Jump to content

Recommended Posts

Posted
Anyone got a pointer to best practice for access permissions for a school network please. Reason for asking - at one secondary level school I work in currently, which has a Windows 2003 server network set up by a local IT company access across the network is currently set to "Everyone" and the only control measures that seem to be in place come from various logon.bat files applied to users in AD!

 

I'm keen to get in there and make things more secure but would find it useful have a plan of action about what to set up.

 

Follow least privilege and you can't go wrong. People should have enough permissions to do their jobs without hindrance, and absolutely no more.

 

And definitely get that everyone access removed as soon as you possibly can. Better to have a dead network than have it that exposed.

  • Thanks 1
Posted

There have been some interesting points raised here however, I don't think there is one answer to fit all schools, I believe the reasons for giving staff access to student data depends on the individual school in question.

 

At my school the read/write permnisssions were already in place when I started and as we all know to well teaching staff are not always keen on change!

 

We have had the need here e.g. student goes off (holiday/study leave/illness etc) and hasn't copied a piece of design work which needs to be machined overnight by the DT teacher to the right place. DT teacher needs to access it. If he has read access he can just get it sorted. I know they can come to us for it but it makes life easier all round if they can simply copy it them self.

 

There are many other examples along the same lines. Students often go off not having printed work needed for portfoilios etc.

 

I see no need for write access though.

 

These are primarily the reasons why staff have access to student data here although these tasks only really need read permissions, I suspect that write permissions are needed by staff when they need to tweak student coursework :eek:

 

Plan to implement changes where staff no longer I have access to student data at all. Where departments need read access to implement the issues mentioned above by jcollings I plan to map network drives to each departmental ICT Suite. Students will have write permissions to these drives and will be only allowed to save files of a particular type to them, copies of any work that needs to be machines over night or printed in colour can be placed in here for staff to access, the files will probably be deleted every so often to stop the drive from being used as a dumping ground.

 

Its still not ideal but possibly a step in the right direction and atleast staff will no longer have direct access to student home directories.

Posted

No access to students work here, staff come and see us if they need to access a students work,so that someone else can witness what staff are doing I have a number of reasons for this.

 

1. If staff have write access they could obviously alter\delete students work either on purpose or by accident. This could mean that students could be advantaged or disadvantaged.

 

2.If staff have read access they can not only read or access course work for their course but all other documents some of which could be private, we all know and explain to students and staff shouldn't store private documents but we know this happens.

 

3. Having another member of staff as a witness when students work is being accessed also covers staff in case a student were to claim a member of staff had altered\deleted their work this is particularly critical when we are talking about course work.

 

4.As part of Teaching Staff Performance Management here, their students Achievement\Attainment is taken into account. Due to this their is always the fear that some unscrupulous staff could improve students work to increase students Achievement\Attainment for personal gain. I am not saying this happens here as far as I know it doesn't, just that it is opening that can of worms and to give the staff the Mechanism to do this by allowing them write access to students work may not be the best idea and may be irresponsible on our parts.

 

This is what I explain to staff when asked as regards giving them access to students work, which they seem to understand I am not trying to be awkward but am trying to cover their backs as well, if they haven't got access on their own then no one can say that they have altered\deleted students work.

  • Thanks 2
Posted
A science teacher has every right to look at a student's science exercise book and textbooks during the lesson. Why should they be checking English books?

Perhaps because he's his form tutor, who should be taking an overall view of the child's education. Perhaps because he's a ICT teacher, who should be monitoring work done in other curriculum areas to assess cross-curricular standards of ICT. Perhaps because the Science teacher has noticed a child's written ability is poor and wants to check their English to see if there is a general problem or more to do with his expectations of what a child can do.

 

Secondary teachers should be taking more of an overview of the whole child, not just focusing on their subject. It's moving more this way. Technology can help with this - and if it's easy, it's more likely to happen.

 

 

Does anybody have any real life scenario where a teacher would need read or read/write access to student's work?

When children work on one project in a team, but the child who's saved the work is off. The teacher needs to go into that child's folder to retrieve it.

 

 

I personally can't think of a good reason why a teacher should need to edit pupils files

Take it back to the other example - this is like the exercise books. We don't say "teachers can't have write access to the exercise books"; we absolutely expect them to write in the books when they mark them.

Good example. Didn't think of that one. We call complain about how much printing goes on - office contains useful tools annotations and feedback. Yes, this can be achieved with departmental folders, but really work should be attached to the child.

Also, a teacher might want to quickly see what a child has achieved in a lesson before it's formally submitted for assessment. They may want to check up on a child who was pissing about all lesson or they may want to gaugue the level of achievement so they can plan their next steps in learning. (I do this with my kids' ICT work, sometimes!) With written work they can have a quick flick through the pile of text books but when work is locked in private folders this isn't possible.

 

A lot of students My Documents folders lack organisation and thus it is bad enough them trying to find the correct version of their coursework - let alone the teacher.

Well, perhaps that's because we treat the My Docs folder like a teenager's bedroom - something rarely to be opened or looked at, rather than a place for storing work, a record of day-to-day achievement, a tool for formative assessment.

