Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

IT was password protected, but it all depends on how it was protected....

 

More to the point why is it stored locally at all, surely having something stored on a server would be much safer when it comes to theft....

 

posted just after localzuk :(

Posted
Hopefully it will just be petty theft and they sell it on or it gets reformatted. The new owner will probably have no idea what data was on it.
Posted
The information is password protected and bosses believe that the information will be of little use to those who stole the computer.

 

That makes it alright then doesn't it? It frustrates me that in 2009, data protection is becoming a real problem yet no one takes the bull by the horns and sets down proper regulation or procedure.

 

The one fundamental question which should always be asked is "Why was the data taken off site and for what purpose?" Lessons can and should be learned from this, but I think a lot of lessons can also be learned from the banking industry. Although not perfect, a lot of their procedures should be adopted and should be implemented in other industries; education being one of them!

Posted
That makes it alright then doesn't it? It frustrates me that in 2009, data protection is becoming a real problem yet no one takes the bull by the horns and sets down proper regulation or procedure.

 

The one fundamental question which should always be asked is "Why was the data taken off site and for what purpose?" Lessons can and should be learned from this, but I think a lot of lessons can also be learned from the banking industry. Although not perfect, a lot of their procedures should be adopted and should be implemented in other industries; education being one of them!

 

The problem is a lack of leadership from the top. And I don't mean in the school, I mean at an LEA level. There are now detailed guidelines on what should be happening, and they have been discussed quite a bit on this site, but as yet, we have yet to receive any guidance on what is expected at a school level from our LEA down here. When we have asked them about it the reply was 'we're looking into it' and that's it.

 

The data protection issue always seems to take a back seat, coming up as an afterthought time and time again. ie. SIMS.net, for example, implemented without much thought to the security of the data held within in my opinion. No method of forcing a time out of sessions, no method of ensuring data isn't being projected onto a screen in a classroom, no support for 2 token authentication. Sure there is a complex ACL system for letting different people see different things, but this is not enough. What about when people go and export data willy-nilly. Littering their local file systems with insecure excel files and word documents?

 

Whenever I think of a new system, the first thought is 'what security is involved' and then work from there. Otherwise, the end result is a system filled with security flaws and holes.

Posted
Why was it stored locally at all?! Information like this should be centralised and then connected to via a VPN or other secure connection...

 

The use of laptops to process such data is common as it removes the risk of central services being down and not having access to the information. This is important if you have to go to difference locations and work / present the information and those locations may not have connections to the central services ... an example would be an Ed Psych coming in to your school and wanting to show information to various folk but they have to have a live 'Net feed to do it over a VPN. How would you feel is a random person came into your school and asked to connect it to your wireless / wired network to set up VPN access to another location?

 

So ... local copies of the data are there to make it usuable.

 

I do agree with the question about the data needing to be encrypted and for all we know it may have been encrypted too ... the news article doesn't really give enough information about it.

 

When it comes to MIS ... then many do have two-factor authentication ... you have to authenticate against a client and then again against the MIS ... the human problem is ensuring that the details for both are not on a post-it note on the screen!

Posted
The use of laptops to process such data is common as it removes the risk of central services being down and not having access to the information. This is important if you have to go to difference locations and work / present the information and those locations may not have connections to the central services ... an example would be an Ed Psych coming in to your school and wanting to show information to various folk but they have to have a live 'Net feed to do it over a VPN. How would you feel is a random person came into your school and asked to connect it to your wireless / wired network to set up VPN access to another location?

 

So ... local copies of the data are there to make it usuable.

 

I do agree with the question about the data needing to be encrypted and for all we know it may have been encrypted too ... the news article doesn't really give enough information about it.

 

When it comes to MIS ... then many do have two-factor authentication ... you have to authenticate against a client and then again against the MIS ... the human problem is ensuring that the details for both are not on a post-it note on the screen!

 

Ah, but why would they need the details of 33,000 people like in this case? Also, we now have a world of 3G internet connections, so there is no longer any excuse.

Posted

3G does not work as a reliable connection solution for fast access. How many of us moan about poor mobile signals in buildings?

