placements) to clear some space in there so teachers could store coursework and files. This I have refused to do - regardless of the work experience kids - as I steadfastly refuse to share the server room with teaching staff. In my 7 years at the school I have to say, that although I respect the difficult job they do, I have not been impressed with the teachers approach to security - from doors being left unlocked to theft from classrooms. The room is likely to become a dumping ground to keep classrooms spic and span. I have got a feeling I might be over-ruled on this as I am being seen as being petty...

 

Anyone have an opinion/experience of this at your site? I'm particularly looking for support I could forward to senior team as I feel my disaster recovery plan could turn into a "disaster waiting to happen plan" if shared access is forced on me.

 

Cheers.

Posted

Put everything in writing and send it to the headteacher. DPA compliance is responsibility and this cannot be assured if physical access to critical network equipment is not restricted as it currently.

/

Posted
They will leave doors open and send kids in to fetch things. Very bad sharing with servers.. the bad points are obvious - cables being pulled out, pressing buttons they shouldn't, stealing data, physical damage. We don't have that problem here, so all I can advise is to write down the reasons why it won't be a good idea and what will happen if it were to go ahead.
Posted

You want that room with as limited access as possible on a special key or code that only you, your immediate staff, SMT and the site supervisors have.

You need to explain how if anything is 'accidentaly' damaged or stolen because of teachers coming in and out how this is going to effect the running or indeed loss of the network. For example where is the school safe? Does everyone have access to it etc etc.

You could also argue about dust and smaller spaces heating up quicker I suppose if your desperate as well.

Posted

With my BOFH hat on, I'd expect having a large button marked 'do not press' hooked up to the halon fire suppression system would solve the problem admirably.

 

Practically, DPA alone should be enough. Check your insurance too. It might evaporate under the circumstances.

  • Thanks 2
Posted

You could always use the health and safety at work act. In regards to the servers being a heat generating source and in the case of a fire anything else in that room i.e. teachers work could cause the fire to spread very rapidly.

Also the security of data under the data security act first line of security is a locked door and as you have already experienced the teaching fraternity's ideas on this (a locked door is just another inconvenience to them so they leave it open). Our LEA has been in touch with me regarding the data protection act and it seems their is a genuine crisis as to the teachers use and access to data in what ever form. In fact so much so that they are having a document produced after liasing with the unions of all the staff members telling the schools of the implications which can be brought about by a member of staff a: leaving a room open with a computer in and logged on and b: leaving access to a computer for an intruder to gain access by whatever means. What this means is that we as Network Managers have a get out clause by making the headteachers aware in writing of the concerns of the LEA and then with his blessing put out a memo to all staff reminding them of the data protection act and that they themselves as individuals are solely responsible for their actions and that they could be legally proscecuted by the courts for failure to comply.

 

sorry if this is long winded but have been going through this evolutionary experience myself.

Good luck with your Head teacher and try and get him on your side becuase legally standing the buck finally stops with him so if you can gently remind him of his obligations to the school in a nice way he should see it your way.

Posted
Things started to go missing from my office which had open access so all staff now have proximity cards and access to my office which has the server room leading off from it is now resricted to 2 people :D
Posted

I absolutely agree with all the above. The only people that have access to my server rooms is the site manager, my technician and myself period.

 

Ben

Posted

If all your servers are in a locked cabinet in there along with the KVM and controls then they might throw back the argument that they would have to force the cabinet door open to do any real damage...

 

But then there's the health and safety issue if there is a distribution unit in there. Kids would not be allowed near one (IIRC).

 

You could also add to your argument that it's their data at risk. If someone accidentally knocked a power switch and took down some of the network, CMIS data, their open files etc could be at risk.

 

Also if teachers are going to dump work in there then they might block your access to the servers or make your path to them more dangerous therfore making your job harder to do.

 

Plenty of possibilities really. But our server room here (we've only got the one with actual servers in) has the master key mortice lock and one of those coded yale locks with a code that is different to ones used on the other coded doors around the site.

Posted

@bossman: IF you are allowed coudl you post that document if you get it? We are having a serious nightmare with the prospect of every teacher having a PC on their desk from next year to do registration and the problems associated with teachers leaving themselves on, kids accessing them etc. We have mentioned the whole DPA and security issue and the general feeling seems to be "we are teachers it doesn't affect us anad we are too busy". This isn't a teacher bash but we can see a serious situation happening and everyone saying "ohh why'd that happen", while we smack our heads against a wall.

 

We have had at least 3 known intruder situations where staff haven't reported seeing someone until much later, or not done anything at all and yet when all this comes out the usual question go around about how coudl this happen, why isn't anything being done. 2 days later, doors are left unlocked again and everything is back to normal! There are only about 4 places I would trust to leave anything, our office, store cupboard and the server room being the main 3.

 

Sorry, turning into a bit of an OT rant now but it is a personal bug bear

 

Would be nice to see what is being said else where.

Posted

I think Simon puts it best: You'll get access to my computer room right after you pry the Halon test key out of my cold, lifeless hands

 

We don't allow anyone into the server room. The site manager has a key, but unless it's on fire he doesn't go in.

 

If you allow unsupervised access to your server room, you have _no_ assurance that stuff hasn't been bumped / damaged / fiddled with. Quote DPA, security or get the locks changed. If SMT still insists on users in server room start looking for another job, Bad Things will happen and you don't want that staining your resume.

Posted
The site manager has a key, but unless it's on fire he doesn't go in.

 

On fire? Is that in his job description? :)

 

ssshh - we only point it out when there's a fire and we need a "volunteer". :)

 

He's got the keys to give to the fire brigade so they can check everywhere if there was / might be a fire.

Posted

Surely, if you are using it as a 'backup' server room, storing the paper copies of coursework in there mitigates the point in keeping them. Imagine the scenario... a server expodes, the room is alight and all those paper copies of the coursework go too!

 

Health and Safety is also a big issue... trailing cables, noise levels, high voltage power supplies... need I go on?

 

Then you have the Becta advice that servers should only be accessible to qualified personnel - they recommend a locked room with limited access! (Check the Matrix and framework stuff)

  • 4 months later...
Posted
I had the same problem a few years ago, took my concerns about teachers particularly ICT Co-ordinator (who considered himself a bit of a whizz but in reality couldn't co-ordinate his tie with his shirts) having access to server room to Head Teacher and quoted Data Protection Act and how if data was lost or stolen he would be ultimately responsible, this got him on board.
  • 3 months later...
  • 1 month later...
Posted

Very interesting thread this as it's similar to my current situation. I currently share a server with staff who I'm constantly reminding to lock my door when they've been in, I even lock it when I'm going next door to use the loo!

 

I could easily get health and safety involved and might well do if the situation doesn't improve, the room is my office as well as the server room and store room and isn't exactly large..

Posted

Sadly I do until the new school is built (2009) where I'll have my own dedicated office and server room, only worry is that the office looks only large enough for one person... and I certainly won't be working here on my own if that's the case.

 

I need assistance as it is, anyway back to work!

  • 7 years later...
Posted

Health and Safety / Data protection / Fire Risk should be easiest way of getting around this issue.

 

Server cabinets require a clean flow of cool air to reduce the risk of over heating and fire risk. Unlikely I know but by storing paperwork you are increasing the risk of fire, you are reducing/restricting the air circulation and increasing the risk of injury. I have had many scuffed knuckles trying to working my way round our server cabinet.

 

our server cabinet even tore my shirt whilst squeezing behind it.

Posted
Physical access to a server compromises basic security which is a Data Protection issue (students should certainly never be in there unsupervised). Storing paper in a server room would present an unacceptable fire hazard.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...