In primary, we spend hours teaching children how to write their date, underline the title, stick their work in their book straight. We ought to treat the work children save in their my docs folder with the same respect - As of tomorrow, I'm going to start yelling at kids who don't save their work properly!

 

 

How's about, as a compromise:

* Pupils have a folder for personal/out of school work that has restricted access (that covers people's privacy fears.)

* Staff have read access to folders (except their private folder).

* A basic directory structure is created for the child (e.g. subject headings) with read only access to the root of the my docs. Children are taught and expected to save their work correctly.

* Staff can create new files in a folder and edit these - however they can not modify/delete work that the child has created. This would prevent accidential deletion/adjusting coursework fears but would allow the teacher to create a duplicate copy of the work which could be annotated for marking/feedback.

* Staff have folders with shortcuts to pupils work whom they teach. This could be created fairly easily with a script and a exported file from SIMS. This would allow them to more easily access the work of the chidren they teach.

Posted

The problem I found is one of attitude ie we're teachers and you are nothing (despite having more experience and qualifications than the entire IT Department put together :lie: )

 

was faced with this dilema. My predecessor pretty much let the IT teachers do what they wanted, especially with regards to accessing the students user spaces. Comming from the private sector this shocked me, but what was wordse was the HT's attitude. When I pointed out "..what if the teachers altered the students work.." I was met with a look that said it all!!

 

I checked with BECTA and the LEA who advised that read access was more than suitable, write access was a deffo no-no but it still hasnt stopped the HOD trying to get hold of a USB External Drive to copy the students work. I covered my back by sending the HOD and HT a memo highlighting that under the DPA they not me are responsable for the data if it get's lost or if there are any suggestions of cheating.

Posted
Perhaps because he's his form tutor, who should be taking an overall view of the child's education. Perhaps because he's a ICT teacher, who should be monitoring work done in other curriculum areas to assess cross-curricular standards of ICT. Perhaps because the Science teacher has noticed a child's written ability is poor and wants to check their English to see if there is a general problem or more to do with his expectations of what a child can do.

 

Secondary teachers should be taking more of an overview of the whole child, not just focusing on their subject. It's moving more this way. Technology can help with this - and if it's easy, it's more likely to happen.

 

Which should be done by communicating with the child and the child's other teachers, surely? We've got wonderful technology to help with this - e-mail, forums, bulletin boards, mobiles, all sorts of collaboration tools. If you want to know how they're doing in English, ask their English teacher.

 

When children work on one project in a team, but the child who's saved the work is off. The teacher needs to go into that child's folder to retrieve it.

 

I wouldn't really call that common enough to warrant access, and it seems to me that its more a failing in the way that the group work is being taught, or in the way that user areas are set up (why don't they have a general group work area?) than it is an excuse to allow permanent read access to a student's entire user area.

 

Good example. Didn't think of that one. We call complain about how much printing goes on - office contains useful tools annotations and feedback. Yes, this can be achieved with departmental folders, but really work should be attached to the child.

 

Editing can also be done just as effectively, and with no trace or auditing. If a teacher had it in for a child, or thought one needed a little boost, what's to stop them? As someone who was a victim of the former at school I am very, very glad that the teacher in question did not have any untraceable way to edit my work.

 

As for departmental folders, why not flip the perspective. Individual submission folders where a child can save work for review, in their own user area, and with appropriate permissions assigned to the teacher.

 

Also, a teacher might want to quickly see what a child has achieved in a lesson before it's formally submitted for assessment. They may want to check up on a child who was pissing about all lesson or they may want to gaugue the level of achievement so they can plan their next steps in learning. (I do this with my kids' ICT work, sometimes!) With written work they can have a quick flick through the pile of text books but when work is locked in private folders this isn't possible.

 

So why not just look at the child's screen and insist they show you the work?

 

How's about, as a compromise:

* Pupils have a folder for personal/out of school work that has restricted access (that covers people's privacy fears.)

* Staff have read access to folders (except their private folder).

* A basic directory structure is created for the child (e.g. subject headings) with read only access to the root of the my docs. Children are taught and expected to save their work correctly.

* Staff can create new files in a folder and edit these - however they can not modify/delete work that the child has created. This would prevent accidential deletion/adjusting coursework fears but would allow the teacher to create a duplicate copy of the work which could be annotated for marking/feedback.

* Staff have folders with shortcuts to pupils work whom they teach. This could be created fairly easily with a script and a exported file from SIMS. This would allow them to more easily access the work of the chidren they teach.

 

Not too bad, but doesn't really agree with the least privilege principle. Its a start though. I'd prefer for it to be a single folder which the staff member does have access to rather than a single folder that they don't.

Posted

Here each teacher has a "drop in box". All kids can see all the teachers drop in boxes, and have write access but no read or modify rights (its actually less than write access, kids can only paste files into the box). When a kid has finished their work, they save it into their folder, copy it and paste it into the drop in box - they can see the subfolders if a teacher has made folders for different classes tasks. If a kid hasn't submitted their work through the drop in box, bad luck, no-one's going to go looking for it.

 

Each teacher can see all the other drop in boxes, but only have full access to their own. We have tried to implement a file naming protocol so if a file appears in a wrong box the teacher knows where it should go.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...