 

33000 people is not a lot. If you have an offline copy of a database it may be that you simply have the version that covers secondary schools. That wouldn't even cover our secondary students in Northants.

 

So, again, I ask you, would you allow them to connect to your network?

Posted
So, again, I ask you, would you allow them to connect to your network?

 

Providing they had valid credentials, then yes - but only to the internet DMZ. They wouldn't get access to our LAN.

Posted

And you have a VLAN in place that takes them to your DMZ? How often do you get such visitors and did you have a struggle with your smt to get the funds to set it up?

 

Good to hear about it though.

Guest Guest
Posted (edited)
The use of laptops to process such data is common as it removes the risk of central services being down and not having access to the information.

 

Then they should make their servers reliable.

 

they have to have a live 'Net feed to do it over a VPN. How would you feel is a random person came into your school and asked to connect it to your wireless / wired network to set up VPN access to another location?

 

They wouldnt be a random person, they would be a person who is responsible for a hell of alot more data than i am, or any of my school are for that matter. Besides which most of us now are on the Northern/Birmingham/etc Grid, what exactly is this grid for if it isnt for this purpose?

 

 

So ... local copies of the data are there to make it usuable.

 

I doubt very much they needed that sort of detail. I fell it is infinately more likely that de-personalised data would have surficed. *

 

 

When it comes to MIS ... then many do have two-factor authentication ... you have to authenticate against a client and then again against the MIS ... the human problem is ensuring that the details for both are not on a post-it note on the screen!

 

The first line of authentication relies on us, the techies, a breed soon to be replaced due to our incompitance (when talking on a national level). Not really good going so far. Now what about when SIMS is using its Active Directory authentication? Not the best method anyway, but what about if a user leaves themselves logged on, or if our system is insecure? What if we have a generic user called "teacher" with a password of "teacher"... and i think its fair to say we could all name atleast one school which has such a user.

 

 

* Following on...

33000 people is not a lot.

 

It is for doing data processing. 33,000 people having data processing perfomed on them is not a job for a laptop. Given this i personally can think of 2 likely reasons for the data being on there; The user is one of these people, who despite being told to leave data on the server, he/she copies it onto his/her laptop whilst doing work. Or he/she was doing data analysis/reporting/graphing/etc, in which case i go back to my original thought of there is no need for peoples personal details to be on that laptop.

 

 

Its exactly that attitude of "oh but its easier [to just have copies of the data flying all over the place, saves me having to plug my laptop in to the network/etc]" which puts me firmly against ID cards. What about when someone "loses" your full DNA data? (A natural progression of biometrics) Do you just apply for new DNA? lol

Edited by Guest
Posted
3G does not work as a reliable connection solution for fast access. How many of us moan about poor mobile signals in buildings?

 

33000 people is not a lot. If you have an offline copy of a database it may be that you simply have the version that covers secondary schools. That wouldn't even cover our secondary students in Northants.

 

So, again, I ask you, would you allow them to connect to your network?

 

Ok, 3G isn't perfect - but put it this way, I work in an area where phone signals are well known for being terrible, and I still make use of 3G/GRPS - if a system won't work over slow connections, it should be altered so that it should. But then again, yes, I would allow them to connect to the network, if I were given the go-ahead by SMT and had checked to ensure their machine isn't riddled with viruses, (when I have some spare time, I will be looking at creating a DMZ but until then, intrusive checks on their machines will have to take place), if they couldn't connect via their own device. There is no excuse for carrying around data!

 

And where are you coming from?! 33,000 people is a lot!! The 33,000 people involved will be thinking it is a lot! As will the information commissioner's office.

 

It is the attitude that 33,000 people's data isn't a lot, and that servers are unreliable etc... that is perpetuating this data loss problem. No-one is taking it seriously. It will not be long before the government finds itself defending itself from a list of civil cases. When it starts costing the local authorities, government departments and subcontractors millions in fees and fines, is that when they will take data security seriously?

 

Put it simply, if I ever receive a letter stating that my data has been lost by some idiot organisation that doesn't encrypt their data, or allows staff to carry around 'offline copies' of databases, I will be talking to a solicitor. Everyone else involved in these situations should be doing too.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...